|
37899
|
25347
|
117
|
5
|
96d5c4220525d4bd9ca3dba72a777f0b2afda79d
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
31892
|
2
|
1791617846
|
1791617936
|
1791617845
|
1791617937
|
|
0
|
|
0
|
Edit
Delete
|
|
37966
|
25358
|
117
|
5
|
115d2ab05561884786fce11f6ea8c5bfd58975fb
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
31931
|
2
|
1791623772
|
1791623788
|
1791623772
|
1791623788
|
|
0
|
|
0
|
Edit
Delete
|
|
38343
|
25414
|
117
|
5
|
4de7ffc25207203884cb41ffb752db1f53ba7066
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32044
|
2
|
1791631699
|
1791631729
|
1791631574
|
1791631729
|
|
0
|
|
0
|
Edit
Delete
|
|
38360
|
25417
|
117
|
5
|
a8bb3e5defb80919ebe6af71e18d7e20221c9a29
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32067
|
2
|
1791636697
|
1791636712
|
1791636697
|
1791636712
|
|
0
|
|
0
|
Edit
Delete
|
|
38421
|
25427
|
117
|
5
|
26adf024e6ed77f1aaf17a184712f3dd74562fe5
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32127
|
2
|
1791643965
|
1791643981
|
1791643964
|
1791643981
|
|
0
|
|
0
|
Edit
Delete
|
|
38447
|
25432
|
117
|
5
|
3d987b7104ec1e773297ff80b14f947c18c37fff
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32153
|
2
|
1791644640
|
1791644656
|
1791644640
|
1791644656
|
|
0
|
|
0
|
Edit
Delete
|
|
38448
|
25433
|
117
|
5
|
5774411e365062bd30ab7f7ec546f04bfa64afa7
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32154
|
2
|
1791644690
|
1791644781
|
1791644689
|
1791644781
|
|
0
|
|
0
|
Edit
Delete
|
|
38499
|
25440
|
117
|
5
|
95bb82c6a7404ba3ce2104a029dab4d28aaf49f1
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
32177
|
2
|
1791646189
|
1791646204
|
1791645710
|
1791646205
|
|
0
|
|
0
|
Edit
Delete
|
|
36410
|
24646
|
121
|
5
|
0463b998f7fecbdea518bacdf53a9a46f6c52d19
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const runtime = new URL('postgres://erk_app@postgres:5432/enterprise_reality_kernel');
runtime.password = runtimePassword;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30773
|
2
|
1790699683
|
1790699714
|
1790699681
|
1790699714
|
|
0
|
|
0
|
Edit
Delete
|
|
36411
|
24647
|
121
|
5
|
0d5b830cbe47876ebe8086fd1f15612466463cec
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const runtime = new URL('postgres://erk_app@postgres:5432/enterprise_reality_kernel');
runtime.password = runtimePassword;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30774
|
2
|
1790699818
|
1790699946
|
1790699816
|
1790699946
|
|
0
|
|
0
|
Edit
Delete
|
|
36412
|
24648
|
121
|
5
|
b9c01e45eb5c807f7cbede70a6aebfbc8d0d60be
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const runtime = new URL('postgres://erk_app@postgres:5432/enterprise_reality_kernel');
runtime.password = runtimePassword;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30775
|
2
|
1790699946
|
1790699962
|
1790699839
|
1790699962
|
|
0
|
|
0
|
Edit
Delete
|
|
36413
|
24649
|
121
|
5
|
b9ae9838a77688fb2e40e839c7416057071ca33a
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@127.0.0.1:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const runtime = new URL('postgres://erk_app@127.0.0.1:5432/enterprise_reality_kernel');
runtime.password = runtimePassword;
const client = new pg.Client({ connectionString: admin.href });
await client.connect();
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30776
|
2
|
1790700077
|
1790700090
|
1790700075
|
1790700091
|
|
0
|
|
0
|
Edit
Delete
|
|
36414
|
24650
|
121
|
5
|
a36511f3577f8c6e3b0198eed24ed3ebef756a15
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: ${{ job.services.postgres.ports[5432] }}
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- "5432"
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30777
|
2
|
1790700179
|
1790700196
|
1790700178
|
1790700197
|
|
0
|
|
0
|
Edit
Delete
|
|
36415
|
24651
|
121
|
5
|
ed1670dc7e6483bacae603db2f59b4b0ecddd81c
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30778
|
2
|
1790700249
|
1790700263
|
1790700247
|
1790700263
|
|
0
|
|
0
|
Edit
