feat : 6 astra improve it
CI / Verify and audit (push) Successful in 2m33s
CI / Build, scan and deploy immutable images (push) Failing after 1m29s

This commit is contained in:
2026-09-22 18:28:18 +07:00 Unverified
parent 88afa8e947
commit 87e6bcd96f
56 changed files with 1351 additions and 511 deletions
+14 -6
View File
@@ -70,6 +70,7 @@ describe("production deployment contract", () => {
"k8s/base/hpa.yaml",
"k8s/base/pdb.yaml",
"k8s/base/ci-rbac.yaml",
"k8s/base/network-policy.yaml",
"k8s/migration/job.yaml",
];
const manifests = (
@@ -81,15 +82,19 @@ describe("production deployment contract", () => {
expect(manifests).not.toContain("resources: [\"secrets\"]");
expect(manifests).not.toContain("kind: ClusterRole");
expect(manifests).not.toContain("kind: ClusterRoleBinding");
expect(manifests).toContain("kind: NetworkPolicy");
expect(manifests).toContain("key: DATABASE_URL");
expect(manifests).not.toContain("secretRef:");
});
it("packages non-root Bun application and migration targets", async () => {
const dockerfile = await repositoryFile("Dockerfile");
expect(dockerfile).toContain("FROM dependencies AS migration");
expect(dockerfile).toContain("FROM oven/bun:${BUN_VERSION} AS app");
expect(dockerfile).toContain("FROM ${BUN_IMAGE} AS migration");
expect(dockerfile).toContain("FROM ${BUN_IMAGE} AS app");
expect(dockerfile).toMatch(/ARG BUN_IMAGE=oven\/bun:1\.3\.14-alpine@sha256:[a-f0-9]{64}/u);
expect(dockerfile.match(/^USER 1000:1000$/gmu)).toHaveLength(2);
expect(dockerfile).toContain('ENTRYPOINT ["bun", "scripts/migrate.ts"]');
expect(dockerfile).toContain('ENTRYPOINT ["bun", "migrate.js"]');
expect(dockerfile).toContain('CMD ["bun", "server.js"]');
expect(dockerfile).toContain("ARG BASE_URL");
expect(dockerfile).toContain("ENV BASE_URL=${BASE_URL}");
@@ -111,6 +116,9 @@ describe("production deployment contract", () => {
expect(workflow).toContain("kubectl kustomize k8s/");
expect(workflow).toContain("needs: verify");
expect(workflow).not.toContain("pull_request:");
expect(workflow).toContain("security:audit");
expect(workflow).toMatch(/gitleaks@sha256:[a-f0-9]{64}/u);
expect(workflow).not.toContain("insecure-skip-tls-verify=true");
expect(workflow).toContain("--target app");
expect(workflow).toContain('--build-arg BASE_URL="$BASE_URL"');
expect(workflow).toContain(
@@ -123,13 +131,13 @@ describe("production deployment contract", () => {
expect(workflow).toContain(
"registry.neko-piranha.ts.net/astral/buzz-sheet",
);
expect(workflow).toContain("migrate-${{ gitea.sha }}");
expect(workflow).toContain("migrate-$REVISION");
expect(workflow).toContain("deployment/buzz-sheet-discord-worker");
const deleteMigrationJob = workflow.indexOf(
'delete job buzz-sheet-migrate --ignore-not-found',
);
const createMigrationJob = workflow.indexOf(
'create --validate=false -f "$migration_manifest"',
'create -f "$migration_manifest"',
);
expect(deleteMigrationJob).toBeGreaterThan(-1);
expect(deleteMigrationJob).toBeLessThan(createMigrationJob);
@@ -176,7 +184,7 @@ describe("environment template contract", () => {
for (const key of requiredKeys) {
expect(environmentExample).toMatch(new RegExp(`^${key}=`, "mu"));
}
expect(environmentExample).toContain("BUZZ_DEMO_MODE=false");
expect(environmentExample).not.toContain("BUZZ_DEMO_MODE");
expect(environmentExample).toContain(
"NEXT_PUBLIC_GOOGLE_ADSENSE_CLIENT_ID=ca-pub-9687404323559597",
);