Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
66 changes: 35 additions & 31 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:

services:
postgres:
image: postgres:18-alpine
image: postgres:18-alpine@sha256:77f585114c32fbca283dc835b0596f4e52b51b4c6662d7810b2f4084f60a1873
env:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: postgres
Expand All @@ -30,7 +30,7 @@ jobs:
--health-timeout 5s
--health-retries 5
redis:
image: redis:8-alpine
image: redis:8-alpine@sha256:3811787313eba226a2ef38658c6ccb91cd5e110edc89c37767de373120a0e5a0
ports:
- 6379:6379
options: >-
Expand All @@ -46,7 +46,7 @@ jobs:
ENCRYPTION_KEY: 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# The default ubuntu-latest runner ships with ~14GB free, which
# the workspace compile + 40+ test-binary link step regularly
Expand All @@ -59,9 +59,11 @@ jobs:
/opt/hostedtoolcache/CodeQL /usr/local/.ghcup
df -h /

- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: taiki-e/install-action@v2
- uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d # stable
with:
toolchain: stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- uses: taiki-e/install-action@183e4297cca2404691e9380e1307288dced5c82a # v2.87.25
with:
tool: cargo-nextest

Expand Down Expand Up @@ -89,7 +91,7 @@ jobs:

services:
postgres:
image: postgres:18-alpine
image: postgres:18-alpine@sha256:77f585114c32fbca283dc835b0596f4e52b51b4c6662d7810b2f4084f60a1873
env:
POSTGRES_USER: postgres
POSTGRES_PASSWORD: postgres
Expand All @@ -106,7 +108,7 @@ jobs:
--health-timeout 5s
--health-retries 10
redis:
image: redis:8-alpine
image: redis:8-alpine@sha256:3811787313eba226a2ef38658c6ccb91cd5e110edc89c37767de373120a0e5a0
ports:
- 6379:6379
options: >-
Expand All @@ -115,7 +117,7 @@ jobs:
--health-timeout 5s
--health-retries 10
clickhouse:
image: clickhouse/clickhouse-server:26.3-alpine
image: clickhouse/clickhouse-server:26.8-alpine@sha256:652d6997949183f3493f8ff601149e3df4d476be829f0d02b9861454d040c410
env:
CLICKHOUSE_USER: default
CLICKHOUSE_PASSWORD: chtest
Expand All @@ -142,7 +144,7 @@ jobs:
TEST_CLICKHOUSE_PASSWORD: chtest

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# Same disk pressure as the unit job: the server plus 50-odd test
# binaries do not fit in the runner's default free space.
Expand All @@ -152,9 +154,11 @@ jobs:
/opt/hostedtoolcache/CodeQL /usr/local/.ghcup
df -h /

- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: taiki-e/install-action@v2
- uses: dtolnay/rust-toolchain@89b12181fb390509a0842a86cc55eeb8eb928c1d # stable
with:
toolchain: stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- uses: taiki-e/install-action@183e4297cca2404691e9380e1307288dced5c82a # v2.87.25
with:
tool: cargo-nextest

Expand All @@ -171,13 +175,13 @@ jobs:
run:
working-directory: web
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
# Pinned — matches `packageManager` in web/package.json.
# Bump together with that field, never alone.
version: 11.0.0
- uses: actions/setup-node@v4
version: 11.28.4
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: pnpm
Expand Down Expand Up @@ -221,30 +225,30 @@ jobs:
matrix:
platform: [linux/amd64, linux/arm64]
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set image prefix
run: echo "IMAGE_PREFIX=ghcr.io/$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV

- name: Docker meta
id: meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: ${{ env.IMAGE_PREFIX }}/think-watch-server

- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Build and push by digest
id: build
uses: docker/build-push-action@v6
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: deploy/docker/Dockerfile.server
Expand All @@ -261,7 +265,7 @@ jobs:
touch "${{ runner.temp }}/digests/${digest#sha256:}"

- name: Upload digest
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: server-digest-${{ strategy.job-index }}
path: ${{ runner.temp }}/digests
Expand All @@ -281,21 +285,21 @@ jobs:
run: echo "IMAGE_PREFIX=ghcr.io/$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV

- name: Download digests
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: server-digest-*
merge-multiple: true
path: ${{ runner.temp }}/digests

- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

# **Tagged by commit SHA only. `:latest` belongs to release.yml.**
#
Expand Down Expand Up @@ -337,26 +341,26 @@ jobs:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set image prefix
run: echo "IMAGE_PREFIX=ghcr.io/$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV

- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Set up QEMU
uses: docker/setup-qemu-action@v3
uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Build and push web image
uses: docker/build-push-action@v6
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: deploy/docker/Dockerfile.web
Expand Down
30 changes: 15 additions & 15 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ jobs:
- platform: linux/arm64
runner: ubuntu-24.04-arm
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Reclaim runner disk
# `Dockerfile.server` links the entire workspace under LTO +
Expand All @@ -63,10 +63,10 @@ jobs:
df -h /

- name: Set up Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Log in to GHCR
uses: docker/login-action@v3
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand All @@ -75,7 +75,7 @@ jobs:
- name: Resolve image name + platform pair
id: meta
# `platform_pair` is the platform name munged for use as an
# artifact suffix — `actions/upload-artifact@v4` rejects `/`.
# artifact suffix — `actions/upload-artifact` rejects `/`.
# `image` lowercases the owner because GHCR is case-sensitive
# on path segments and the Helm values default to lowercase.
run: |
Expand All @@ -87,7 +87,7 @@ jobs:

- name: Build & push by digest
id: build
uses: docker/build-push-action@v6
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: deploy/docker/Dockerfile.${{ matrix.component }}
Expand All @@ -114,7 +114,7 @@ jobs:
touch "${{ runner.temp }}/digests/${digest#sha256:}"

- name: Upload digest
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: digests-${{ matrix.component }}-${{ steps.meta.outputs.platform_pair }}
path: ${{ runner.temp }}/digests/*
Expand All @@ -135,17 +135,17 @@ jobs:
component: [server, web]
steps:
- name: Download digests
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: ${{ runner.temp }}/digests
pattern: digests-${{ matrix.component }}-*
merge-multiple: true

- name: Set up Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Log in to GHCR
uses: docker/login-action@v3
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down Expand Up @@ -201,8 +201,8 @@ jobs:
name: Helm chart
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: azure/setup-helm@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: latest
- name: Resolve version
Expand All @@ -220,7 +220,7 @@ jobs:
--app-version "${{ steps.meta.outputs.version }}" \
--destination .
- name: Upload chart artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: helm-chart
path: think-watch-*.tgz
Expand All @@ -234,9 +234,9 @@ jobs:
needs: [merge-manifests, package-helm]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Download Helm chart artifact
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: helm-chart
path: .
Expand Down Expand Up @@ -290,7 +290,7 @@ jobs:
esac
echo "prerelease=$PRERELEASE" >> "$GITHUB_OUTPUT"
- name: Create release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
with:
tag_name: ${{ github.ref_name }}
name: ThinkWatch ${{ github.ref_name }}
Expand Down
Loading
Loading