57 lines
2.2 KiB
YAML
57 lines
2.2 KiB
YAML
# pfv-bms CI [#784 #778] — fleet standard per Discourse "CI/CD: Gitea Actions".
|
|
# Runs on dev (pre-release gate) and release (final gate before live pull).
|
|
name: ci
|
|
on:
|
|
push:
|
|
branches: [dev, release]
|
|
jobs:
|
|
lint:
|
|
runs-on: ultix
|
|
container:
|
|
image: node:20-bookworm
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: yamllint
|
|
run: |
|
|
apt-get update -qq >/dev/null && apt-get install -qq -y python3-pip >/dev/null && pip install --quiet --break-system-packages yamllint
|
|
yamllint -c .yamllint .
|
|
- name: secret scan
|
|
run: |
|
|
if grep -rInE "BEGIN (RSA |OPENSSH |EC |DSA )?PRIVATE KEY|aws_secret_access_key *=|AKIA[0-9A-Z]{16}" --exclude-dir=.git .; then
|
|
echo "::error::secret material committed"; exit 1
|
|
else
|
|
echo "secret scan clean"
|
|
fi
|
|
- name: sdlc regression tests
|
|
run: |
|
|
chmod +x tests/test_sdlc.sh
|
|
bash tests/test_sdlc.sh
|
|
|
|
# Real load validation: boots Home Assistant against the repo config and
|
|
# proves HA can parse + set up every integration (yamllint only proves the
|
|
# YAML parses; this catches unknown keys, bad Jinja, schema drift).
|
|
# Pinned to the HA version the box runs (needs python >=3.14).
|
|
# actions/checkout is NOT used: it needs node in the job container, and
|
|
# python images have none (lint works because node:20 ships node).
|
|
# Clone with the job's auto token instead. Stub secrets are CI-only
|
|
# fixtures — never present on the live box.
|
|
config-check:
|
|
runs-on: ultix
|
|
container:
|
|
image: python:3.14-bookworm
|
|
steps:
|
|
- name: clone
|
|
run: |
|
|
test -n "$GITHUB_TOKEN" || { echo "GITHUB_TOKEN missing"; exit 1; }
|
|
git clone --depth 1 "https://x-access-token:${GITHUB_TOKEN}@git.knownelement.com/${GITHUB_REPOSITORY}.git" .
|
|
git log -1 --oneline
|
|
- name: install homeassistant 2026.8.3
|
|
run: pip install --quiet homeassistant==2026.8.3
|
|
- name: homeassistant check_config
|
|
run: |
|
|
cp tests/fixtures/secrets-stub.yaml secrets.yaml
|
|
python3 -m homeassistant --script check_config --config .
|
|
rc=$?
|
|
rm -f secrets.yaml home-assistant_v2.db home-assistant.log*
|
|
exit $rc
|