Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
87 changes: 87 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
# Tier 1: runs on every PR and on main. Red blocks merge (XWING-2207 AC#2).
# Mirrors the Makefile so CI and local behave identically.
name: CI

on:
pull_request:
push:
branches: [main]

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: "3.12"
- run: uv sync --frozen
- run: make lint

test:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12"] # 3.11 is the requires-python floor
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: ${{ matrix.python-version }}
- run: uv sync --frozen
- run: make test

postgres:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env:
POSTGRES_USER: traust
POSTGRES_PASSWORD: traust-test-only
POSTGRES_DB: traust_test
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U traust"
--health-interval 5s
--health-timeout 5s
--health-retries 10
env:
# Matches the Makefile default; psycopg (v3) driver.
TRAUST_TEST_DATABASE_URL: postgresql+psycopg://traust:traust-test-only@127.0.0.1:5432/traust_test
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: "3.12"
- run: uv sync --frozen --extra postgres
- run: make test-integration

api-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: "3.12"
- run: uv sync --frozen
# The api-check target is delivered by XWING-2208. Until it lands this is a
# no-op notice rather than a hard failure, and it activates automatically
# once `make api-check` exists.
- name: api-check
run: |
if make -n api-check >/dev/null 2>&1; then
make api-check
else
echo "::notice::'make api-check' not defined yet (XWING-2208) — skipping"
fi
41 changes: 41 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# Tier 2: manual release (XWING-2207 AC#3). Self-versioned — no package index yet.
#
# traust-core is versioned by the VERSION file (kept equal to pyproject.toml) and
# released with the house release.py: test -> `uv build` -> create the vX.Y.Z git
# tag. There is no package index; consumers pin the git tag/rev (as traust-core
# pins traust-contracts today). traust-platform-api.md calls for moving to an
# index so consumers can use `>=` — wire `uv publish` here once that's decided.
#
# To cut a release: bump in a PR (`make bump patch|minor|major`), merge, then run
# this workflow. Default build+tag is local to the run; set push=true to publish
# the tag to origin.
name: Release

on:
workflow_dispatch:
inputs:
push:
description: "Push the vX.Y.Z tag to origin"
type: boolean
default: false

jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # release.py inspects existing tags
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: "3.12"
- run: uv sync --frozen
- name: Release (check + test + build + tag)
run: ./release.py release ${{ inputs.push && '--push' || '' }}
- uses: actions/upload-artifact@v4
with:
name: traust-core-dist
path: dist/*
20 changes: 19 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,11 @@ TRAUST_TEST_DATABASE_URL ?= postgresql+psycopg://$(DB_USER):$(DB_PASSWORD)@127.0
export TRAUST_TEST_DATABASE_URL


.PHONY: help setup sync lint lint-fix test test-integration coverage coverage-html coverage-all db-up db-down
PYTHON ?= python3
RELEASE := ./release.py
BUMP_PARTS := patch minor major

.PHONY: help setup sync lint lint-fix test test-integration coverage coverage-html coverage-all db-up db-down status bump $(BUMP_PARTS)

help:
@echo "Targets ($(notdir $(CURDIR))):"
Expand Down Expand Up @@ -74,3 +78,17 @@ db-up:
db-down:
@podman stop $(DB_CONTAINER) 2>/dev/null || true

status:
$(PYTHON) $(RELEASE) status

$(BUMP_PARTS):
@:

bump:
@part="$(filter $(BUMP_PARTS),$(MAKECMDGOALS))"; \
if [ -z "$$part" ]; then \
echo "usage: make bump patch|minor|major" >&2; \
exit 1; \
fi; \
$(PYTHON) $(RELEASE) bump $$part

1 change: 1 addition & 0 deletions VERSION
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
0.1.0
Loading
Loading