-
Notifications
You must be signed in to change notification settings - Fork 12
Expand file tree
/
Copy pathaction.yml
More file actions
136 lines (121 loc) · 5.53 KB
/
Copy pathaction.yml
File metadata and controls
136 lines (121 loc) · 5.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
name: Setup integration test environment
description: Prepare toolchains, Viceroy, and Docker images for integration test jobs.
inputs:
origin-port:
description: Fixed origin port baked into the WASM binary for integration tests.
required: true
check-dependency-versions:
description: Run the integration dependency version consistency check.
required: false
default: "true"
install-viceroy:
description: Install the Viceroy binary used by integration tests.
required: false
default: "true"
build-wasm:
description: Build the trusted-server WASM binary for integration tests.
required: false
default: "true"
build-axum:
description: Build the trusted-server-axum native binary for integration tests.
required: false
default: "true"
build-test-images:
description: Build the framework Docker images used by integration tests.
required: false
default: "true"
build-cloudflare:
description: Build the Cloudflare Workers bundle (wasm32-unknown-unknown) for integration tests.
required: false
default: "false"
outputs:
node-version:
description: Node.js version read from .tool-versions.
value: ${{ steps.node-version.outputs.node-version }}
runs:
using: composite
steps:
- name: Check shared dependency versions
if: ${{ inputs.check-dependency-versions == 'true' }}
shell: bash
run: ./scripts/check-integration-dependency-versions.sh
- name: Retrieve Rust version
id: rust-version
shell: bash
run: echo "rust-version=$(grep '^rust ' .tool-versions | awk '{print $2}')" >> "$GITHUB_OUTPUT"
- name: Retrieve Node.js version
id: node-version
shell: bash
run: echo "node-version=$(grep '^nodejs ' .tool-versions | awk '{print $2}')" >> "$GITHUB_OUTPUT"
- name: Retrieve Viceroy version
id: viceroy-version
if: ${{ inputs.install-viceroy == 'true' }}
shell: bash
# `.tool-versions` is the single source of truth for the Viceroy pin.
# The pin matters because upstream Viceroy > v0.16.4 has bumped MSRV
# beyond the rustc pin in `rust-toolchain.toml`.
run: echo "viceroy-version=$(grep '^viceroy ' .tool-versions | awk '{print $2}')" >> "$GITHUB_OUTPUT"
- name: Set up Rust toolchain
uses: actions-rust-lang/setup-rust-toolchain@v1
with:
toolchain: ${{ steps.rust-version.outputs.rust-version }}
target: wasm32-wasip1
cache-shared-key: cargo-${{ runner.os }}
- name: Cache Viceroy binary
if: ${{ inputs.install-viceroy == 'true' }}
id: cache-viceroy
uses: actions/cache@v4
with:
path: ~/.cargo/bin/viceroy
key: viceroy-${{ runner.os }}-v${{ steps.viceroy-version.outputs.viceroy-version }}
- name: Install Viceroy
if: ${{ inputs.install-viceroy == 'true' && steps.cache-viceroy.outputs.cache-hit != 'true' }}
shell: bash
run: cargo install --git https://github.com/fastly/Viceroy --tag v${{ steps.viceroy-version.outputs.viceroy-version }} viceroy
- name: Build WASM binary
if: ${{ inputs.build-wasm == 'true' }}
shell: bash
env:
TRUSTED_SERVER__PUBLISHER__ORIGIN_URL: http://127.0.0.1:${{ inputs.origin-port }}
TRUSTED_SERVER__PUBLISHER__PROXY_SECRET: integration-test-proxy-secret
TRUSTED_SERVER__EC__PASSPHRASE: integration-test-ec-secret-padded-32
TRUSTED_SERVER__EC__PARTNERS: >-
[{"name":"Integration Test Partner","source_domain":"inttest.example.com","bidstream_enabled":true,"api_token":"integration-test-token-alpha-32-bytes-ok"},{"name":"Integration Test Partner 2","source_domain":"inttest2.example.com","bidstream_enabled":true,"api_token":"integration-test-token-bravo-32-bytes-ok"}]
TRUSTED_SERVER__PROXY__CERTIFICATE_CHECK: "false"
run: cargo build --package trusted-server-adapter-fastly --release --target wasm32-wasip1
- name: Build Axum native binary
if: ${{ inputs.build-axum == 'true' }}
shell: bash
env:
TRUSTED_SERVER__PUBLISHER__ORIGIN_URL: http://127.0.0.1:${{ inputs.origin-port }}
TRUSTED_SERVER__PUBLISHER__PROXY_SECRET: integration-test-proxy-secret
TRUSTED_SERVER__EDGE_COOKIE__SECRET_KEY: integration-test-secret-key
TRUSTED_SERVER__PROXY__CERTIFICATE_CHECK: "false"
run: cargo build -p trusted-server-adapter-axum
- name: Build WordPress test container
if: ${{ inputs.build-test-images == 'true' }}
shell: bash
run: |
docker build -t test-wordpress:latest \
crates/integration-tests/fixtures/frameworks/wordpress/
- name: Build Next.js test container
if: ${{ inputs.build-test-images == 'true' }}
shell: bash
run: |
docker build \
--build-arg NODE_VERSION=${{ steps.node-version.outputs.node-version }} \
-t test-nextjs:latest \
crates/integration-tests/fixtures/frameworks/nextjs/
- name: Add wasm32-unknown-unknown target for Cloudflare build
if: ${{ inputs.build-cloudflare == 'true' }}
shell: bash
run: rustup target add wasm32-unknown-unknown
- name: Build Cloudflare Workers bundle
if: ${{ inputs.build-cloudflare == 'true' }}
shell: bash
env:
TRUSTED_SERVER__PUBLISHER__ORIGIN_URL: http://127.0.0.1:${{ inputs.origin-port }}
TRUSTED_SERVER__PUBLISHER__PROXY_SECRET: integration-test-proxy-secret
TRUSTED_SERVER__SYNTHETIC__SECRET_KEY: integration-test-secret-key
TRUSTED_SERVER__PROXY__CERTIFICATE_CHECK: "false"
run: bash crates/trusted-server-adapter-cloudflare/build.sh