Files
Ruslan KonviserandClaude Opus 5 a6ab2fc9e3 ci(verdaccio): route the Cypress and Currents e2e installs through the internal npm cache
These were the last two dependency-installing workflows still resolving packages
straight from the public npm registry. Both are covered now, using the same
placement discipline as build.yml.

The step goes AFTER the yarn cache restore and BEFORE `yarn bootstrap`, because
the action rewrites yarn.lock's resolved URLs (the load-bearing half - yarn v1
fetches the URL recorded in the lockfile and ignores the registry setting) while
hashFiles() in a cache key evaluates at step runtime. Configuring the registry
first would move the key and bifurcate the cache namespace by VIP reachability.

No save-key pinning was required. build.yml needs it because it uses the split
actions/cache/restore + actions/cache/save pair, whose save step re-derives
hashFiles() at save time. Both files here use the COMBINED actions/cache, which
records its primary key with core.saveState during the restore - before the
rewrite - and whose post-job save reads that recorded key back, so the entry is
written under exactly the key the next run's restore computes.

Scope, and what was deliberately left alone:

- test_currents.yml `e2e-tests` and test_cypress.yml `e2e-tests` get the step.
  Both resolve to the self-hosted ARC pool via vars.RUNNER_LINUX_X64_8
  (= ever-k8s-linux-x64-8), the only place the VIP answers. The action probes
  the VIP and falls back to the public registry, so the `|| 'ubuntu-latest'`
  fallback runner degrades to today's behaviour rather than hanging on a LAN IP.
- test_currents.yml `prepare` installs nothing - it only emits a build UUID.
- test_cypress.yml `e2e-tests-setup` overrides its install with
  `install-command: node -p 'os.cpus()'`, so it resolves no packages from any
  npm registry. Adding the step there would buy nothing and would rewrite
  yarn.lock ahead of cypress-io/github-action's own lockfile-keyed cache,
  splitting it in two.

`expect-vip` is derived from the runner variable rather than the
contains(matrix.os, ...) idiom the app workflows use: these jobs' only matrix
key is `containers`, so that expression would collapse to false and silently
disable the in-network VIP retry and its warning.

Additive only - no workflow, job or step was removed or reordered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-22 21:50:01 +02:00

