|
36419
|
24655
|
121
|
5
|
bc4d59f2822b56e8b97570d25cfd4d8b61cdde12
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30782
|
2
|
1790701881
|
1790701895
|
1790701880
|
1790701895
|
|
0
|
|
0
|
Edit
Delete
|
|
36420
|
24656
|
121
|
5
|
8bb41429437f46d37678921b75ffcaff1ed78841
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Use Node.js 22
uses: https://gitea.com/actions/setup-node@v4
with:
node-version: "22"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import { readFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const port = Number(process.env.CI_POSTGRES_PORT);
if (!Number.isInteger(port) || port < 1 || port > 65535) {
throw new Error('PostgreSQL service did not publish a valid port');
}
const defaultRoute = readFileSync('/proc/net/route', 'utf8').split('\n').find((line) => line.split('\t')[1] === '00000000');
const gatewayHex = defaultRoute?.split('\t')[2];
const gateway = gatewayHex && gatewayHex.length === 8
? gatewayHex.match(/../g).reverse().map((part) => parseInt(part, 16)).join('.')
: null;
const hosts = ['127.0.0.1', 'host.docker.internal', gateway].filter(Boolean);
let admin;
let client;
for (const host of hosts) {
const candidate = new URL(`postgres://postgres@${host}:${port}/enterprise_reality_kernel`);
candidate.password = process.env.CI_ADMIN_PASSWORD;
const probe = new pg.Client({ connectionString: candidate.href, connectionTimeoutMillis: 2000 });
try {
await probe.connect();
const identity = await probe.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
admin = candidate;
client = probe;
break;
} catch {
await probe.end().catch(() => {});
}
}
if (!admin || !client) throw new Error('Disposable PostgreSQL service is unreachable from this runner');
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
CI_POSTGRES_PORT: '55432'
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
ports:
- 55432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30783
|
2
|
1790702047
|
1790702061
|
1790702045
|
1790702062
|
|
0
|
|
0
|
Edit
Delete
|
|
36421
|
24657
|
121
|
5
|
21d073490c60bb141a267af9424b9f0ef7c3440d
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30784
|
2
|
1790702130
|
1790702160
|
1790702129
|
1790702161
|
|
0
|
|
0
|
Edit
Delete
|
|
36422
|
24658
|
121
|
5
|
5f607eb22a5ef160fdc74423910299d135063168
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30785
|
2
|
1790704681
|
1790704711
|
1790704679
|
1790704711
|
|
0
|
|
0
|
Edit
Delete
|
|
36423
|
24659
|
121
|
5
|
236c67c85b0ed28961bd3807befc1c00d6573f6b
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30786
|
2
|
1790704736
|
1790704736
|
1790704735
|
1790704736
|
|
0
|
|
0
|
Edit
Delete
|
|
36424
|
24660
|
121
|
5
|
fde5331617b33e7df7ff5c3b2893c2053144142e
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30787
|
2
|
1790704840
|
1790704870
|
1790704838
|
1790704870
|
|
0
|
|
0
|
Edit
Delete
|
|
36425
|
24661
|
121
|
5
|
9a22d271d30299b841cf10ab3fd13fb9b80ad52d
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30788
|
2
|
1790706834
|
1790706865
|
1790706834
|
1790706865
|
|
0
|
|
0
|
Edit
Delete
|
|
36426
|
24662
|
121
|
5
|
f1a8d28bca7a42159b14cbdaedf8c7366eac94a3
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30789
|
2
|
1790707011
|
1790707042
|
1790707011
|
1790707042
|
|
0
|
|
0
|
Edit
Delete
|
|
36427
|
24663
|
121
|
5
|
691734908943b30681e8ee6fd13a831559a77f90
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30790
|
2
|
1790708868
|
1790708899
|
1790708867
|
1790708899
|
|
0
|
|
0
|
Edit
Delete
|
|
36428
|
24664
|
121
|
5
|
08ee25840d11be98bf59f94f0e5af109d4f54154
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30791
|
2
|
1790709203
|
1790709233
|
1790709202
|
1790709234
|
|
0
|
|
0
|
Edit
Delete
|
|
36429
|
24665
|
121
|
5
|
907797d2c3dfcdbe5e36aa805f27351dbe3341e9