Delete
|
|
36416
|
24652
|
121
|
5
|
531738daba6ed7d634074e65138f030ab7bf8aa9
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30779
|
2
|
1790700305
|
1790700319
|
1790700304
|
1790700319
|
|
0
|
|
0
|
Edit
Delete
|
|
36417
|
24653
|
121
|
5
|
495fc74942c3d101613165202d9e5b8016969eb8
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30780
|
2
|
1790701525
|
1790701542
|
1790701524
|
1790701542
|
|
0
|
|
0
|
Edit
Delete
|
|
36418
|
24654
|
121
|
5
|
3ba1a77bc465975ce829de1a44fb90623e01f069
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30781
|
2
|
1790701756
|
1790701771
|
1790701755
|
1790701771
|
|
0
|
|
0
|
Edit
Delete
|
|
36419
|
24655
|
121
|
5
|
bc4d59f2822b56e8b97570d25cfd4d8b61cdde12
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30782
|
2
|
1790701881
|
1790701895
|
1790701880
|
1790701895
|
|
0
|
|
0
|
Edit
Delete
|
|
36420
|
24656
|
121
|
5
|
8bb41429437f46d37678921b75ffcaff1ed78841
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30783
|
2
|
1790702047
|
1790702061
|
1790702045
|
1790702062
|
|
0
|
|
0
|
Edit
Delete
|
|
36421
|
24657
|
121
|
5
|
21d073490c60bb141a267af9424b9f0ef7c3440d
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30784
|
2
|
1790702130
|
1790702160
|
1790702129
|
1790702161
|
|
0
|
|
0
|
Edit
Delete
|
|
36422
|
24658
|
121
|
5
|
5f607eb22a5ef160fdc74423910299d135063168
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30785
|
2
|
1790704681
|
1790704711
|
1790704679
|
1790704711
|
|
0
|
|
0
|
Edit
Delete
|
|
36423
|
24659
|
121
|
5
|
236c67c85b0ed28961bd3807befc1c00d6573f6b
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30786
|
2
|
1790704736
|
1790704736
|
1790704735
|
1790704736
|
|
0
|
|
0
|
Edit
Delete
|
|
36424
|
24660
|
121
|
5
|
fde5331617b33e7df7ff5c3b2893c2053144142e
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30787
|
2
|
1790704840
|
1790704870
|
1790704838
|
1790704870
|
|
0
|
|
0
|
Edit
Delete
|
|
36425
|
24661
|
121
|
5
|
9a22d271d30299b841cf10ab3fd13fb9b80ad52d
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30788
|
2
|
1790706834
|
1790706865
|
1790706834
|
1790706865
|
|
0
|
|
0
|
Edit
Delete
|
|
36426
|
24662
|
121
|
5
|
f1a8d28bca7a42159b14cbdaedf8c7366eac94a3
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30789
|
2
|
1790707011
|
1790707042
|
1790707011
|
1790707042
|
|
0
|
|
0
|
Edit
Delete
|
|
36427
|
24663
|
121
|
5
|
691734908943b30681e8ee6fd13a831559a77f90
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30790
|
2
|
1790708868
|
1790708899
|
1790708867
|
1790708899
|
|
0
|
|
0
|
Edit
Delete
|
|
36428
|
24664
|
121
|
5
|
08ee25840d11be98bf59f94f0e5af109d4f54154
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30791
|
2
|
1790709203
|
1790709233
|
1790709202
|
1790709234
|
|
0
|
|
0
|
Edit
Delete
|
|
36429
|
24665
|
121
|
5
|
907797d2c3dfcdbe5e36aa805f27351dbe3341e9
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30792
|
2
|
1790709394
|
1790709424
|
1790709393
|
1790709425
|
|
0
|
|
0
|
Edit
Delete
|
|
36430
|
24666
|
121
|
5
|
66dd585b50ea50118c84acfb376a659cbe13ece2
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30793
|
2
|
1790709685
|
1790709715
|
1790709684
|
1790709715
|
|
0
|
|
0
|
Edit
Delete
|
|
36431
|
24667
|
121
|
5
|
52c6066b272780512668b1792cda06d4c7d4161a
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30794
|
2
|
1790709945
|
1790709976
|
1790709945
|
1790709976
|
|
0
|
|
0
|
Edit
Delete
|
|
36432
|
24668
|
121
|
5
|
3da56b9cd940e730d60f20634a0ec060c0cab053
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30795
|
2
|
1790710018
|
1790710049
|
1790710017
|
1790710049
|
|
0
|
|
0
|
Edit
Delete
|
|
36433
|
24669
|
121
|
5
|
674f7888c46788fd1fe700e46428ad831b843918
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30796
|
2
|
1790710069
|
1790710100
|
1790710068
|
1790710100
|
|
0
|
|
0
|
Edit
Delete
|
|
36434
|
24670
|
121
|
5
|
1ef1c1e2e752fbce5e22ea1d5a703c74aa43b365
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30797
|
2
|
1790710332
|
1790710362
