name: CI on: pull_request: push: branches: [main] permissions: contents: read concurrency: group: ci-${{ github.ref }} cancel-in-progress: true jobs: # Keep commands serial within each job: fixtures restart Workers and mutate state. core-control: runs-on: blacksmith-2vcpu-ubuntu-2404 steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: pnpm - run: pnpm install --frozen-lockfile - run: pnpm typecheck - run: pnpm test:control-plane-effect - run: pnpm test:customer-runtime-effect - run: pnpm test:mcp-catalog - run: pnpm test:mcp-model - run: pnpm test:mcp-runtime - run: pnpm test:mcp-health - run: pnpm test:mcp-tools - run: pnpm test:capability-policy - run: pnpm test:capability-approvals - run: pnpm test:mcp-resources - run: pnpm test:mcp-invocation - run: pnpm test:skill-package - run: pnpm test:bundled-skills - run: pnpm test:installed-skills - run: pnpm test:skill-management - run: pnpm test:skill-activation - run: pnpm test:skill-resources - run: pnpm test:skill-script-runner - run: pnpm test:skill-script-workspace - run: pnpm test:skill-execution - run: pnpm test:skill-script-output - run: pnpm test:skill-permissions - run: pnpm test:skill-installer - run: pnpm test:mcp-oauth - run: pnpm test:mcp-headers - run: pnpm test:config - run: pnpm test:providers - run: pnpm test:attachments - run: pnpm build:release # Catalog tests rewrite dist/catalog; finish before building its consumers. - run: pnpm test:catalog - run: pnpm test:worker - run: pnpm test:deployment - run: pnpm test:deployment-network - run: pnpm test:runtime - run: pnpm test:diagnostics - run: pnpm test:think - run: pnpm test:activities - run: pnpm test:memory - run: pnpm test:tasks - uses: ./.github/actions/install-playwright - run: pnpm build:control-plane - run: pnpm test:oauth - run: pnpm test:bridge-server - run: pnpm test:ownership - run: pnpm test:orchestrator - run: pnpm test:installation-status - run: pnpm test:updates - run: pnpm test:upgrade-state - run: pnpm test:bridge - run: pnpm test:domains execution: runs-on: blacksmith-2vcpu-ubuntu-2404 steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: pnpm - run: pnpm install --frozen-lockfile - run: pnpm build:release - run: pnpm test:execution browser: runs-on: blacksmith-2vcpu-ubuntu-2404 steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: pnpm - run: pnpm install --frozen-lockfile - run: pnpm build:release - uses: ./.github/actions/install-playwright - run: pnpm test:browser - run: pnpm test:settings - run: pnpm test:app-shell - run: pnpm test:tasks-ui - run: pnpm test:schedule-action - run: pnpm test:chat-ui sandbox: runs-on: blacksmith-2vcpu-ubuntu-2404 steps: - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: pnpm - run: pnpm install --frozen-lockfile - run: pnpm build:release - uses: ./.github/actions/install-playwright - run: pnpm build:control-plane - run: docker info - run: pnpm test:web - run: pnpm test:shell - run: pnpm test:golden-path # Preserve the required check name and reject failed, cancelled or skipped jobs. check: if: ${{ always() }} needs: [core-control, execution, browser, sandbox] runs-on: blacksmith-2vcpu-ubuntu-2404 steps: - name: Require every test job to pass env: JOB_RESULTS: ${{ toJSON(needs.*.result) }} run: jq --exit-status 'length == 4 and all(. == "success")' <<< "$JOB_RESULTS"