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30792
|
2
|
1790709394
|
1790709424
|
1790709393
|
1790709425
|
|
0
|
|
0
|
Edit
Delete
|
|
36430
|
24666
|
121
|
5
|
66dd585b50ea50118c84acfb376a659cbe13ece2
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30793
|
2
|
1790709685
|
1790709715
|
1790709684
|
1790709715
|
|
0
|
|
0
|
Edit
Delete
|
|
36431
|
24667
|
121
|
5
|
52c6066b272780512668b1792cda06d4c7d4161a
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30794
|
2
|
1790709945
|
1790709976
|
1790709945
|
1790709976
|
|
0
|
|
0
|
Edit
Delete
|
|
36432
|
24668
|
121
|
5
|
3da56b9cd940e730d60f20634a0ec060c0cab053
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30795
|
2
|
1790710018
|
1790710049
|
1790710017
|
1790710049
|
|
0
|
|
0
|
Edit
Delete
|
|
36433
|
24669
|
121
|
5
|
674f7888c46788fd1fe700e46428ad831b843918
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30796
|
2
|
1790710069
|
1790710100
|
1790710068
|
1790710100
|
|
0
|
|
0
|
Edit
Delete
|
|
36434
|
24670
|
121
|
5
|
1ef1c1e2e752fbce5e22ea1d5a703c74aa43b365
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30797
|
2
|
1790710332
|
1790710362
|
1790710331
|
1790710363
|
|
0
|
|
0
|
Edit
Delete
|
|
36435
|
24671
|
121
|
5
|
7fd3e4f60c59dcf18f9dc7ffa25c09b5bbf1eb92
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30798
|
2
|
1790711139
|
1790711169
|
1790711137
|
1790711169
|
|
0
|
|
0
|
Edit
Delete
|
|
36436
|
24672
|
121
|
5
|
ff106635225e578aa518e953630b6cdf74e6468f
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30799
|
2
|
1790711506
|
1790711536
|
1790711504
|
1790711536
|
|
0
|
|
0
|
Edit
Delete
|
|
36437
|
24673
|
121
|
5
|
7fea3622f7d34b757b3b84a6a07d122a458a82aa
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30800
|
2
|
1790711628
|
1790711659
|
1790711627
|
1790711659
|
|
0
|
|
0
|
Edit
Delete
|
|
36438
|
24674
|
121
|
5
|
2fb32ee378ad3679c15f8321bd8b703a0c96fe15
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30801
|
2
|
1790711941
|
1790711972
|
1790711941
|
1790711972
|
|
0
|
|
0
|
Edit
Delete
|
|
36439
|
24675
|
121
|
5
|
3654c9cb3f8e8dbc89a90ef90ac0873829888414
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30802
|
2
|
1790714849
|
1790714879
|
1790714849
|
1790714879
|
|
0
|
|
0
|
Edit
Delete
|
|
36440
|
24676
|
121
|
5
|
dc6f993749156ec83571a9c49e77a562142b6f14
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30803
|
2
|
1790715137
|
1790715168
|
1790715136
|
1790715168
|
|
0
|
|
0
|
Edit
Delete
|
|
36441
|
24677
|
121
|
5
|
d810bb55a42c9534ea1f0fd5f7976358514403c7
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30804
|
2
|
1790715562
|
1790715593
|
1790715561
|
1790715593
|
|
0
|
|
0
|
Edit
Delete
|
|
36442
|
24678
|
121
|
5
|
332ca07c7e031b3a6aa7e3c50449681f743fff46
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30805
|
2
|
1790715847
|
1790715878
|
1790715846
|
1790715878
|
|
0
|
|
0
|
Edit
Delete
|
|
36443
|
24679
|
121
|
5
|
7b4ee57a5ebc2367e29f490efff07e6353c2c9a2
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30806
|
2
|
1790718120
|
1790718151
|
1790718118
|
1790718151
|
|
0
|
|
0
|
Edit
Delete
|
|
36444
|
24680
|
121
|
5
|
7be74e5dadfcc30f0859135b89be11c3606dd8a1
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30807
|
2
|
1790718395
|
1790718425
|
1790718394
|
1790718426
|
|
0
|
|
0
|
Edit
Delete
|
|
36445
|
24681
|
121
|
5
|
be0b505b7fc4f2826cc81d55891dbf055c4e4952
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30808
|
2
|
1790724034
|
1790724064
|
1790724032
|
1790724064
|
|
0
|
|
0
|
Edit
Delete
|
|
36446
|
24682
|
121
|
5
|
a30eb8f455637fd119fc65c60763a4cfccf7b67e
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30809
|
2
|
1790724153
|
1790724183
|
1790724151
|
1790724183
|
|
0
|
|
0
|
Edit
Delete
|
|
36447
|
24683
|
121
|
5
|
