panels-origin/.github/workflows/ci.yml
Cursor Agent 1ac04996b6
ops: generar accesos por ambiente y verificar Postgres, Redis y Contabo
Scripts create-accesses / verify-connectivity para un Postgres+Redis+bucket
por ambiente. /v1/health y el arranque de la API incluyen sonda de storage.

Co-authored-by: alberto.martinez <alberto.martinez@mrdev.mx>
2026-09-02 21:22:39 +00:00

123 lines
4.8 KiB
YAML

name: CI
on:
pull_request:
push:
branches: [main]
jobs:
api:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env:
POSTGRES_PASSWORD: postgres
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U postgres"
--health-interval 10s
--health-timeout 5s
--health-retries 10
redis:
image: redis:7
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 10s
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@v4
- uses: denoland/setup-deno@v2
with:
deno-version: v2.x
- uses: actions/setup-java@v4
with:
distribution: temurin
java-version: "21"
- name: Aprovisionar roles/esquemas Postgres + ACLs Redis
env:
PGHOST: localhost
PGPASSWORD: postgres
PLATFORM_OWNER_PASSWORD: ci-platform-owner
PLATFORM_APP_PASSWORD: ci-platform-app
IAM_OWNER_PASSWORD: ci-iam-owner
IAM_APP_PASSWORD: ci-iam-app
CORE_OWNER_PASSWORD: ci-core-owner
CORE_APP_PASSWORD: ci-core-app
REDIS_ADMIN_URL: redis://localhost:6379
IAM_REDIS_PASSWORD: ci-iam-redis
CORE_REDIS_PASSWORD: ci-core-redis
run: |
sudo apt-get update -qq && sudo apt-get install -y -qq postgresql-client redis-tools
./db/provision/docker-provision.sh
./db/provision/05-redis-acl.sh
- name: Dry-run de Liquibase (updateSQL) -- no debe fallar antes de aplicar
env:
DATABASE_URL_PLATFORM_OWNER: postgresql://panels_platform_owner:ci-platform-owner@localhost:5432/panels_platform
DATABASE_URL_IAM_OWNER: postgresql://panels_iam_owner:ci-iam-owner@localhost:5432/panels_product
DATABASE_URL_CORE_OWNER: postgresql://panels_core_owner:ci-core-owner@localhost:5432/panels_product
run: ./db/update.sh all --context-filter='!dev' -- updateSQL
- name: Aplicar migraciones (con datos de demo, para los tests)
env:
DATABASE_URL_PLATFORM_OWNER: postgresql://panels_platform_owner:ci-platform-owner@localhost:5432/panels_platform
DATABASE_URL_IAM_OWNER: postgresql://panels_iam_owner:ci-iam-owner@localhost:5432/panels_product
DATABASE_URL_CORE_OWNER: postgresql://panels_core_owner:ci-core-owner@localhost:5432/panels_product
run: ./db/update.sh all --context-filter=dev
- name: Verificar aislamiento (roles/RLS/ACLs)
env:
DATABASE_URL_PLATFORM: postgresql://panels_platform_app:ci-platform-app@localhost:5432/panels_platform
DATABASE_URL_IAM: postgresql://panels_iam_app:ci-iam-app@localhost:5432/panels_product
DATABASE_URL_CORE: postgresql://panels_core_app:ci-core-app@localhost:5432/panels_product
REDIS_URL_IAM: redis://panels_iam_redis:ci-iam-redis@localhost:6379
REDIS_URL_CORE: redis://panels_core_redis:ci-core-redis@localhost:6379
run: ./db/provision/verify-isolation.sh
- name: Verificar conectividad Postgres/Redis (S3 opcional en CI)
env:
DATABASE_URL_PLATFORM: postgresql://panels_platform_app:ci-platform-app@localhost:5432/panels_platform
DATABASE_URL_PLATFORM_OWNER: postgresql://panels_platform_owner:ci-platform-owner@localhost:5432/panels_platform
DATABASE_URL_IAM: postgresql://panels_iam_app:ci-iam-app@localhost:5432/panels_product
DATABASE_URL_IAM_OWNER: postgresql://panels_iam_owner:ci-iam-owner@localhost:5432/panels_product
DATABASE_URL_CORE: postgresql://panels_core_app:ci-core-app@localhost:5432/panels_product
DATABASE_URL_CORE_OWNER: postgresql://panels_core_owner:ci-core-owner@localhost:5432/panels_product
REDIS_URL_IAM: redis://panels_iam_redis:ci-iam-redis@localhost:6379
REDIS_URL_CORE: redis://panels_core_redis:ci-core-redis@localhost:6379
run: ./db/provision/verify-connectivity.sh
- name: deno check
working-directory: api
run: deno check main.ts
- name: deno test
working-directory: api
env:
DATABASE_URL_CORE_OWNER: postgresql://panels_core_owner:ci-core-owner@localhost:5432/panels_product
run: deno test --allow-net --allow-read --allow-write --allow-env
web:
runs-on: ubuntu-latest
strategy:
matrix:
app: [web-panel, web-saas]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: ${{ matrix.app }}/package-lock.json
- run: npm ci
working-directory: ${{ matrix.app }}
- run: npm run build
working-directory: ${{ matrix.app }}