Repository navigation
perf(deploy): cut a quarter of a deploy's SSH round trips #266
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| rubocop: | |
| name: RuboCop | |
| runs-on: ubuntu-latest | |
| env: | |
| BUNDLE_ONLY: rubocop | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| with: | |
| persist-credentials: false | |
| - name: Setup Ruby and install gems | |
| uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1.310.0 | |
| with: | |
| ruby-version: 3.3.0 | |
| bundler-cache: true | |
| - name: Run Rubocop | |
| run: bundle exec rubocop --parallel | |
| lint-actions: | |
| name: GitHub Actions audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| with: | |
| persist-credentials: false | |
| - name: Run actionlint | |
| uses: rhysd/actionlint@914e7df21a07ef503a81201c76d2b11c789d3fca # v1.7.12 | |
| - name: Run zizmor | |
| uses: zizmorcore/zizmor-action@5f14fd08f7cf1cb1609c1e344975f152c7ee938d # v0.5.6 | |
| with: | |
| advanced-security: false | |
| tests: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| ruby-version: | |
| - "3.2" | |
| - "3.3" | |
| - "3.4" | |
| - "4.0" | |
| gemfile: | |
| - Gemfile | |
| - gemfiles/rails_edge.gemfile | |
| exclude: | |
| - ruby-version: "3.2" | |
| gemfile: gemfiles/rails_edge.gemfile | |
| name: ${{ format('Tests (Ruby {0})', matrix.ruby-version) }} | |
| runs-on: ubuntu-latest | |
| env: | |
| BUNDLE_GEMFILE: ${{ github.workspace }}/${{ matrix.gemfile }} | |
| # Every job resolves from scratch (Gemfile.lock is removed below), so one | |
| # rubygems.org blip fails the whole job - give bundler extra retries. | |
| BUNDLE_RETRY: "6" | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| with: | |
| persist-credentials: false | |
| - name: Remove gemfile.lock | |
| run: rm Gemfile.lock | |
| - name: Install Ruby | |
| uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1.310.0 | |
| with: | |
| ruby-version: ${{ matrix.ruby-version }} | |
| bundler-cache: true | |
| - name: Configure Docker with overlay2 storage driver | |
| run: | | |
| sudo systemctl stop docker | |
| sudo systemctl stop docker.socket | |
| sudo mkdir -p /etc/docker /mnt/docker | |
| cat <<'EOF' | sudo tee /etc/docker/daemon.json | |
| { | |
| "storage-driver": "overlay2", | |
| "data-root": "/mnt/docker" | |
| } | |
| EOF | |
| sudo rm -rf /var/lib/docker/* /mnt/docker/* | |
| sudo systemctl start docker | |
| timeout 30 sh -c 'until docker info >/dev/null 2>&1; do sleep 1; done' | |
| df -h | |
| - name: Run tests | |
| run: bin/test | |
| env: | |
| RUBYOPT: ${{ startsWith(matrix.ruby-version, '3.4.') && '--enable=frozen-string-literal' || '' }} | |
| - name: Check disk usage | |
| if: always() | |
| run: | | |
| df -h | |
| # /mnt/docker only exists if the Docker configure step ran; without the | |
| # guard this always() step adds a second, misleading failure whenever an | |
| # earlier step (e.g. bundle install) is what actually failed. | |
| if [ -d /mnt/docker ]; then sudo du -sh /mnt/docker; fi |