214 lines
7.9 KiB
YAML

name: Cypress Tests
on:
push:
branches: [nope]
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
# Least-privilege scope for the automatic GITHUB_TOKEN.
# This workflow only builds/tests/deploys from a checkout — read access is sufficient.
permissions:
contents: read
jobs:
e2e-tests-setup:
runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }}
timeout-minutes: 360
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Cypress install
uses: cypress-io/github-action@v5
# let's give this action an ID so we can refer to its output values later
id: cypress
with:
# we want to install Cypress only
install: true
install-command: node -p 'os.cpus()'
# we don't want to run tests in this job, we only setup Cypress here
runTests: false
env:
CYPRESS_RECORD_KEY: ${{ secrets.CYPRESS_RECORD_KEY }}
CYPRESS_PROJECT_ID: ${{ secrets.CYPRESS_PROJECT_ID }}
# pass GitHub token to allow accurately detecting a build vs a re-run build
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
e2e-tests:
runs-on: ${{ vars.RUNNER_LINUX_X64_8 || 'ubuntu-latest' }}
timeout-minutes: 360
# we can try to run tests in the Docker containers later
# container: cypress/browsers:node14.17.0-chrome88-ff89
needs: e2e-tests-setup
strategy:
# when one test fails, DO NOT cancel the other
# containers, because this will kill Cypress processes
# leaving the Dashboard hanging ...
# https://github.com/cypress-io/github-action/issues/48
fail-fast: false
matrix:
# run copies of the current job in parallel on different runners
containers: [1, 2]
env:
CYPRESS_CACHE_FOLDER: C:\Users\Evereq\AppData\Local\Cypress\Cache
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Get yarn cache directory path
id: yarn-cache-dir-path
shell: pwsh
run: |
$cacheDir = yarn cache dir
"dir=$cacheDir" | Out-File -FilePath $env:GITHUB_OUTPUT -Encoding utf8 -Append
- uses: actions/cache@v5
id: yarn-cache
with:
path: ${{ steps.yarn-cache-dir-path.outputs.dir }}
key: ${{ runner.os }}-${{ runner.arch }}-yarn-${{ hashFiles('yarn.lock') }}
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-yarn-
# Route the installs below through the internal Verdaccio cache. This job resolves to the
# self-hosted ARC pool (vars.RUNNER_LINUX_X64_8), which is the only place the VIP is
# reachable; the action PROBES it and falls back to the public npm registry otherwise, so the
# `|| 'ubuntu-latest'` fallback runner degrades to today's behaviour instead of hanging.
#
# Placed AFTER the yarn cache restore on purpose: the action rewrites yarn.lock's resolved
# URLs (that rewrite is the load-bearing half — yarn v1 fetches the URL recorded in the
# lockfile and ignores the registry setting), and hashFiles() in a cache key evaluates at step
# runtime. Configuring the registry before the restore would move the key and bifurcate the
# cache namespace by VIP reachability. Same ordering as build.yml.
#
# No save-key pinning is needed here, unlike build.yml: that file uses a split
# cache/restore + cache/save pair, whose save step re-derives hashFiles() at save time. This
# is the COMBINED actions/cache action — it captures its primary key during the restore, i.e.
# before the rewrite, and its post-job save reuses that captured key, so the entry is written
# under exactly the key the next run's restore computes.
#
# Deliberately NOT added to the `e2e-tests-setup` job above: its cypress-io/github-action step
# overrides the install with `install-command: node -p 'os.cpus()'`, so that job resolves no
# packages from any npm registry. Adding the step there would buy nothing and would rewrite
# yarn.lock ahead of that action's own internal lockfile-keyed cache, splitting it in two.
- name: Configure Registry
uses: ever-co/ever-gauzy/.github/actions/configure-registry@aa4ee19926fabcf820aa1294385a76aec6bdb548
with:
verdaccio-registry: ${{ vars.VERDACCIO_REGISTRY }}
verdaccio-token: ${{ secrets.VERDACCIO_TOKEN }}
force-public: ${{ vars.VERDACCIO_FORCE_PUBLIC }}
# NOT contains(matrix.os, ...) as the app workflows use: this job's only matrix key is
# `containers`, so that expression collapses to false and would silently disable the
# in-network VIP retry and its warning. Derive it from the runner variable this job uses.
expect-vip: ${{ vars.RUNNER_LINUX_X64_8 != '' }}
# - name: Increase file limit
# run: echo fs.inotify.max_user_watches=524288 | sudo tee -a /etc/sysctl.conf && sudo sysctl -p
- name: Add Yarn to path
run: echo "C:\Users\Evereq\AppData\Roaming\npm" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append
- name: Install Packages & Bootstrap
run: yarn bootstrap
- name: Build all packages
run: yarn build:package:all
- name: Install forever package
shell: bash
# The k8s ARC container runners' system npm prefix (/usr/lib) is root-owned and there
# is no sudo - route npm -g installs to a user-writable prefix (harmless on VM runners).
run: |
npm config set prefix "$HOME/.npm-global"
echo "$HOME/.npm-global/bin" >> "$GITHUB_PATH"
npm install forever -g
- name: Run API in background
run: yarn start:api:forever
- name: Run UI in background
run: yarn start:gauzy:forever
- name: Install Cypress Package
run: npm install -g cypress@8.3.1
- name: Install Cypress for our e2e tests
run: |
cd apps/gauzy-e2e
yarn cypress install
- name: Cypress info
env:
# make sure every Cypress install prints minimal information
CI: 1
# print Cypress and OS info
run: |
npx cypress verify
npx cypress info
npx cypress version
npx cypress version --component package
npx cypress version --component binary
npx cypress version --component electron
npx cypress version --component node
- name: Cypress run
uses: cypress-io/github-action@v5
# let's give this action an ID so we can refer to its output values later
id: cypress
# Continue the build in case of an error, as we need to set the
# commit status in the next step, both in case of success and failure
continue-on-error: true
with:
# we have already installed all dependencies above
install: false
# record using CYPRESS_RECORD_KEY defined in env
record: true
# run tests in parallel
parallel: true
group: '1 - all e2e tests'
# Cypress tests and config file are in "apps/gauzy-e2e" folder
working-directory: 'apps/gauzy-e2e'
# We wait till both API and UI runs completely here
wait-on: 'http://localhost:3000/api,http://localhost:4200'
# wait up to 20 minutes for the servers to respond
wait-on-timeout: 1200
browser: chrome
headless: true
config-file: cypress.json
env:
CYPRESS_RECORD_KEY: ${{ secrets.CYPRESS_RECORD_KEY }}
CYPRESS_PROJECT_ID: ${{ secrets.CYPRESS_PROJECT_ID }}
# pass GitHub token to allow accurately detecting a build vs a re-run build
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Print Dashboard URL
run: |
echo Cypress finished with: ${{ steps.cypress.outcome }}
echo See results at ${{ steps.cypress.outputs.dashboardUrl }}