fix(ci): make the validate job actually able to run — it never had
CI / validate (pull_request) Failing after 14s
CI / validate (pull_request) Failing after 14s
ci.yml has been invalid YAML since introduction: the 'Config validation' and old inline checks dedented out of their run:| block scalar, so Gitea could never parse the workflow — CI never ran on any PR despite CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always passed (|| echo swallows the grep hit) and never scanned *.yml — where six embedded credentials were living. - validation logic moved to ci_check.py (testable locally: python3 ci_check.py all) - secrets check now FAILS on embedded http-basic URLs and long api_keys, across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist - added workflow-YAML parse gate so this class of breakage can't recur - py_compile steps no longer swallow errors with '|| echo skipped' - removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml copy would have deployed Mumuni on rc tags too, breaking canary policy, and never ran anyway. - CI_STATUS.md rewritten with the real state + caveats (history still contains the old creds — rotation is a server-side task)
This commit is contained in:
+8
-25
@@ -21,35 +21,18 @@ jobs:
|
||||
|
||||
- name: Python syntax check
|
||||
run: |
|
||||
python3 -m py_compile plugins/platforms/zulip/adapter.py 2>/dev/null && echo "✅ adapter.py OK" || echo "⚠️ adapter.py check skipped"
|
||||
python3 -m py_compile agent-zero-zulip/src/agent_zero_zulip/adapter.py 2>/dev/null && echo "✅ a2a adapter OK" || echo "⚠️ a2a check skipped"
|
||||
python3 -m py_compile plugins/platforms/zulip/adapter.py && echo "✅ adapter.py OK"
|
||||
python3 -m py_compile agent-zero-zulip/src/agent_zero_zulip/adapter.py && echo "✅ a2a adapter OK"
|
||||
|
||||
- name: Workflow YAML parse check
|
||||
run: python3 ci_check.py workflows
|
||||
|
||||
- name: Config validation
|
||||
run: |
|
||||
python3 -c "
|
||||
import yaml
|
||||
cfg = yaml.safe_load(open('config.yaml.example'))
|
||||
assert 'zulip' in cfg, 'Missing zulip config'
|
||||
print('✅ config.yaml.example valid')
|
||||
" 2>/dev/null || echo "⚠️ Config check skipped (no pyyaml)"
|
||||
run: python3 ci_check.py config
|
||||
|
||||
- name: No secrets check
|
||||
run: |
|
||||
! grep -r "api_key.*[A-Za-z0-9]\{20,\}" --include="*.py" --include="*.ts" --include="*.yaml" . 2>/dev/null || echo "⚠️ Possible API key found!"
|
||||
run: python3 ci_check.py secrets
|
||||
|
||||
- name: Deploy script syntax
|
||||
run: bash -n scripts/deploy.sh && echo "✅ deploy.sh syntax OK" || echo "⚠️ deploy.sh syntax issue"
|
||||
run: bash -n scripts/deploy.sh && echo "✅ deploy.sh syntax OK"
|
||||
|
||||
deploy:
|
||||
if: startsWith(github.ref, 'refs/tags/v')
|
||||
runs-on: ubuntu-latest
|
||||
needs: [validate]
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- run: echo "🚀 Deploy tag $(echo $GITHUB_REF_NAME)"
|
||||
|
||||
- name: Deploy to Tanko (canary)
|
||||
run: ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 jerome@192.168.68.122 "cd /root && bash -s" < scripts/deploy.sh --ct=tanko --mode=native "$GITHUB_REF_NAME" 2>&1 || echo "⚠️ Tanko deploy skipped"
|
||||
|
||||
- name: Deploy to Mumuni
|
||||
run: ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 root@192.168.68.123 "cd /root && bash -s" < scripts/deploy.sh --ct=mumuni --mode=native "$GITHUB_REF_NAME" 2>&1 || echo "⚠️ Mumuni deploy skipped"
|
||||
|
||||
Reference in New Issue
Block a user