-
Notifications
You must be signed in to change notification settings - Fork 0
144 lines (117 loc) · 3.72 KB
/
ci.yml
File metadata and controls
144 lines (117 loc) · 3.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
name: CI
on:
push:
branches: [main, develop]
pull_request:
branches: [main, develop]
env:
DOTNET_VERSION: '10.0.x'
DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true
DOTNET_CLI_TELEMETRY_OPTOUT: true
jobs:
build:
name: Build & Test
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v4
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Restore dependencies
run: dotnet restore
- name: Build
run: dotnet build --no-restore --configuration Release
- name: Run Unit Tests
run: |
dotnet test tests/OrderMonitor.UnitTests/OrderMonitor.UnitTests.csproj \
--no-build \
--configuration Release \
--logger "trx;LogFileName=unit-test-results.trx" \
--collect:"XPlat Code Coverage" \
--results-directory ./TestResults
- name: Run Integration Tests
run: |
dotnet test tests/OrderMonitor.IntegrationTests/OrderMonitor.IntegrationTests.csproj \
--no-build \
--configuration Release \
--logger "trx;LogFileName=integration-test-results.trx" \
--results-directory ./TestResults
- name: Upload Test Results
uses: actions/upload-artifact@v4
if: always()
with:
name: test-results
path: ./TestResults
retention-days: 7
- name: Upload Coverage Report
uses: actions/upload-artifact@v4
if: always()
with:
name: coverage-report
path: ./TestResults/**/coverage.cobertura.xml
retention-days: 7
- name: Code Coverage Summary
uses: irongut/CodeCoverageSummary@v1.3.0
if: always()
with:
filename: ./TestResults/**/coverage.cobertura.xml
badge: true
format: markdown
output: both
thresholds: '60 80'
lint:
name: Code Analysis
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v4
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Restore dependencies
run: dotnet restore
- name: Run Code Analysis
run: dotnet build --no-restore --configuration Release /p:TreatWarningsAsErrors=false
validate-manifests:
name: Validate K8s Manifests
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Validate YAML syntax
run: |
pip install pyyaml
for f in k8s/base/*.yaml; do
echo "Validating $f..."
python3 -c "import yaml; yaml.safe_load(open('$f'))"
done
- name: Validate Kustomize overlays
run: |
echo "Validating staging overlay..."
kubectl kustomize k8s/overlays/staging > /dev/null
echo "Validating production overlay..."
kubectl kustomize k8s/overlays/production > /dev/null
security:
name: Security Scan
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v4
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Restore dependencies
run: dotnet restore
- name: Run Security Audit
run: dotnet list package --vulnerable --include-transitive 2>&1 | tee security-report.txt
- name: Upload Security Report
uses: actions/upload-artifact@v4
if: always()
with:
name: security-report
path: security-report.txt
retention-days: 7