f15d0ba44dbc24265c6562733afb73688846dd2a
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30810
|
2
|
1790724211
|
1790724242
|
1790724210
|
1790724242
|
|
0
|
|
0
|
Edit
Delete
|
|
36448
|
24684
|
121
|
5
|
9cc65b89600e965b8bc07fe20c97b62994e0734c
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Install locked dependencies
run: |
set -eu
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm install --frozen-lockfile
- name: Check documentation claims
run: node scripts/check-doc-claims.js
- name: Check invariants
run: node scripts/check-invariants.js
- name: Check module boundaries
run: node scripts/check-module-boundaries.js
- name: Check model
run: node scripts/check-model.js
- name: Check spec source
run: node scripts/check-spec-source.js
- name: Check full spec
run: node scripts/check-full-spec.js
- name: Check cross-owner write exceptions
run: node scripts/check-cross-owner-writes.js
- name: Check plan ledger against Git history
run: pnpm check:plan-ledger
- name: Configure isolated database roles
run: |
set -eu
node --input-type=module <<'NODE'
import { randomBytes } from 'node:crypto';
import { appendFileSync } from 'node:fs';
import pg from 'pg';
const runtimePassword = randomBytes(24).toString('hex');
const tokenSecret = randomBytes(32).toString('hex');
const migrationTestDatabase = `erk_migration_test_${randomBytes(6).toString('hex')}`;
const admin = new URL('postgres://postgres@postgres:5432/enterprise_reality_kernel');
admin.password = process.env.CI_ADMIN_PASSWORD;
const client = new pg.Client({ connectionString: admin.href, connectionTimeoutMillis: 3000 });
await client.connect();
const runtime = new URL(admin.href);
runtime.username = 'erk_app';
runtime.password = runtimePassword;
try {
const identity = await client.query('SELECT current_database() AS name, current_user AS role');
if (identity.rows[0]?.name !== 'enterprise_reality_kernel' || identity.rows[0]?.role !== 'postgres') {
throw new Error('Unexpected PostgreSQL service identity');
}
await client.query(`CREATE DATABASE ${migrationTestDatabase}`);
} finally {
await client.end();
}
const migrationTest = new URL(admin.href);
migrationTest.pathname = `/${migrationTestDatabase}`;
appendFileSync(process.env.GITHUB_ENV, [
`MIGRATION_DATABASE_URL=${admin.href}`,
`MIGRATION_TEST_DATABASE_URL=${migrationTest.href}`,
`DATABASE_URL=${runtime.href}`,
`TEST_DATABASE_URL=${runtime.href}`,
`RUNTIME_DB_PASSWORD=${runtimePassword}`,
`KERNEL_TOKEN_SECRET=${tokenSecret}`
].join('\n') + '\n');
NODE
env:
CI_ADMIN_PASSWORD: erk_ci_disposable_admin
- name: Migrate as postgres owner
run: pnpm db:migrate
- name: Test as restricted erk_app
run: pnpm test
- name: Check database roles and cross-owner references
run: |
set -eu
pnpm check:db-roles
pnpm check:cross-refs
pnpm check:cross-fks
- name: Check event histories
run: |
set -eu
pnpm check:all-events
pnpm check:integration-events
pnpm check:external-sales-order-history
pnpm check:schedule-history
pnpm check:trigger-condition-history
pnpm check:trigger-authorization-history
pnpm check:trigger-state-history
- name: Check partitions and audit chain
run: |
set -eu
pnpm check:partition-identities
pnpm check:partition-references
pnpm check:partition-horizon
pnpm check:partition-cutover
pnpm check:audit-chain
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: enterprise_reality_kernel
POSTGRES_PASSWORD: erk_ci_disposable_admin
POSTGRES_USER: postgres
options: --health-cmd "pg_isready -U postgres -d enterprise_reality_kernel" --health-interval 2s --health-timeout 3s --health-retries 30
container: node:22-bookworm
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30811
|
2
|
1790724698
|
1790724729
|
1790724697
|
1790724729
|
|
0
|
|
0
|
Edit
Delete
|
|
36449
|
24685
|
121
|
5
|
950ad3a0d628572150c9fc517d872f0a49e56a06
