Repository navigation
201 lines (189 loc) · 10.4 KB
/
Copy pathintegration-prisma-next.yml
File metadata and controls
201 lines (189 loc) · 10.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
name: Integration — prisma-next (EQL v3)
# Real ZeroKMS ciphertext against a real Postgres, on BOTH database variants —
# the prisma-next leg of the shared test-kit family driver (the same catalog,
# oracle, and single-vs-bulk crossover as the Drizzle and Supabase jobs).
#
# The prisma-next adapter talks straight to the database, so it does not need
# PostgREST — but it does need to work on managed Postgres, where the `postgres`
# role is not a superuser, the EQL install takes its self-skipping path, and the
# ORE domains cannot hold data. The Supabase compose file brings up PostgREST
# too; this job simply ignores it.
#
# Separate from `tests.yml` on purpose: these suites need CipherStash credentials
# and a database, and they THROW rather than skip when unconfigured. Keeping them
# out of the unit job is what lets `pnpm test` stay runnable with neither.
on:
push:
branches: [main]
paths:
- 'languages/typescript/packages/stack/src/eql/v3/**'
- 'languages/typescript/packages/stack-prisma/**'
# Source layers the adapter's encoding/round-trip rests on: a break here
# (not just under src/eql/v3) can produce wrong rows, so trigger the live
# suite that would catch it.
- 'languages/typescript/packages/stack/src/encryption/**'
- 'languages/typescript/packages/stack/src/schema/**'
- 'languages/typescript/packages/test-kit/**'
- 'languages/typescript/packages/cli/src/installer/**'
- 'local/docker-compose.postgres.yml'
- 'local/docker-compose.supabase.yml'
- 'local/supabase-init.sql'
- '.github/workflows/integration-prisma-next.yml'
- '.github/actions/integration-setup/**'
- '.github/actions/integration-db/**'
- '.github/actions/build-ffi-binding/**'
- '.github/actions/build-auth-binding/**'
# The Rust that produces every EQL payload these suites round-trip.
# Absorbing protect-ffi put it in-tree, so a crate change can now
# break them in a PR that touches no TypeScript at all.
#
# The manifests are here for the same reason as the sources: a
# dependency bump in Cargo.lock changes the compiled encryption core
# without touching a .rs file, and package.json / mise.toml carry the
# build scripts and the toolchain pin. Matching the filter in
# tests-rust.yml, which already covers all four.
- 'languages/typescript/packages/protect-ffi/crates/**'
- 'languages/typescript/packages/protect-ffi/src/**'
- 'languages/typescript/packages/protect-ffi/Cargo.toml'
- 'languages/typescript/packages/protect-ffi/Cargo.lock'
- 'languages/typescript/packages/protect-ffi/package.json'
- 'languages/typescript/packages/protect-ffi/mise.toml'
# Out of that package, and a compile input all the same: the cdylib
# crate carries
# `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the
# EQL wire types are linked into the `index.node` this job encrypts
# through. The native cache key in `.github/actions/build-ffi-binding`
# hashes both, so an edit here misses that cache and the binding gets
# rebuilt — correctly. Without these two entries the miss never happens,
# because the workflow does not trigger at all: a payload-encoding change
# under packages/eql/crates merges with this suite green by absence.
# Pinned by scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs.
- 'packages/eql/crates/**'
- 'packages/eql/Cargo.toml'
pull_request:
branches: ['**']
# Repeated verbatim: GitHub Actions does not support YAML anchors/aliases.
paths:
- 'languages/typescript/packages/stack/src/eql/v3/**'
- 'languages/typescript/packages/stack-prisma/**'
# Source layers the adapter's encoding/round-trip rests on: a break here
# (not just under src/eql/v3) can produce wrong rows, so trigger the live
# suite that would catch it.
- 'languages/typescript/packages/stack/src/encryption/**'
- 'languages/typescript/packages/stack/src/schema/**'
- 'languages/typescript/packages/test-kit/**'
- 'languages/typescript/packages/cli/src/installer/**'
- 'local/docker-compose.postgres.yml'
- 'local/docker-compose.supabase.yml'
- 'local/supabase-init.sql'
- '.github/workflows/integration-prisma-next.yml'
- '.github/actions/integration-setup/**'
- '.github/actions/integration-db/**'
- '.github/actions/build-ffi-binding/**'
- '.github/actions/build-auth-binding/**'
