name: Deployment release gate on: pull_request: push: branches: [main] workflow_dispatch: inputs: windows_docker_startup: description: Run the native self-hosted Windows Docker Desktop/WSL2 release gate required: false type: boolean default: false permissions: contents: read concurrency: group: deployment-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: deterministic: name: LF, Compose, docs, and TypeScript runs-on: ubuntu-24.04 timeout-minutes: 25 env: PYTHONDONTWRITEBYTECODE: "1" steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: "24.16.0" package-manager-cache: false - name: Verify shell syntax and LF policy run: | git ls-files -z '*.sh' | xargs -0 -n1 bash -n bash scripts/verify-line-endings.sh - name: Verify Compose and installation contracts run: | bash scripts/test-unified-compose.sh bash scripts/test-no-deployment-coupling-scope.sh bash scripts/test-compose-secret-policy.sh bash scripts/test-no-deployment-coupling.sh bash scripts/test-preprocess-compose-config.sh bash scripts/test-verify-workspace-install-docs.sh git diff --check - name: Assert clean checkout before release trust bootstrap run: | git diff --exit-code git diff --cached --exit-code test -z "$(git ls-files --others --exclude-standard)" - name: Verify schema-v3-only release gate run: bash scripts/verify-schema-v3-only-release.sh - name: Verify Task 13 clean-install and runtime fixtures run: | bash scripts/test-server-pi-state-topology.sh bash scripts/unified-deployment-smoke.sh --self-test - name: Test and type-check backend working-directory: backend run: | npx vitest run npx tsc --noEmit -p . - name: Install frontend dependencies working-directory: frontend run: npm ci - name: Test and type-check frontend working-directory: frontend run: | npx vitest run npx tsc -b authentication-browser: name: Hermetic authentication browser gate needs: deterministic runs-on: ubuntu-24.04 timeout-minutes: 30 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: "24.16.0" package-manager-cache: false - name: Set up Go uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: go-version: "1.26.5" cache-dependency-path: tools/tht/go.sum - name: Install backend dependencies working-directory: backend run: npm ci - name: Install frontend dependencies working-directory: frontend run: npm ci - name: Install Chromium for Playwright working-directory: frontend run: npx playwright install --with-deps chromium - name: Run authentication and authenticated F1 browser smoke run: bash scripts/authentication-smoke.sh linux-docker: name: Linux Docker deployment and rollback runs-on: ubuntu-24.04 timeout-minutes: 100 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Run unified deployment smoke run: timeout --signal=TERM --kill-after=45s 32m bash scripts/unified-deployment-smoke.sh - name: Run tht update smoke run: timeout --signal=TERM --kill-after=45s 32m bash scripts/tht-update-smoke.sh - name: Run Linux server deployment smoke run: timeout --signal=TERM --kill-after=45s 32m bash scripts/server-deployment-smoke.sh windows-clone: name: Windows clone and Compose contract runs-on: windows-2025 timeout-minutes: 20 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: "24.16.0" package-manager-cache: false - name: Install backend dependencies working-directory: backend run: npm ci - name: Verify clean backend distribution working-directory: backend run: node --test --test-concurrency=1 scripts/clean-dist.test.mjs - name: Set up Go uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: go-version: "1.26.5" cache-dependency-path: tools/tht/go.sum - name: Run native Windows retained-capability tests working-directory: tools/tht run: go test ./internal/safeio ./internal/backup ./internal/authstorage -count=1 - name: Verify Windows clone contract shell: pwsh run: ./scripts/test-windows-clone-contract.ps1 windows-docker-release: name: Native Windows Docker Desktop/WSL2 startup if: github.event_name == 'workflow_dispatch' && inputs.windows_docker_startup runs-on: [self-hosted, Windows, X64, docker-desktop] timeout-minutes: 45 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: go-version: "1.26.5" cache-dependency-path: tools/tht/go.sum - name: Run spaced-path Windows Docker release gate shell: pwsh run: ./scripts/test-windows-clone-contract.ps1 -DockerStartup