Refactorise les 4 workflows de déclencheur d'opencode-openchamber sur le pattern exact de web/mydl :
Avant / après
Jobs hadolint/test dupliqués dans chaque workflow (4 copies) → un seul _ci-common.yaml (workflow_call) appelé par pr/main/tag/cron avec secrets: inherit.
tests/test.sh (smoke HTTP réel : container up, ready loop, assertions) n'était jamais appelé par aucun workflow → maintenant job build-test dans _ci-common avec load: true (sinon l'image reste dans le cache Buildx et docker run la voit pas).
Builds sans cache → cache-from/to: type=gha partout (builds nightly bien plus rapides).
main.yaml : job tag avec URL remote corrompue (x-access-token:*** secrets... — le {{était manquant) → corrigé. PAT SA_TOKEN_ACTION_PUSH_TAGS conservé pour déclencher tag.yaml.
workflow_dispatch ajouté sur pr.yaml et main.yaml (déclenchement manuel possible).
Concurrency group de PR cancel-in-progress.
Sortie Docker (inchangée, déjà mydl-like)
:vX.Y.Z + :vX.Y.Z-latest au push de tag (seule source de push Docker)
rebuild nightly :vX.Y.Z-latest via git describe
Pas de :latest nu.
Refactorise les 4 workflows de déclencheur d'opencode-openchamber sur le pattern exact de web/mydl :
## Avant / après
- Jobs hadolint/test **dupliqués** dans chaque workflow (4 copies) → un seul `_ci-common.yaml` (`workflow_call`) appelé par pr/main/tag/cron avec `secrets: inherit`.
- `tests/test.sh` (smoke HTTP réel : container up, ready loop, assertions) **n'était jamais appelé** par aucun workflow → maintenant job `build-test` dans `_ci-common` avec `load: true` (sinon l'image reste dans le cache Buildx et `docker run` la voit pas).
- Builds sans cache → `cache-from/to: type=gha` partout (builds nightly bien plus rapides).
- `main.yaml` : job tag avec **URL remote corrompue** (`x-access-token:*** secrets...` — le `{{`était manquant) → corrigé. PAT `SA_TOKEN_ACTION_PUSH_TAGS` conservé pour déclencher `tag.yaml`.
- `workflow_dispatch` ajouté sur pr.yaml et main.yaml (déclenchement manuel possible).
- Concurrency group de PR `cancel-in-progress`.
## Sortie Docker (inchangée, déjà mydl-like)
- `:vX.Y.Z` + `:vX.Y.Z-latest` au push de tag (seule source de push Docker)
- rebuild nightly `:vX.Y.Z-latest` via `git describe`
- Pas de `:latest` nu.
Refactor the 4 trigger workflows to call a shared _ci-common.yaml
(hadolint + build-test), like web/mydl:
- pr.yaml -> PR checks via _ci-common (concurrency group, dispatch)
- main.yaml -> CI + cached load-build + git semver tag (PAT)
- tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest
- cron.yaml -> nightly rebuild of :vX.Y.Z-latest
- _ci-common.yaml -> hadolint (step-level continue-on-error) + build-test
with GHA cache, load:true and tests/test.sh actually run
(real HTTP smoke tests - they existed but were never
invoked by any workflow)
Fixes: main.yaml tag job had a corrupted remote URL line; tests never ran
on any trigger path.
opencodecabilloteu
requested review from jcabillot 2026-10-08 18:16:18 -04:00
Fix du test suite: premier run a échoué car OpenChamber refuse de binder 0.0.0.0 sans UI password (OPENCHAMBER_UI_PASSWORD ou OPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=true). Ajout de -e OPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=true dans tests/test.sh pour que le smoke HTTP localhost-only puisse tourner en CI. CI: verte.
Fix du test suite: premier run a échoué car OpenChamber refuse de binder 0.0.0.0 sans UI password (`OPENCHAMBER_UI_PASSWORD` ou `OPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=true`). Ajout de `-e OPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=true` dans `tests/test.sh` pour que le smoke HTTP localhost-only puisse tourner en CI. CI: verte.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Refactorise les 4 workflows de déclencheur d'opencode-openchamber sur le pattern exact de web/mydl :
Avant / après
_ci-common.yaml(workflow_call) appelé par pr/main/tag/cron avecsecrets: inherit.tests/test.sh(smoke HTTP réel : container up, ready loop, assertions) n'était jamais appelé par aucun workflow → maintenant jobbuild-testdans_ci-commonavecload: true(sinon l'image reste dans le cache Buildx etdocker runla voit pas).cache-from/to: type=ghapartout (builds nightly bien plus rapides).main.yaml: job tag avec URL remote corrompue (x-access-token:*** secrets...— le{{était manquant) → corrigé. PATSA_TOKEN_ACTION_PUSH_TAGSconservé pour déclenchertag.yaml.workflow_dispatchajouté sur pr.yaml et main.yaml (déclenchement manuel possible).cancel-in-progress.Sortie Docker (inchangée, déjà mydl-like)
:vX.Y.Z+:vX.Y.Z-latestau push de tag (seule source de push Docker):vX.Y.Z-latestviagit describe:latestnu.Refactor the 4 trigger workflows to call a shared _ci-common.yaml (hadolint + build-test), like web/mydl: - pr.yaml -> PR checks via _ci-common (concurrency group, dispatch) - main.yaml -> CI + cached load-build + git semver tag (PAT) - tag.yaml -> CI + build/push :vX.Y.Z and :vX.Y.Z-latest - cron.yaml -> nightly rebuild of :vX.Y.Z-latest - _ci-common.yaml -> hadolint (step-level continue-on-error) + build-test with GHA cache, load:true and tests/test.sh actually run (real HTTP smoke tests - they existed but were never invoked by any workflow) Fixes: main.yaml tag job had a corrupted remote URL line; tests never ran on any trigger path.Fix du test suite: premier run a échoué car OpenChamber refuse de binder 0.0.0.0 sans UI password (
OPENCHAMBER_UI_PASSWORDouOPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=true). Ajout de-e OPENCHAMBER_ALLOW_UNAUTHENTICATED_LAN=truedanstests/test.shpour que le smoke HTTP localhost-only puisse tourner en CI. CI: verte.