# The Rust that produces every EQL payload these suites round-trip.
# Absorbing protect-ffi put it in-tree, so a crate change can now
# break them in a PR that touches no TypeScript at all.
#
# The manifests are here for the same reason as the sources: a
# dependency bump in Cargo.lock changes the compiled encryption core
# without touching a .rs file, and package.json / mise.toml carry the
# build scripts and the toolchain pin. Matching the filter in
# tests-rust.yml, which already covers all four.
- 'languages/typescript/packages/protect-ffi/crates/**'
- 'languages/typescript/packages/protect-ffi/src/**'
- 'languages/typescript/packages/protect-ffi/Cargo.toml'
- 'languages/typescript/packages/protect-ffi/Cargo.lock'
- 'languages/typescript/packages/protect-ffi/package.json'
- 'languages/typescript/packages/protect-ffi/mise.toml'
# Out of that package, and a compile input all the same: the cdylib
# crate carries
# `eql-bindings = { path = "../../../../../../packages/eql/crates/eql-bindings" }`, so the
# EQL wire types are linked into the `index.node` this job encrypts
# through. The native cache key in `.github/actions/build-ffi-binding`
# hashes both, so an edit here misses that cache and the binding gets
# rebuilt — correctly. Without these two entries the miss never happens,
# because the workflow does not trigger at all: a payload-encoding change
# under packages/eql/crates merges with this suite green by absence.
# Pinned by scripts/__tests__/wasm-build-inputs-paths-filter.test.mjs.
- 'packages/eql/crates/**'
- 'packages/eql/Cargo.toml'
jobs:
integration:
name: prisma-next v3 integration (db=${{ matrix.db }})
runs-on: blacksmith-4vcpu-ubuntu-2404
# No concurrency group: `integration-db` gives each job its own compose
# project and ephemeral host ports, so live-DB jobs no longer contend and do
# not need serialising. See that action for why the old
# `integration-live-db-<db>` group had to go (it cancelled a third
# contender rather than queueing it).
#
# Fork PRs have no secrets. Skip cleanly rather than fail on something the
# contributor cannot fix — `tests.yml` still gives them a green signal.
# Every OTHER event runs, which is why this gates on "not a fork PR" rather
# than listing the event names allowed through: the listing form skipped
# the job on `workflow_dispatch` in integration-protect-ffi.yml, making a
# declared manual trigger do nothing. Enforced by
# scripts/__tests__/workflow-dispatch-job-conditions.test.mjs.
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
strategy:
fail-fast: false
# prisma-next talks straight to Postgres, so it runs against BOTH
# databases. The Supabase variant is not a formality: its `postgres` role
# is not a superuser, so the EQL install takes its self-skipping path. A
# suite that passes on a superuser database can still fail there.
matrix:
db: [postgres, supabase]
env:
CS_WORKSPACE_CRN: ${{ vars.CS_WORKSPACE_CRN }}
CS_CLIENT_ID: ${{ vars.CS_CLIENT_ID }}
CS_CLIENT_KEY: ${{ secrets.CS_CLIENT_KEY }}
CS_CLIENT_ACCESS_KEY: ${{ secrets.CS_CLIENT_ACCESS_KEY }}
# EXPLICIT, never inferred — same rationale as the Drizzle workflow.
CS_IT_DB_VARIANT: ${{ matrix.db }}
steps:
- uses: actions/checkout@v6
- uses: ./.github/actions/integration-setup
# Fast pre-flight: fail in seconds if a secret was rotated or cleared,
# before the binding build and the docker pull. The in-test
# `requireIntegrationEnv` is the correctness guarantee; this is the cheap
# one, so nothing expensive may be ordered ahead of it.
- name: Require CipherStash secrets
uses: ./.github/actions/require-cs-secrets
with:
workspace-crn: ${{ vars.CS_WORKSPACE_CRN }}
client-id: ${{ vars.CS_CLIENT_ID }}
client-key: ${{ secrets.CS_CLIENT_KEY }}
client-access-key: ${{ secrets.CS_CLIENT_ACCESS_KEY }}
# No `wasm: true` — the prisma-next family suites go through the native
# binding only.
- name: Build the protect-ffi binding
uses: ./.github/actions/build-ffi-binding
- name: Build the @cipherstash/auth binding
uses: ./.github/actions/build-auth-binding
# No pre-`up` cleanup step any more: the project name is unique per job, so
# a container leaked by a hard-killed prior run cannot hold this job's
# name or its (ephemeral) port. Blanket-pruning would now be actively
# unsafe — without the concurrency group, another job's stack may be live
# on this runner.
- name: Start ${{ matrix.db }}
id: db
uses: ./.github/actions/integration-db
with:
db: ${{ matrix.db }}
# `globalSetup` installs EQL v3 by shelling out to the real
# `stash eql install --eql-version 3`, so an installer regression fails
# here rather than hiding behind a test-only SQL apply.
- name: prisma-next v3 family suites
run: pnpm exec turbo run test:integration --filter @cipherstash/stack-prisma --env-mode=loose
env:
# Step env, not a `.env` file: `dotenv/config` does not override an
# already-set `process.env`, so these win and no secret hits disk.
DATABASE_URL: ${{ steps.db.outputs.database-url }}
PGRST_URL: ${{ steps.db.outputs.pgrest-url }}
# Guarded on the project being set: if the stack never came up, there is
# nothing to tear down and an unguarded `-p ""` would fail the job with a
# confusing error that masks the real one.
- name: Stop ${{ matrix.db }}
if: always() && env.CS_COMPOSE_PROJECT != ''
run: docker compose -p "$CS_COMPOSE_PROJECT" -f "$CS_COMPOSE_FILE" down -v