Files
OpenShell/mise.toml
Jorge e2939b919d feat(e2e): run the Kubernetes e2e suite on cargo-nextest with machine- and human-readable reports (#3344)
* feat(e2e): run kubernetes suite on cargo-nextest with JUnit/HTML reports

Switch e2e:kubernetes (and all its variants) from `cargo test` to
`cargo nextest run` for per-test process isolation and output consistent
with the other nextest-based CI runs.

- Add a dedicated `e2e-kubernetes` nextest profile with a JUnit report and a
  generous slow-timeout (60s flag, 5-min terminate) suited to live-cluster
  tests; kept separate from `ci` so its JUnit path and timeouts don't affect
  the workspace run.
- Pin `--target-dir` for the run so the profile's relative JUnit path resolves
  to the repo-root results/ regardless of any inherited CARGO_TARGET_DIR
  (nextest ignores absolute JUnit paths).
- Render the JUnit XML to a standalone HTML report via xsltproc and a committed
  XSLT stylesheet (best-effort; never masks the test exit code).
- Name each report via `OPENSHELL_E2E_REPORT_NAME` (default `e2e-kubernetes`),
  used verbatim for both the `results/<name>.{xml,html}` filenames and the HTML
  heading. Tasks that invoke the script multiple times in one run set a distinct
  name per invocation so the reports no longer clobber the single fixed path:
  the credential-driver runs write results/e2e-kubernetes-secrets.xml and
  -vault.xml, and e2e:kubernetes:agent-sandbox-versions writes
  results/e2e-kubernetes-agent-sandbox-v1beta1.xml and -v1alpha1.xml.
- Declare cargo-nextest in mise [tools] so the task runs without the Nix shell.
- Ignore the results/ output directory.

The results/ reports do not leak information. They are gitignored and no
workflow uploads them as artifacts, so they stay on the ephemeral CI runner
and are discarded when it is torn down. The HTML template renders only test
names, status, timings, and failure messages (no captured stdout/stderr).
Moving from `cargo test -- --nocapture` to nextest's captured, failure-only
output also reduces what lands in the retained, viewable console logs.

Signed-off-by: Jorge Garcia Oncins <jgarciao@redhat.com>

* chore(e2e): revert per-lane report names for agent-sandbox-versions

The agent-sandbox-versions task runs two lanes sequentially against the
same cluster: v0.5.0 (v1beta1 storage version) then v0.4.6 (v1alpha1).
On a reused cluster the second lane fails when kubectl applies the older
CRD, because Kubernetes refuses to drop v1beta1 from spec.versions while
it remains in status.storedVersions (the storage-version downgrade
guardrail). This is a pre-existing issue with the v0.4.6 lane, unrelated
to the nextest reporting work.

The per-lane OPENSHELL_E2E_REPORT_NAME additions do not address that
downgrade failure, so revert them to keep this PR scoped to the nextest
change. Agent Sandbox 0.4.x is also superseded (1.0.0 is published);
dropping or bumping the v1alpha1 lane is left as a follow-up.

Signed-off-by: Jorge Garcia Oncins <jgarciao@redhat.com>

---------

Signed-off-by: Jorge Garcia Oncins <jgarciao@redhat.com>
2026-09-18 15:50:03 +00:00

81 lines
3.0 KiB
TOML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# OpenShell mise configuration
# See https://mise.jdx.dev/ for documentation
#
# Tasks are defined in tasks/*.toml — run `mise tasks` to list them all.
# NOTE: keep this version in sync with what CI uses in Dockerfile.ci
min_version = { soft = "2026.9.9" }
redactions = ["*_TOKEN", "*_PASSWORD"]
[settings]
experimental = true
python.precompiled_flavor = "install_only_stripped"
lockfile = true
lockfile_platforms = ["linux-x64", "linux-arm64", "macos-arm64", "windows-x64", "windows-arm64"]
[tools]
python = "3.14.5"
rust = "1.95.0"
node = "24.15.0"
kubectl = { version = "1.36.1", version_prefix = "v" }
uv = "0.10.12"
protoc = "29.6"
go = "1.26.7"
"go:github.com/golangci/golangci-lint/v2/cmd/golangci-lint" = "2.12"
"go:google.golang.org/protobuf/cmd/protoc-gen-go" = "1.36.11"
"go:google.golang.org/grpc/cmd/protoc-gen-go-grpc" = "1.6.2"
"go:golang.org/x/tools/cmd/goimports" = "0.48.0"
buf = "1.72.0"
helm = { version = "4.2.0", version_prefix = "v" }
helm-docs = "1.14.2"
yq = "4.53.6"
skaffold = { version = "2.20.0", os = ["linux", "macos"], version_prefix = "v" }
# Keep k3d out of Linux CI images until upstream ships a release rebuilt with
# patched Go/container dependencies. Linux Kubernetes E2E uses kind or an
# externally provided cluster context.
k3d = { version = "5.8.3", os = ["macos"] }
"github:anchore/syft" = { version = "1.44.0" }
"github:EmbarkStudios/cargo-about" = { version = "0.8.4", version_prefix = "" }
"github:EmbarkStudios/cargo-deny" = { version = "0.20.2", version_prefix = "" }
zig = "0.14.1"
"github:rust-secure-code/cargo-auditable" = "0.7.5"
"github:nextest-rs/nextest" = { version = "0.9.143", version_prefix = "cargo-nextest-" }
"github:rust-cross/cargo-zigbuild" = "0.22.3"
"npm:markdownlint-cli2" = "0.22.0"
[tools."github:mozilla/sccache"]
version = "0.16.0"
[tools."github:mozilla/sccache".platforms]
# NOTE: this override is necessary only for linux-x64, otherwise it selects an invalid artifact (sccache-dist-vx.y.z-x86_64-unknown-linux-musl.tar.gz)
linux-x64 = { asset_pattern = "sccache-v*x86_64*linux*.tar.gz" }
[env]
_.path = ["{{config_root}}/scripts/bin"]
_.python.venv = { path = ".venv", create = true }
_.file = [".env"]
KUBECONFIG = "{{config_root}}/kubeconfig"
UV_CACHE_DIR = "{{config_root}}/.cache/uv"
# Enable sccache for faster Rust builds. Preserve an SCCACHE_DIR selected by the
# caller so workstations and CI can configure their cache locations separately.
RUSTC_WRAPPER = "sccache"
SCCACHE_DIR = "{{ get_env(name='SCCACHE_DIR', default=config_root ~ '/.cache/sccache') }}"
# Shared build constants (overridable via environment).
# DOCKER_BUILDKIT enables BuildKit for Docker; ignored by podman.
DOCKER_BUILDKIT = "1"
[vars]
# Python paths to include in formatting/linting
python_paths = "python/ tasks/scripts/*.py e2e/mcp-conformance/*.py deploy/sbom/*.py"
[task_config]
includes = ["tasks/*.toml"]