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
node -e "if (Number(process.versions.node.split('.')[0]) !== 22) process.exit(1)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30812
|
2
|
1790724963
|
1790724968
|
1790724963
|
1790724968
|
|
0
|
|
0
|
Edit
Delete
|
|
36450
|
24686
|
121
|
5
|
b7c32eeb3ea9f76fb999be97d16c5398791fbc53
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) !== 22) { console.error('Node.js 22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30813
|
2
|
1790725044
|
1790725049
|
1790725044
|
1790725049
|
|
0
|
|
0
|
Edit
Delete
|
|
36451
|
24687
|
121
|
5
|
643e66dc473e76639b1e1979310f1cf8ea5a0170
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) < 22) { console.error('Node.js >=22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30814
|
2
|
1790725280
|
1790725677
|
1790725279
|
1790725677
|
|
0
|
|
0
|
Edit
Delete
|
|
36467
|
24703
|
121
|
5
|
4ee009dc47250ce356a6d2116465fdcc3f5967d7
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) < 22) { console.error('Node.js >=22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
30830
|
2
|
1790734106
|
1790734532
|
1790733259
|
1790734532
|
|
0
|
|
0
|
Edit
Delete
|
|
36493
|
24729
|
117
|
5
|
98467cbc83c7415b6fe7d8fa0ee96786ed288edf
|
0
|
Governance tests (report-only until act_runner is Governance tests (report-only until act_runner is enabled)...
|
1
|
name: Governance
"on":
push:
b name: Governance
"on":
push:
branches: [main]
pull_request:
workflow_dispatch:
env:
FOUNDATION_REPORT_DIR: ${{ runner.temp }}/foundation-reports
PNPM_VERSION: 9.15.9
jobs:
governance-tests:
name: Governance tests (report-only until act_runner is enabled)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "22"
- name: Governance tests
run: pnpm --dir 平台治理/基础 test
continue-on-error: true
- name: Governance gates (all gates run to completion; not blocking yet)
run: pnpm --dir 平台治理/基础 check
continue-on-error: true
- name: Tracked-secrets gate (root scope; the only gate whose CI result is meaningful without nested repos)
run: node 平台治理/基础/scripts/check-tracked-secrets.mjs --scope=root
timeout-minutes: "20"
permissions:
contents: read
...
|
governance-tests
|
null
|
["ubuntu-latest"]
|
30856
|
2
|
1790749001
|
1790749024
|
1790748285
|
1790749025
|
|
0
|
|
0
|
Edit
Delete
|
|
36495
|
24730
|
116
|
5
|
745d6a97cc8ddaa8c27f6b7013faf92a0dbe4172
|
0
|
Static governance (repo root, private packages)
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
static:
name: Static governance (repo root, private packages)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: runtime/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install runtime workspace (frozen lockfile)
run: pnpm --dir runtime install --frozen-lockfile
- name: Install contracts dependencies (public npm only, frozen lockfile; CT-1 build / validators / generated-types check)
run: pnpm --dir contracts install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm --dir runtime prisma:generate
- name: Build runtime modules (fixture suites evaluate migrated rules from dist)
run: pnpm runtime:build:modules
- name: Repo-root governance gate
run: pnpm check
- name: Source tree must stay clean apart from latest reports (no tracked .npmrc mutation)
run: |
git status --porcelain | grep -vE '\.latest\.json$' && { echo "::error::静态门禁修改了报告以外的跟踪文件"; exit 1; } || echo "clean apart from latest reports"
- if: always()
name: Upload static evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-static-${{ env.CANDIDATE_TAG }}
path: |
reports/*.latest.json
runtime/reports/*.latest.json
!runtime/reports/runtime-acceptance.latest.json
!runtime/reports/conformance-differential.latest.json
!runtime/reports/ui-acceptance.latest.json
retention-days: "30"
timeout-minutes: "30"
permissions:
contents: read
...
|
static
|
null
|
["ubuntu-latest"]
|
30858
|
2
|
1790749064
|
1790749076
|
1790748286
|
1790749076
|
|
0
|
|
0
|
Edit
Delete
|
|
36501
|
24730
|
116
|
5
|
745d6a97cc8ddaa8c27f6b7013faf92a0dbe4172
|
0
|
Release candidate verification + manifest
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
candidate:
name: Release candidate verification + manifest
runs-on: ubuntu-latest
if: always()
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Download static evidence
uses: actions/download-artifact@v3
with:
name: platform-static-${{ env.CANDIDATE_TAG }}
path: candidate/static
continue-on-error: true
- name: Download runtime evidence
uses: actions/download-artifact@v3
with:
name: platform-runtime-${{ env.CANDIDATE_TAG }}
path: candidate/runtime/runtime/reports
continue-on-error: true
- name: Download identity evidence
uses: actions/download-artifact@v3
with:
name: platform-identity-${{ env.CANDIDATE_TAG }}
path: candidate/identity/identity/reports
continue-on-error: true
- name: Download port-conformance evidence
uses: actions/download-artifact@v3
with:
name: platform-port-conformance-${{ env.CANDIDATE_TAG }}
path: candidate/port-conformance/reports
continue-on-error: true
- id: verify
name: Verify candidate (per-report sourceSha / dirty / status / digest; missing → ineligible)
run: node governance/verify-candidate.mjs --candidate candidate --sha "${{ github.sha }}" --run-id "${{ github.run_id }}" --attempt "${{ github.run_attempt }}" --out reports/release-candidate.latest.json
continue-on-error: true
- name: Download image and full SBOM evidence for the same candidate
uses: actions/download-artifact@v3
with:
name: platform-image-${{ env.CANDIDATE_TAG }}
path: reports
- name: Release Manifest (known facts, status partial until all deliverables exist)
run: node governance/release-manifest.mjs
- if: always()
name: Upload candidate evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: error
name: platform-candidate-${{ env.CANDIDATE_TAG }}
path: |
reports/release-candidate.latest.json
reports/release-manifest.latest.json
retention-days: "30"
- if: always()
name: Propagate upstream results and candidate eligibility
run: |
echo "public-static=${{ needs.public-static.result }} static=${{ needs.static.result }} runtime=${{ needs.runtime.result }} identity=${{ needs.identity.result }} verify=${{ steps.verify.outcome }}"
test "${{ needs.public-static.result }}" = "success"
test "${{ needs.static.result }}" = "success"
test "${{ needs.unit.result }}" = "success"
test "${{ needs.port-conformance.result }}" = "success"
test "${{ needs.runtime.result }}" = "success"
test "${{ needs.identity.result }}" = "success"
test "${{ needs.image.result }}" = "success"
test "${{ steps.verify.outcome }}" = "success"
timeout-minutes: "10"
permissions:
contents: read
...
|
candidate
|
["public-static","static","uni ["public-static","static","unit","port-conformance","runtime","identity","image"]...
|
["ubuntu-latest"]
|
30871
|
2
|
1790752719
|
1790752737
|
1790748286
|
1790752737
|
|
1
|
|
0
|
Edit
Delete
|
|
16
|
15
|
2
|
2
|
061edb11a5fd660934c3b57491d585077b3805cf
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: self-hosted
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["self-hosted"]
|
0
|
3
|
0
|
1770875534
|
1770874771
|
1770875534
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
17
|
16
|
2
|
2
|
062acdd73d520de0360ff9d9158e60f202a02578
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["gitea.g-hi.com/zhangjunnan/gitea-runner:node ["gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1"]...
|
0
|
3
|
0
|
1770877321
|
1770877295
|
1770877321
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
18
|
17
|
2
|
2
|
5bb99418afc48f8e77d3cdb4edd9fa1390476c57
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["gitea.g-hi.com/zhangjunnan/gitea-runner:node ["gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1"]...
|
0
|
3
|
0
|
1770877939
|
1770877350
|
1770877939
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
19
|
18
|
2
|
2
|
fbac0054c597227db514fa1c6581f5e9002a4c84
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["gitea.g-hi.com/zhangjunnan/gitea-runner:node ["gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1"]...
|
0
|
3
|
0
|
1770878173
|
1770878076
|
1770878173
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
20
|
19
|
2
|
2
|
b277cb95b0e9e11aded5a72555e5bfe6066bd7b5
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["gitea.g-hi.com/zhangjunnan/gitea-runner:node ["gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1"]...
|
0
|
3
|
0
|
1770878314
|
1770878195
|
1770878314
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
21
|
20
|
2
|
2
|
22ffb09cf279f85db485e386b24c7d3a1cdda4e6
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: docker://gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["docker://gitea.g-hi.com/zhangjunnan/gitea-ru ["docker://gitea.g-hi.com/zhangjunnan/gitea-runner:node20-rsync-v1"]...
|
0
|
3
|
0
|
1770878361
|
1770878332
|
1770878361
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
24
|
23
|
2
|
2
|
2ac24ff0484bc4a60c5bfed9495a83a4e337f27b
|
0
|
deploy
|
0
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: ubuntu-latest
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file
run: |
echo "$RSYNC_PASSWORD" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
env:
RSYNC_PASSWORD: ${{ secrets.TEST_RSYNC_SECRETS }}
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n /usr/bin/rsync -avz --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n \n /usr/bin/rsync -avz --relative \\\n --files-from=/tmp/changed.txt \\\n --password-file=/tmp/rsync.pass \\\n ./ \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: ${{ secrets.TEST_RSYNC_HOST }}
RSYNC_USER: ${{ secrets.TEST_RSYNC_USER }}
RSYNC_MODULE: ftp
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1770884630
|
1770882563
|
1770884630
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
38
|
37
|
2
|
2
|
359a23bb2b3c088576051d47f237505eaa12d9e9
|
0
|
deploy
|
1
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: ubuntu-latest
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file (HARDCODED for test)
run: |
echo "m9QNiLJ8LIqBozXwmsoKdNXa23xia34R" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
echo "✅ /tmp/rsync.pass created with password 'm9QNiLJ8LIqBozXwmsoKdNXa23xia34R'"
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n /usr/bin/rsync -avz --no-owner --no-group --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n . \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n echo \"Total changed files: $(wc -l < /tmp/changed.txt)\"\n\n # ✅ 关键修复:去掉 --relative\n /usr/bin/rsync -avz --no-owner --no-group \\\n --files-from=/tmp/changed.txt \\\n . \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: "172.17.70.241"
RSYNC_USER: "ahead_rsync_user"
RSYNC_MODULE: "ftp"
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["ubuntu-latest"]
|
30
|
3
|
1770890490
|
1770890599
|
1770890489
|
1770890599
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
39
|
38
|
2
|
2
|
8b9043cb7c726e4e59948720bb4009d9c10c8041
|
0
|
deploy
|
1
|
name: Smart Deploy via Rsync Daemon
"on": name: Smart Deploy via Rsync Daemon
"on": [push]
jobs:
deploy:
name: deploy
runs-on: ubuntu-latest
steps:
- name: Checkout code manually
run: |
# 调试输出
echo "GITEA_HOST: $GITEA_HOST"
echo "GITHUB_REPOSITORY: ${{ github.repository }}"
echo "GITHUB_SHA: ${{ github.sha }}"
if [ -z "$GITEA_HOST" ]; then
echo "❌ GITEA_HOST secret is missing!"
