Skip to content

planning: refresh Q4 roadmap with blocker prioritization #142

planning: refresh Q4 roadmap with blocker prioritization

planning: refresh Q4 roadmap with blocker prioritization #142

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
merge_group:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
- uses: extractions/setup-just@v4
- name: Run the local-equivalent checks
run: |
go build ./...
just check
- name: Smoke generated project without a bootc host
run: |
go build -o remora ./cmd/remora
D=$(mktemp -d)
printf 'base: quay.io/fedora/fedora-bootc:latest\npackage_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml"
./remora generate --dir "$D"
grep -q 'FROM quay.io/fedora/fedora-bootc:latest' "$D/Containerfile"
./remora install --dir "$D" --no-build vim
./remora list --dir "$D" | grep -qx vim
- name: Smoke the digest-pinned base path
run: |
D=$(mktemp -d)
printf 'base: quay.io/fedora/fedora-bootc\npackage_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml"
# A pre-existing pin is reused verbatim, with no registry round trip.
printf 'quay.io/fedora/fedora-bootc@sha256:%064d\n' 0 > "$D/base"
./remora generate --dir "$D"
grep -q "FROM quay.io/fedora/fedora-bootc@sha256:" "$D/Containerfile"
# The package transaction gets its own layer, so that editing a
# build script does not invalidate the cached install.
test "$(grep -c "<<'REMORA_EOF'" "$D/Containerfile")" = 3
# apply refuses to switch when nothing has been built.
if ./remora apply --dir "$D" 2>/dev/null; then
echo "apply should fail with no local image" >&2
exit 1
fi
- name: Smoke the lockfile invariants without a container runtime
run: |
D=$(mktemp -d)
printf 'package_manager: dnf\npackages: [htop]\n' > "$D/remora.yaml"
printf 'quay.io/fedora/fedora-bootc@sha256:%064d\n' 0 > "$D/base"
# A lockfile left by an earlier build must never outlive the
# resolver: it would pin an old package set indefinitely, and the
# Containerfile would COPY a file generation did not vouch for.
echo stale > "$D/remora.lock.yaml"
./remora generate --dir "$D"
test ! -e "$D/remora.lock.yaml"
! grep -q 'remora.lock.yaml' "$D/Containerfile"
# Without a resolver the build still installs from the spec list.
grep -q 'dnf -y install' "$D/Containerfile"
required-checks:
if: always()
needs: [test]
runs-on: ubuntu-24.04
steps:
- name: Verify required validation passed
run: test "${{ needs.test.result }}" = success