name: Deployment release gate on: pull_request: push: branches: [main] workflow_dispatch: permissions: contents: read concurrency: group: deployment-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: deterministic: name: LF, Compose, docs, and TypeScript runs-on: ubuntu-24.04 timeout-minutes: 25 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Node.js uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: "24.16.0" package-manager-cache: false - name: Verify shell syntax and LF policy run: | git ls-files -z '*.sh' | xargs -0 -n1 bash -n bash scripts/verify-line-endings.sh - name: Verify Compose and installation contracts run: | bash scripts/test-unified-compose.sh bash scripts/test-compose-secret-policy.sh bash scripts/test-no-deployment-coupling.sh bash scripts/test-verify-workspace-install-docs.sh bash scripts/unified-deployment-smoke.sh --self-test git diff --check - name: Install backend dependencies working-directory: backend run: npm ci - name: Test and type-check backend working-directory: backend run: | npx vitest run npx tsc --noEmit -p . - name: Install frontend dependencies working-directory: frontend run: npm ci - name: Test and type-check frontend working-directory: frontend run: | npx vitest run npx tsc -b linux-docker: name: Linux Docker deployment and rollback runs-on: ubuntu-24.04 timeout-minutes: 70 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Run unified deployment smoke run: timeout --signal=TERM --kill-after=45s 30m bash scripts/unified-deployment-smoke.sh - name: Run thothctl update smoke run: timeout --signal=TERM --kill-after=45s 30m bash scripts/thothctl-update-smoke.sh windows-clone: name: Windows clone and Compose contract runs-on: windows-2025 timeout-minutes: 20 steps: - name: Check out source uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - name: Set up Go uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0 with: go-version: "1.26.5" cache-dependency-path: tools/thothctl/go.sum - name: Build native Windows thothctl working-directory: tools/thothctl shell: pwsh run: | New-Item -ItemType Directory -Force -Path ../../dist/thothctl | Out-Null go build -trimpath -o ../../dist/thothctl/thothctl-windows-amd64.exe ./cmd/thothctl - name: Verify Windows clone contract shell: pwsh run: >- ./scripts/test-windows-clone-contract.ps1 -ThothctlPath "$PWD/dist/thothctl/thothctl-windows-amd64.exe"