Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/ci/minio/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# CI only: upstream container registries deny these releases, but the official
# GitHub release binaries remain available. Keep versions aligned with Compose.
# The integration runners use linux/amd64; this is not a deployment image.
FROM alpine:3.22.6@sha256:5291449c3df73caf6ed85e649dec1b9e818b39a5d8c871e97afc13e9cd5e8fa8

RUN apk add --no-cache ca-certificates curl

ADD --checksum=sha256:7c5bd8512c6e966455b1d198209358b2d191c77a83ab377c4073281065fb855f --chmod=755 \
https://github.com/minio/minio/releases/download/RELEASE.2025-09-07T16-13-09Z/minio.linux-amd64.RELEASE.2025-09-07T16-13-09Z /usr/local/bin/minio
ADD --checksum=sha256:01f866e9c5f9b87c2b09116fa5d7c06695b106242d829a8bb32990c00312e891 --chmod=755 \
https://github.com/minio/mc/releases/download/RELEASE.2025-08-13T08-35-41Z/mc.linux-amd64.RELEASE.2025-08-13T08-35-41Z /usr/local/bin/mc

ENTRYPOINT ["minio"]
12 changes: 12 additions & 0 deletions .github/workflows/_ci-relay.yml
Original file line number Diff line number Diff line change
Expand Up @@ -207,6 +207,8 @@ jobs:
--archive-file target/ci/postgres-tests.tar.zst

desktop-e2e-integration-shard:
env:
COMPOSE_FILE: docker-compose.yml:docker-compose.ci.yml
name: Desktop E2E Integration (${{ matrix.shard }}/2)
runs-on: ubuntu-latest
timeout-minutes: 20
Expand All @@ -220,6 +222,8 @@ jobs:
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Build CI MinIO image
run: docker compose build minio
- name: Start integration services
run: |
for attempt in 1 2 3; do
Expand Down Expand Up @@ -400,6 +404,8 @@ jobs:
echo "Desktop E2E Integration shards passed"

backend-integration:
env:
COMPOSE_FILE: docker-compose.yml:docker-compose.ci.yml
name: Backend Integration (relay e2e)
runs-on: ubuntu-latest
timeout-minutes: 20
Expand All @@ -413,6 +419,8 @@ jobs:
uses: taiki-e/install-action@0fd46367812ee04360509b4169d9f659d6892bb2 # v2.79.15
with:
tool: cargo-nextest@0.9.136
- name: Build CI MinIO image
run: docker compose build minio
- name: Start integration services
run: |
for attempt in 1 2 3; do
Expand Down Expand Up @@ -562,6 +570,8 @@ jobs:
if-no-files-found: ignore

relay-e2e:
env:
COMPOSE_FILE: docker-compose.yml:docker-compose.ci.yml
name: Relay E2E
runs-on: ubuntu-latest
timeout-minutes: 20
Expand All @@ -581,6 +591,8 @@ jobs:
with:
name: desktop-e2e-relay
path: target/ci
- name: Build CI MinIO image
run: docker compose build minio
- name: Start relay
run: |
chmod +x ./target/ci/buzz-relay ./target/ci/git-credential-nostr
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,6 +55,8 @@ jobs:
- 'deny.toml'
- '.github/workflows/ci.yml'
- '.github/workflows/_ci-*.yml'
- '.github/ci/minio/**'
- 'docker-compose.ci.yml'
- 'scripts/run-tests.sh'
- 'scripts/model-capabilities.json'
- 'scripts/normative-corpus.json'
Expand Down
13 changes: 13 additions & 0 deletions docker-compose.ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Layer over docker-compose.yml for the disposable AMD64 integration runners.
# Build once with `docker compose build minio`; both services use that local image.
services:
minio:
image: buzz-ci-minio:local
platform: linux/amd64
pull_policy: never
build:
context: .github/ci/minio
minio-init:
image: buzz-ci-minio:local
platform: linux/amd64
pull_policy: never
2 changes: 2 additions & 0 deletions scripts/ci-selection.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,8 @@ const scenarios = [
["relay", ["crates/buzz-relay/src/main.rs"], ["rust"]],
["migration", ["migrations/123.sql"], ["rust"]],
["shared workflow", [".github/workflows/ci.yml"], ["rust", "mobile"]],
["CI MinIO image", [".github/ci/minio/Dockerfile"], ["rust"]],
["CI Compose override", ["docker-compose.ci.yml"], ["rust"]],
[
"mixed mobile and relay",
["mobile/lib/main.dart", "crates/buzz-core/src/lib.rs"],
Expand Down
13 changes: 13 additions & 0 deletions scripts/test-ci-required-context-isolation.sh
Original file line number Diff line number Diff line change
Expand Up @@ -83,4 +83,17 @@ if grep -Eq '^ desktop-build-macos:|desktop_macos_result:' "$desktop_workflow";
fail "Desktop Domain must not own the isolated macOS required check"
fi

# Each job has an isolated Docker daemon: every Compose consumer must build
# the local MinIO image before starting services, including the script caller.
for job in desktop-e2e-integration-shard backend-integration relay-e2e; do
body=$(extract_job "$job" "$relay_workflow")
[[ "$body" == *'COMPOSE_FILE: docker-compose.yml:docker-compose.ci.yml'* ]] ||
fail "$job must select the CI Compose override"
[[ "$body" == *'docker compose build minio'* ]] ||
fail "$job must build its own CI MinIO image"
before_build=${body%%docker compose build minio*}
[[ "$before_build" != *'docker compose up'* && "$before_build" != *'./scripts/start-relay-for-tests.sh'* ]] ||
fail "$job must build MinIO before starting services"
done

echo "CI required-context isolation contract passed"
Loading