diff --git a/.tangled/workflows/test-postgres.yml b/.tangled/workflows/test-postgres.yml new file mode 100644 index 0000000..bab9c93 --- /dev/null +++ b/.tangled/workflows/test-postgres.yml @@ -0,0 +1,52 @@ +# Runs the postgres-gated tests that test.yml silently skips: +# server/test/catalog_index_postgres_test.gleam and shelf_index_postgres_test.gleam +# both no-op when DATABASE_URL is unset (see their with_store helpers). The +# nixery engine used by test.yml has no service-container support; only the +# microvm engine does, via a `services` block passed through to NixOS +# modules. Kept as its own workflow (not folded into test.yml) so this engine +# switch can be verified in isolation: delete this file to revert with zero +# risk to the working nixery pipeline. +when: + - event: ["push"] + branch: ["main"] + - event: ["pull_request"] + +engine: microvm +image: nixos + +# Same reasoning as test.yml's nixery dependencies: the pinned nixos release's +# gleam is too old for our deps and formatter. +registry: + nixpkgs: github:nixos/nixpkgs/nixos-unstable + +dependencies: + - gleam + - erlang + - rebar3 + - nodejs + - bun + - gnumake + - git + +# postgresql_18 to match deploy/docker-compose.yml (postgres:18-alpine). Peer +# auth over the unix socket needs the role name to match the connecting OS +# user; docs.tangled.org/spindles.html shows ensureUsers.name equal to the +# database name in its own worked example, so that pattern is mirrored here. +# UNCONFIRMED: which OS user microvm steps actually run as, so whether peer +# auth resolves automatically here needs verifying on the first real run. +environment: + DATABASE_URL: "postgresql:///at_record_test?host=/run/postgresql" + +services: + postgresql: + enable: true + package: postgresql_18 + ensureDatabases: ["at_record_test"] + ensureUsers: + - name: at_record_test + ensureDBOwnership: true + +steps: + - name: postgres-gated tests + command: | + make test