name: CI
on:
pull_request:
push:
tags:
- 'v[0-9]+.[0-9]+.[0-9]+'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
rust:
name: Rust (fmt / clippy / test / coverage)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Set up Rust stable
uses: dtolnay/rust-toolchain@stable
with:
components: clippy, rustfmt, llvm-tools-preview
- name: Cache Rust build artefacts
uses: Swatinem/rust-cache@v2
- name: cargo fmt
run: cargo fmt --all -- --check
- name: cargo clippy (all targets, all features)
run: cargo clippy --all-targets --all-features -- -D warnings
- name: cargo test (all features)
run: cargo test --all-features
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
- name: cargo llvm-cov
run: cargo llvm-cov --all-features --lcov --output-path lcov.info
- name: cargo build --release
run: cargo build --release
audit:
name: Security audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Run cargo-audit
uses: rustsec/audit-check@v2.0.0
with:
token: ${{ secrets.GITHUB_TOKEN }}
check-deps:
name: Check dependencies
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Install cargo-deny
uses: taiki-e/install-action@cargo-deny
- name: cargo deny check
run: cargo deny check
- name: Install cargo-hack
uses: taiki-e/install-action@cargo-hack
- name: cargo hack check
run: cargo hack check --feature-powerset --depth 2
typos:
name: Spell check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Run typos
uses: crate-ci/typos@v1.49.0
docker:
name: Docker image (build + smoke test)
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- uses: actions/checkout@v7
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Build Docker image (same build args as release)
uses: docker/build-push-action@v7
with:
context: .
push: false
load: true
tags: llm-browser-testkit:ci
cache-from: type=gha
cache-to: type=gha,mode=max
build-args: |
ENABLE_AWS_CLI=true
ENABLE_AZURE_CLI=true
- name: Verify binary is on PATH
run: |
docker run --rm --entrypoint sh llm-browser-testkit:ci -euc '
set -e
bin=$(command -v llm-browser-testkit)
echo "binary: $bin"
test "$bin" = "/usr/local/bin/llm-browser-testkit"
llm-browser-testkit --help | grep -q "Run a TOML test scenario"
test -x /usr/bin/chromium-browser
test -x /usr/bin/chromedriver
command -v aws
command -v az
'
- name: Verify job-container mode (boot alive + version + exec)
run: |
docker run -d --name kit-job llm-browser-testkit:ci
sleep 1
state=$(docker inspect -f '{{.State.Status}}' kit-job)
echo "container state: $state"
test "$state" = "running"
docker logs kit-job 2>&1 | grep -Eq 'llm-browser-testkit [0-9]+\.[0-9]+'
docker exec kit-job sh -c 'test -x /usr/local/bin/llm-browser-testkit'
docker exec kit-job llm-browser-testkit --help | grep -q "Run a TOML test scenario"
docker rm -f kit-job
- name: Browser smoke test (navigation + screenshot)
run: |
docker run --rm \
-v "${{ github.workspace }}/examples/docker-smoke.toml:/docker-smoke.toml:ro" \
-v "${{ github.workspace }}/examples/docker-smoke.html:/www/index.html:ro" \
--entrypoint sh llm-browser-testkit:ci -euc '
set -e
llm-browser-testkit run /docker-smoke.toml
test -s /tmp/container-smoke.png
'