|
1790710331
|
1790710363
|
|
0
|
|
0
|
Edit
Delete
|
|
36435
|
24671
|
121
|
5
|
7fd3e4f60c59dcf18f9dc7ffa25c09b5bbf1eb92
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30798
|
2
|
1790711139
|
1790711169
|
1790711137
|
1790711169
|
|
0
|
|
0
|
Edit
Delete
|
|
36436
|
24672
|
121
|
5
|
ff106635225e578aa518e953630b6cdf74e6468f
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30799
|
2
|
1790711506
|
1790711536
|
1790711504
|
1790711536
|
|
0
|
|
0
|
Edit
Delete
|
|
36437
|
24673
|
121
|
5
|
7fea3622f7d34b757b3b84a6a07d122a458a82aa
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30800
|
2
|
1790711628
|
1790711659
|
1790711627
|
1790711659
|
|
0
|
|
0
|
Edit
Delete
|
|
36438
|
24674
|
121
|
5
|
2fb32ee378ad3679c15f8321bd8b703a0c96fe15
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30801
|
2
|
1790711941
|
1790711972
|
1790711941
|
1790711972
|
|
0
|
|
0
|
Edit
Delete
|
|
36439
|
24675
|
121
|
5
|
3654c9cb3f8e8dbc89a90ef90ac0873829888414
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30802
|
2
|
1790714849
|
1790714879
|
1790714849
|
1790714879
|
|
0
|
|
0
|
Edit
Delete
|
|
36440
|
24676
|
121
|
5
|
dc6f993749156ec83571a9c49e77a562142b6f14
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30803
|
2
|
1790715137
|
1790715168
|
1790715136
|
1790715168
|
|
0
|
|
0
|
Edit
Delete
|
|
36441
|
24677
|
121
|
5
|
d810bb55a42c9534ea1f0fd5f7976358514403c7
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30804
|
2
|
1790715562
|
1790715593
|
1790715561
|
1790715593
|
|
0
|
|
0
|
Edit
Delete
|
|
36442
|
24678
|
121
|
5
|
332ca07c7e031b3a6aa7e3c50449681f743fff46
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30805
|
2
|
1790715847
|
1790715878
|
1790715846
|
1790715878
|
|
0
|
|
0
|
Edit
Delete
|
|
36443
|
24679
|
121
|
5
|
7b4ee57a5ebc2367e29f490efff07e6353c2c9a2
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30806
|
2
|
1790718120
|
1790718151
|
1790718118
|
1790718151
|
|
0
|
|
0
|
Edit
Delete
|
|
36444
|
24680
|
121
|
5
|
7be74e5dadfcc30f0859135b89be11c3606dd8a1
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30807
|
2
|
1790718395
|
1790718425
|
1790718394
|
1790718426
|
|
0
|
|
0
|
Edit
Delete
|
|
36445
|
24681
|
121
|
5
|
be0b505b7fc4f2826cc81d55891dbf055c4e4952
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30808
|
2
|
1790724034
|
1790724064
|
1790724032
|
1790724064
|
|
0
|
|
0
|
Edit
Delete
|
|
36446
|
24682
|
121
|
5
|
a30eb8f455637fd119fc65c60763a4cfccf7b67e
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30809
|
2
|
1790724153
|
1790724183
|
1790724151
|
1790724183
|
|
0
|
|
0
|
Edit
Delete
|
|
36447
|
24683
|
121
|
5
|
f15d0ba44dbc24265c6562733afb73688846dd2a
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30810
|
2
|
1790724211
|
1790724242
|
1790724210
|
1790724242
|
|
0
|
|
0
|
Edit
Delete
|
|
36448
|
24684
|
121
|
5
|
9cc65b89600e965b8bc07fe20c97b62994e0734c
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30811
|
2
|
1790724698
|
1790724729
|
1790724697
|
1790724729
|
|
0
|
|
0
|
Edit
Delete
|
|
36449
|
24685
|
121
|
5
|
950ad3a0d628572150c9fc517d872f0a49e56a06
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
node -e "if (Number(process.versions.node.split('.')[0]) !== 22) process.exit(1)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30812
|
2
|
1790724963
|
1790724968
|
1790724963
|
1790724968
|
|
0
|
|
0
|
Edit
Delete
|
|
36450
|
24686
|
121
|
5
|
b7c32eeb3ea9f76fb999be97d16c5398791fbc53
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) !== 22) { console.error('Node.js 22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30813
|
2
|
1790725044
|
1790725049
|
1790725044
|
1790725049
|
|
0
|
|
0
|
Edit
Delete
|
|
36451
|
24687
|
121
|
5
|
643e66dc473e76639b1e1979310f1cf8ea5a0170
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) < 22) { console.error('Node.js >=22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30814
|
2
|
1790725280
|
1790725677
|
1790725279
|
1790725677
|
|
0
|
|
0
|
Edit
Delete
|