-
Notifications
You must be signed in to change notification settings - Fork 66
187 lines (168 loc) · 7.09 KB
/
Copy pathnightly-quality-gate.yaml
File metadata and controls
187 lines (168 loc) · 7.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
name: "Nightly Quality Gate"
on:
# allow for kicking off quality gate check manually
workflow_dispatch:
# run 5 AM (UTC) daily
schedule:
- cron: "0 5 * * *"
permissions: {}
concurrency:
group: nightly-quality-gate
cancel-in-progress: true
jobs:
select-providers:
runs-on: runs-on=${{ github.run_id }}/cpu=2/ram=4+8/family=t4g+t3a+t3+m6g+m6a/spot=price-capacity-optimized/retry=when-interrupted
permissions:
contents: read
outputs:
providers: ${{ steps.determine-providers.outputs.providers }}
multicore-providers: ${{ steps.split-providers.outputs.multicore-providers }}
other-providers: ${{ steps.split-providers.outputs.other-providers }}
steps:
- uses: runs-on/action@4e5f72399b6b17f2e79c511c1b38a315a64d22dc #v2.2.0
if: ${{ vars.TRACK_RESOURCE_METRICS != '' }}
with:
metrics: ${{ vars.TRACK_RESOURCE_METRICS }}
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 #v7.0.0
with:
# in order to properly resolve the version from git
fetch-depth: 0
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
with:
tools: false
- name: Determine providers
id: determine-providers
run: |
# select all providers as test subjects (this populates the matrix downstream)
content=`cd tests/quality && make all-providers`
echo $content
echo "providers=$content" >> $GITHUB_OUTPUT
- name: Split providers by concurrency needs
id: split-providers
run: |
cd tests/quality
# use vunnel's tag system to split providers by concurrency needs
multicore_providers=$(make all-providers TAG=multicore)
other_providers=$(make all-providers TAG='!multicore')
echo "multicore-providers=$multicore_providers" >> $GITHUB_OUTPUT
echo "other-providers=$other_providers" >> $GITHUB_OUTPUT
validate-provider-multicore:
runs-on: runs-on=${{ github.run_id }}-multicore-${{ strategy.job-index }}/cpu=16/ram=32+64/family=c6gd+c5ad+m6gd+c7gd+c5d/spot=price-capacity-optimized/retry=when-interrupted
timeout-minutes: 480
needs: select-providers
if: needs.select-providers.outputs.multicore-providers != '[]'
strategy:
matrix:
provider: ${{fromJson(needs.select-providers.outputs.multicore-providers)}}
fail-fast: false
permissions:
contents: read
packages: read
steps:
- uses: runs-on/action@4e5f72399b6b17f2e79c511c1b38a315a64d22dc #v2.2.0
if: ${{ vars.TRACK_RESOURCE_METRICS != '' }}
with:
metrics: ${{ vars.TRACK_RESOURCE_METRICS }}
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 #v7.0.0
with:
# in order to properly resolve the version from git
fetch-depth: 0
# we need submodules for the quality gate to work (requires vulnerability-match-labels repo)
submodules: true
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
- name: Run quality gate
uses: ./.github/actions/quality-gate
with:
provider: ${{ matrix.provider }}
env:
# needed as a secret for the github provider
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
validate-provider:
runs-on: runs-on=${{ github.run_id }}-provider-${{ strategy.job-index }}/cpu=8/ram=16+64/family=c6gd+c5ad+m6gd+c7gd+c5d+c6id+m5ad+m7gd+m5d+r6gd+m6id+r5ad+r7gd+r5d+r6id/spot=price-capacity-optimized/retry=when-interrupted
timeout-minutes: 480
needs: select-providers
if: needs.select-providers.outputs.other-providers != '[]'
strategy:
matrix:
provider: ${{fromJson(needs.select-providers.outputs.other-providers)}}
fail-fast: false
permissions:
contents: read
packages: read
steps:
- uses: runs-on/action@4e5f72399b6b17f2e79c511c1b38a315a64d22dc #v2.2.0
if: ${{ vars.TRACK_RESOURCE_METRICS != '' }}
with:
metrics: ${{ vars.TRACK_RESOURCE_METRICS }}
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 #v7.0.0
with:
# in order to properly resolve the version from git
fetch-depth: 0
# we need submodules for the quality gate to work (requires vulnerability-match-labels repo)
submodules: true
persist-credentials: false
- name: Bootstrap environment
uses: ./.github/actions/bootstrap
- name: Run quality gate
uses: ./.github/actions/quality-gate
with:
provider: ${{ matrix.provider }}
env:
# needed as a secret for the github provider
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# note: the name for this check is referenced in release.yaml, do not change here without changing there
Nightly-Quality-Gate:
runs-on: runs-on=${{ github.run_id }}/cpu=2/ram=4+8/family=t4g+t3a+t3+m6g+m6a/spot=price-capacity-optimized/retry=when-interrupted
needs:
- validate-provider
- validate-provider-multicore
if: ${{ always() && !cancelled() }}
steps:
- uses: runs-on/action@4e5f72399b6b17f2e79c511c1b38a315a64d22dc #v2.2.0
if: ${{ vars.TRACK_RESOURCE_METRICS != '' }}
with:
metrics: ${{ vars.TRACK_RESOURCE_METRICS }}
# based on https://docs.github.com/en/actions/learn-github-actions/contexts#job-context
# the valid result values are: success, failure, cancelled
- env:
VALIDATION_STATUS: ${{ needs.validate-provider.result }}
VALIDATION_MULTICORE_STATUS: ${{ needs.validate-provider-multicore.result }}
run: |
echo "Validations Status: $VALIDATION_STATUS"
echo "Validations Multicore Status: $VALIDATION_MULTICORE_STATUS"
# allow "skipped" status since empty matrices result in skipped jobs
case "$VALIDATION_STATUS" in
success|skipped) ;;
*) fail=1 ;;
esac
case "$VALIDATION_MULTICORE_STATUS" in
success|skipped) ;;
*) fail=1 ;;
esac
if [ "$fail" = 1 ]; then
echo "🔴 Quality gate FAILED! 😭"
exit 1
fi
echo "🟢 Quality gate passed!"
- name: Notify Slack on failure
uses: slackapi/slack-github-action@91efab103c0de0a537f72a35f6b8cda0ee76bf0a #v2.1.1
if: ${{ failure() }}
with:
webhook: ${{ secrets.SLACK_TOOLBOX_WEBHOOK_URL }}
webhook-type: incoming-webhook
payload: |
text: "Vunnel nightly quality gate has failed"
blocks:
- type: section
text:
type: mrkdwn
text: |
*Vunnel nightly quality gate has failed*
• Repo: `${{ github.repository }}`
• Workflow: `${{ github.workflow }}`
• Event: `${{ github.event_name }}`
• <https://github.com/anchore/vunnel/actions/workflows/nightly-quality-gate.yaml|View Workflow>