From 65e14f5b8c7500a0aee55717011ba62791c07b3a Mon Sep 17 00:00:00 2001 From: Dennis Juhler Aagaard Date: Thu, 24 Sep 2026 19:56:34 +0200 Subject: [PATCH] ci: run validation in pinned container --- .dockerignore | 4 ++++ .gitea/workflows/ci.yml | 20 +++-------------- tests/Dockerfile.ci | 15 +++++++++++++ tests/test_addon_metadata.py | 42 ++++++++++++++++++++++-------------- 4 files changed, 48 insertions(+), 33 deletions(-) create mode 100644 .dockerignore create mode 100644 tests/Dockerfile.ci diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..b67e93e --- /dev/null +++ b/.dockerignore @@ -0,0 +1,4 @@ +.git +.venv +.pytest_cache +**/__pycache__ diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 9a472dd..28ce98e 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -15,24 +15,10 @@ jobs: timeout-minutes: 45 steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 - - name: Install test toolchain - run: | - set -eu - apk add --no-cache curl python3 py3-pip - curl --fail --location --silent --show-error \ - --output /tmp/go1.27.1.linux-amd64.tar.gz \ - https://go.dev/dl/go1.27.1.linux-amd64.tar.gz - echo "63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 /tmp/go1.27.1.linux-amd64.tar.gz" \ - | sha256sum -c - - mkdir -p /opt/go1.27.1 - tar --extract --gzip --file /tmp/go1.27.1.linux-amd64.tar.gz \ - --directory /opt/go1.27.1 --strip-components 1 - ln -sf /opt/go1.27.1/bin/go /usr/local/bin/go - go version - python3 -m venv .venv - .venv/bin/pip install --requirement requirements-dev.txt + - name: Build validation image + run: docker buildx build --platform linux/amd64 --file tests/Dockerfile.ci --load --tag homeassistant-stelloauth-tests:test . - name: Validate metadata, patches, and process manager - run: .venv/bin/pytest -q + run: docker run --rm homeassistant-stelloauth-tests:test -q - name: Build amd64 image run: docker buildx build --platform linux/amd64 --build-arg BUILD_ARCH=amd64 --load --tag homeassistant-stelloauth-addon:test stelloauth - name: Exercise runtime diff --git a/tests/Dockerfile.ci b/tests/Dockerfile.ci new file mode 100644 index 0000000..71c0750 --- /dev/null +++ b/tests/Dockerfile.ci @@ -0,0 +1,15 @@ +FROM golang:1.27.1-bookworm@sha256:69a7b9788769bec032d238959b61854e9ae87f57be9029ec04e9885fabf99195 + +RUN apt-get update \ + && apt-get install --yes --no-install-recommends python3 python3-venv + +WORKDIR /workspace + +COPY requirements-dev.txt ./ +RUN python3 -m venv /opt/venv \ + && /opt/venv/bin/pip install --no-cache-dir --requirement requirements-dev.txt + +COPY . ./ +RUN git init + +ENTRYPOINT ["/opt/venv/bin/pytest"] diff --git a/tests/test_addon_metadata.py b/tests/test_addon_metadata.py index 2323074..d3304ea 100644 --- a/tests/test_addon_metadata.py +++ b/tests/test_addon_metadata.py @@ -173,32 +173,42 @@ def test_ci_builds_and_loads_only_the_amd64_test_image() -> None: assert publication_primitive not in workflow -def test_ci_installs_toolchain_without_hosted_toolcache_actions() -> None: +def test_ci_runs_validation_in_pinned_container() -> None: workflow = (ROOT / ".gitea/workflows/ci.yml").read_text(encoding="utf-8") parsed = yaml.safe_load(workflow) steps = parsed["jobs"]["validate"]["steps"] - setup_command = next( - step["run"] for step in steps if step.get("name") == "Install test toolchain" - ) - assert "actions/setup-python" not in workflow assert "actions/setup-go" not in workflow - for required_command in ( - "apk add --no-cache curl python3 py3-pip", - "go1.27.1.linux-amd64.tar.gz", - "63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445", - "sha256sum -c -", - "python3 -m venv .venv", - ".venv/bin/pip install --requirement requirements-dev.txt", - ): - assert required_command in setup_command - + build_command = next( + step["run"] for step in steps if step.get("name") == "Build validation image" + ) + assert build_command.split() == [ + "docker", + "buildx", + "build", + "--platform", + "linux/amd64", + "--file", + "tests/Dockerfile.ci", + "--load", + "--tag", + "homeassistant-stelloauth-tests:test", + ".", + ] validation_command = next( step["run"] for step in steps if step.get("name") == "Validate metadata, patches, and process manager" ) - assert validation_command == ".venv/bin/pytest -q" + assert validation_command == "docker run --rm homeassistant-stelloauth-tests:test -q" + + dockerfile = (ROOT / "tests/Dockerfile.ci").read_text(encoding="utf-8") + assert ( + "golang:1.27.1-bookworm@sha256:" + "69a7b9788769bec032d238959b61854e9ae87f57be9029ec04e9885fabf99195" + ) in dockerfile + assert "python3 python3-venv" in dockerfile + assert 'ENTRYPOINT ["/opt/venv/bin/pytest"]' in dockerfile def test_patch_payloads_disable_git_whitespace_errors() -> None: