Repository navigation
Merge pull request #295 from reactome/013-handoff-through-captcha #606
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: reactome_chatbot CI | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| types: | |
| - opened | |
| - synchronize | |
| push: | |
| branches: | |
| - main | |
| # A second push to a PR makes the first run's result irrelevant; without this | |
| # they both run to completion and queue behind each other. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| # Least privilege by default. id-token: write is granted only to docker-push, | |
| # which needs it to assume the AWS role. | |
| permissions: | |
| contents: read | |
| jobs: | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python and Poetry | |
| uses: ./.github/actions/install_python_poetry | |
| # ruff replaces black + isort; its `I` rules sort imports and | |
| # `ruff format` is black-compatible. Config lives in pyproject.toml. | |
| - name: Lint | |
| run: poetry run ruff check . | |
| - name: Check formatting | |
| run: poetry run ruff format --check . | |
| - name: Type check | |
| run: poetry run mypy | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python and Poetry | |
| uses: ./.github/actions/install_python_poetry | |
| # The same data the Dockerfile installs. BM25 tokenises with | |
| # word_tokenize(..., language="english"), so any test that drives | |
| # retrieval needs punkt_tab -- without it the suite passes locally, | |
| # where a developer has downloaded it, and fails here. | |
| - name: Fetch NLTK data used by BM25 | |
| run: poetry run python -m nltk.downloader punkt_tab | |
| - name: Run tests | |
| run: poetry run pytest | |
| poetry-check: | |
| # No event filter. It used to run only on pull_request and | |
| # workflow_dispatch, so every push to main skipped it -- and GitHub counts | |
| # a skipped required check as not-passing, leaving main permanently | |
| # showing 6/8. A main branch that always looks amber is a main branch | |
| # nobody reads. The expensive steps stay gated on poetry.lock actually | |
| # having changed, which on a push means comparing against HEAD^. | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| matrix: | |
| os: [ubuntu-latest, macos-15-intel] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 # need the base branch to diff against | |
| # Plain git rather than a third-party action: this workflow can reach | |
| # AWS, so every extra action is supply-chain surface for a one-line check. | |
| - name: Check poetry.lock for changes | |
| id: check-poetry-lock | |
| shell: bash | |
| run: | | |
| base="${{ github.base_ref }}" | |
| before="${{ github.event.before }}" | |
| if [ -z "$base" ] && [ "${{ github.event_name }}" = "push" ]; then | |
| # A push has no base branch; compare against where main was | |
| # before it, so this stays as cheap here as it is on a PR. | |
| # | |
| # github.event.before, not HEAD^. Rebase merges are enabled on | |
| # this repository, so one push can advance main by several | |
| # commits -- HEAD^ would then inspect only the last of them and | |
| # miss a poetry.lock change in any earlier one, reporting | |
| # changed=false and skipping the verification entirely. | |
| # It is all zeros for the first push to a ref, and a force push | |
| # can leave it unreachable, so fall back to verifying. | |
| if [ -z "$before" ] || [ "$before" = "0000000000000000000000000000000000000000" ] \ | |
| || ! git cat-file -e "$before^{commit}" 2>/dev/null; then | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| elif git diff --name-only "$before" HEAD -- poetry.lock | grep -q .; then | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| elif [ -z "$base" ]; then | |
| # workflow_dispatch: nothing to compare against, so verify. | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| elif git diff --name-only "origin/$base...HEAD" -- poetry.lock | grep -q .; then | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Set up Python and Poetry | |
| if: steps.check-poetry-lock.outputs.changed == 'true' | |
| uses: ./.github/actions/install_python_poetry | |
| - name: Verify Python imports | |
| if: steps.check-poetry-lock.outputs.changed == 'true' | |
| env: | |
| PYTHONPATH: ./bin:./src | |
| run: | | |
| poetry check | |
| poetry run python ./.github/actions/verify_imports.py | |
| docker-build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Build and push Docker image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| file: ./Dockerfile | |
| tags: reactome-chatbot:${{ github.sha }} | |
| outputs: type=docker,dest=/tmp/image.tar | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: image-artifact | |
| path: /tmp/image.tar | |
| docker-push: | |
| if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }} | |
| needs: docker-build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| id-token: write # assume the AWS role via OIDC | |
| contents: read | |
| steps: | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| name: image-artifact | |
| path: /tmp | |
| - id: get-hash | |
| run: | | |
| FULL_SHA=${{ github.sha }} | |
| echo "SHORT_SHA=${FULL_SHA:0:7}" >> $GITHUB_OUTPUT | |
| - env: | |
| AWS_REGION: us-east-1 | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| role-to-assume: ${{ vars.AWS_ROLE }} | |
| aws-region: ${{ env.AWS_REGION }} | |
| - id: login-ecr | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| with: | |
| registry-type: public | |
| - env: | |
| AWS_REGISTRY: ${{ steps.login-ecr.outputs.registry }} | |
| AWS_REGISTRY_ALIAS: reactome | |
| AWS_REPO: reactome-chatbot | |
| IMG_TAG: ${{ steps.get-hash.outputs.SHORT_SHA }} | |
| run: | | |
| docker load --input /tmp/image.tar | |
| docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG | |
| docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest | |
| docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG | |
| docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest |