Repository navigation
Tooling, quality gates, and integration of upgrade-langchain / plantreactome / userguide-qa #249
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: reactome_chatbot CI | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| types: | |
| - opened | |
| - synchronize | |
| push: | |
| branches: | |
| - main | |
| # A second push to a PR makes the first run's result irrelevant; without this | |
| # they both run to completion and queue behind each other. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| # Least privilege by default. id-token: write is granted only to docker-push, | |
| # which needs it to assume the AWS role. | |
| permissions: | |
| contents: read | |
| jobs: | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python and Poetry | |
| uses: ./.github/actions/install_python_poetry | |
| # ruff replaces black + isort; its `I` rules sort imports and | |
| # `ruff format` is black-compatible. Config lives in pyproject.toml. | |
| - name: Lint | |
| run: poetry run ruff check . | |
| - name: Check formatting | |
| run: poetry run ruff format --check . | |
| - name: Type check | |
| run: poetry run mypy | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python and Poetry | |
| uses: ./.github/actions/install_python_poetry | |
| - name: Run tests | |
| run: poetry run pytest | |
| poetry-check: | |
| if: ${{ github.event_name == 'pull_request' || github.event_name == 'workflow_dispatch' }} | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| matrix: | |
| os: [ubuntu-latest, macos-15-intel] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 # need the base branch to diff against | |
| # Plain git rather than a third-party action: this workflow can reach | |
| # AWS, so every extra action is supply-chain surface for a one-line check. | |
| - name: Check poetry.lock for changes | |
| id: check-poetry-lock | |
| shell: bash | |
| run: | | |
| base="${{ github.base_ref }}" | |
| if [ -z "$base" ]; then | |
| # manual run: no base to compare against, so always verify | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| elif git diff --name-only "origin/$base...HEAD" -- poetry.lock | grep -q .; then | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Set up Python and Poetry | |
| if: steps.check-poetry-lock.outputs.changed == 'true' | |
| uses: ./.github/actions/install_python_poetry | |
| - name: Verify Python imports | |
| if: steps.check-poetry-lock.outputs.changed == 'true' | |
| env: | |
| PYTHONPATH: ./bin:./src | |
| run: | | |
| poetry check | |
| poetry run python ./.github/actions/verify_imports.py | |
| docker-build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Build and push Docker image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: ./Dockerfile | |
| tags: reactome-chatbot:${{ github.sha }} | |
| outputs: type=docker,dest=/tmp/image.tar | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: image-artifact | |
| path: /tmp/image.tar | |
| docker-push: | |
| if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }} | |
| needs: docker-build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| id-token: write # assume the AWS role via OIDC | |
| contents: read | |
| steps: | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| name: image-artifact | |
| path: /tmp | |
| - id: get-hash | |
| run: | | |
| FULL_SHA=${{ github.sha }} | |
| echo "SHORT_SHA=${FULL_SHA:0:7}" >> $GITHUB_OUTPUT | |
| - env: | |
| AWS_REGION: us-east-1 | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| role-to-assume: ${{ vars.AWS_ROLE }} | |
| aws-region: ${{ env.AWS_REGION }} | |
| - id: login-ecr | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| with: | |
| registry-type: public | |
| - env: | |
| AWS_REGISTRY: ${{ steps.login-ecr.outputs.registry }} | |
| AWS_REGISTRY_ALIAS: reactome | |
| AWS_REPO: reactome-chatbot | |
| IMG_TAG: ${{ steps.get-hash.outputs.SHORT_SHA }} | |
| run: | | |
| docker load --input /tmp/image.tar | |
| docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG | |
| docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest | |
| docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG | |
| docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest |