ci: require manual gated releases from main
All checks were successful
Build and deploy / Validate source (push) Successful in 1m28s
Build and deploy / Integration suite on a real stack (push) Successful in 4m3s
Build and deploy / Secret scan and release gate (push) Successful in 11s
Build and deploy / Publish images and notify Portainer (push) Has been skipped

This commit is contained in:
Cauê Faleiros
2026-09-23 11:27:18 -03:00
parent 24013458c9
commit cfcbe545f1
9 changed files with 137 additions and 93 deletions

View File

@@ -1,8 +1,27 @@
import unittest
from pathlib import Path
from .production_preflight import config_errors, source_errors
class ReleaseWorkflowTests(unittest.TestCase):
def test_main_push_cannot_publish_and_manual_release_is_gated(self):
workflow = (Path(__file__).resolve().parents[1] /
'.gitea/workflows/deploy.yml').read_text()
release = workflow.split(' publish-and-deploy:\n', 1)[1]
self.assertIn("if: gitea.event_name == 'workflow_dispatch' && "
"gitea.ref == 'refs/heads/main'", release)
preflight = release.index('python3 deploy/production_preflight.py --source-only')
webhook = release.index('test -n "$PORTAINER_WEBHOOK"')
scan = release.index('- name: Image vulnerabilities')
publish = release.index('- name: Publish validated images')
redeploy = release.index('- name: Trigger Portainer redeployment')
self.assertLess(preflight, scan)
self.assertLess(webhook, scan)
self.assertLess(scan, publish)
self.assertLess(publish, redeploy)
def valid_config():
digest = '1' * 64
values = {