exit 1
fi
# 使用 github 上下文变量
REPO="${{ github.repository }}"
SHA="${{ github.sha }}"
if [ -z "$REPO" ] || [ -z "$SHA" ]; then
echo "❌ Missing GITHUB_REPOSITORY or GITHUB_SHA"
exit 1
fi
REPO_URL="https://${GITEA_TOKEN}@${GITEA_HOST}/${REPO}.git"
echo "Cloning from: ${REPO_URL//${GITEA_TOKEN}/***REDACTED***} (SHA: $SHA)"
git init
git remote add origin "$REPO_URL"
git fetch --depth=1 origin "$SHA"
git checkout "$SHA"
env:
GITEA_HOST: ${{ secrets.GITEAS_HOST }}
GITEA_TOKEN: ${{ secrets.GITEAS_TOKEN }}
- name: Prepare rsync password file (HARDCODED for test)
run: |
echo "m9QNiLJ8LIqBozXwmsoKdNXa23xia34R" > /tmp/rsync.pass
chmod 600 /tmp/rsync.pass
echo "✅ /tmp/rsync.pass created with password 'm9QNiLJ8LIqBozXwmsoKdNXa23xia34R'"
- name: Get commit message and decide sync mode
run: "COMMIT_MSG=$(git log -1 --pretty=%B | head -n1)\necho \"Commit message: $COMMIT_MSG\"\n\nRSYNC_TARGET=\"rsync://${RSYNC_USER}@${RSYNC_HOST}/${RSYNC_MODULE}/\"\n\nif [[ \"$COMMIT_MSG\" == *\"全量同步\"* ]] || [[ \"$COMMIT_MSG\" == *\"full sync\"* ]]; then\n echo \"\U0001F50D Full sync requested...\"\n /usr/bin/rsync -avz --no-owner --no-group --delete \\\n --exclude='.git' \\\n --exclude='.gitea' \\\n --exclude='node_modules/' \\\n --password-file=/tmp/rsync.pass \\\n . \\\n \"$RSYNC_TARGET\"\nelse\n echo \"\U0001F504 Incremental sync...\"\n\n if git rev-parse HEAD~1 >/dev/null 2>&1; then\n git diff --name-only HEAD~1 HEAD > /tmp/changed.txt\n else\n find . -type f -not -path './.git/*' -not -path './.gitea/*' | sed 's|^\\./||' > /tmp/changed.txt\n fi\n\n if [ -s /tmp/changed.txt ]; then\n echo \"Files to sync:\"\n cat /tmp/changed.txt\n echo \"Total changed files: $(wc -l < /tmp/changed.txt)\"\n\n /usr/bin/rsync -avz --no-owner --no-group \\\n --files-from=/tmp/changed.txt \\\n . \\\n \"$RSYNC_TARGET\"\n else\n echo \"✅ No files changed.\"\n fi\nfi\n"
env:
RSYNC_HOST: "172.17.70.241"
RSYNC_USER: "ahead_rsync_user"
RSYNC_MODULE: "ftp"
- if: always()
name: Clean up
run: rm -f /tmp/rsync.pass
...
|
deploy
|
null
|
["ubuntu-latest"]
|
31
|
3
|
1770890621
|
1770890726
|
1770890620
|
1770890726
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
41
|
40
|
6
|
5
|
d169207d2a046f90cf861f8e805b45d3855fddc3
|
0
|
检测代码变更
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main, develop, 'feature/**', 'claude/**']
pull_request:
branches: [main, develop]
env:
NODE_VERSION: "20"
PNPM_VERSION: "8"
jobs:
detect-changes:
name: 检测代码变更
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- id: filter
uses: dorny/paths-filter@v3
with:
filters: |
backend:
- 'backend/**'
- 'shared/**'
frontend:
- 'frontend/**'
- 'shared/**'
mobile:
- 'mobile/**'
- 'shared/**'
shared:
- 'shared/**'
workflows:
- '.github/workflows/**'
outputs:
backend: ${{ steps.filter.outputs.backend }}
frontend: ${{ steps.filter.outputs.frontend }}
mobile: ${{ steps.filter.outputs.mobile }}
shared: ${{ steps.filter.outputs.shared }}
workflows: ${{ steps.filter.outputs.workflows }}
...
|
detect-changes
|
null
|
["ubuntu-latest"]
|
33
|
3
|
1771862353
|
1771862367
|
1771862352
|
1771862367
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
42
|
40
|
6
|
5
|
d169207d2a046f90cf861f8e805b45d3855fddc3
|
0
|
安装依赖
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main, develop, 'feature/**', 'claude/**']
pull_request:
branches: [main, develop]
env:
NODE_VERSION: "20"
PNPM_VERSION: "8"
jobs:
setup:
name: 安装依赖
runs-on: ubuntu-latest
steps:
- name: 检出代码
uses: actions/checkout@v4
- name: 安装 pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ env.PNPM_VERSION }}
- name: 设置 Node.js
uses: actions/setup-node@v4
with:
cache: pnpm
node-version: ${{ env.NODE_VERSION }}
- name: 安装依赖
run: pnpm install --frozen-lockfile
- name: 构建共享包
run: pnpm --filter @juhi/shared run build
- name: 缓存 node_modules
uses: actions/cache/save@v4
with:
key: deps-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
path: |
node_modules
backend/node_modules
frontend/node_modules
mobile/node_modules
shared/node_modules
shared/dist
...
|
setup
|
null
|
["ubuntu-latest"]
|
34
|
3
|
1771862354
|
1771862367
|
1771862352
|
1771862367
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
43
|
40
|
6
|
5
|
d169207d2a046f90cf861f8e805b45d3855fddc3
|
0
|
共享包检查
|
0
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main, develop, 'feature/**', 'claude/**']
pull_request:
branches: [main, develop]
env:
NODE_VERSION: "20"
PNPM_VERSION: "8"
jobs:
shared-check:
name: 共享包检查
runs-on: ubuntu-latest
if: needs.detect-changes.outputs.shared == 'true'
steps:
- uses: actions/checkout@v4
- name: 安装 pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ env.PNPM_VERSION }}
- name: 设置 Node.js
uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
- name: 恢复依赖缓存
uses: actions/cache/restore@v4
with:
key: deps-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
path: |
node_modules
backend/node_modules
frontend/node_modules
mobile/node_modules
shared/node_modules
shared/dist
- name: TypeScript 类型检查
run: pnpm --filter @juhi/shared run build
- name: 验证导出
run: |
cd shared
node -e "import('./dist/index.js').then(m => console.log('✅ 共享包导出验证通过'))"
...
|
shared-check
|
["setup","detect-changes"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1771862367
|
1771862352
|
1771862367
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|
|
44
|
40
|
6
|
5
|
d169207d2a046f90cf861f8e805b45d3855fddc3
|
0
|
后端代码检查
|
0
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main, develop, 'feature/**', 'claude/**']
pull_request:
branches: [main, develop]
env:
NODE_VERSION: "20"
PNPM_VERSION: "8"
jobs:
backend-lint:
name: 后端代码检查
runs-on: ubuntu-latest
if: needs.detect-changes.outputs.backend == 'true'
steps:
- uses: actions/checkout@v4
- name: 安装 pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ env.PNPM_VERSION }}
- name: 设置 Node.js
uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
- name: 恢复依赖缓存
uses: actions/cache/restore@v4
with:
key: deps-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
path: |
node_modules
backend/node_modules
frontend/node_modules
mobile/node_modules
shared/node_modules
shared/dist
- name: 生成 Prisma Client
run: pnpm --filter juhi-api run db:generate
- name: ESLint 检查
run: pnpm --filter juhi-api run lint
- name: TypeScript 类型检查
run: pnpm --filter juhi-api run type-check
...
|
backend-lint
|
["setup","detect-changes"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1771862367
|
1771862352
|
1771862367
|
NULL
|
NULL
|
|
0
|
Edit
Delete
|