-
Notifications
You must be signed in to change notification settings - Fork 6
82 lines (74 loc) · 2.76 KB
/
integration.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# Run secret-dependent integration tests only after /ok-to-test approval
on:
pull_request: {}
repository_dispatch:
types: [ok-to-test-command]
name: Integration tests
jobs:
# Branch-based pull request
integration-trusted:
runs-on: ubuntu-latest
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
permissions:
id-token: write
steps:
- name: Branch based PR checkout
uses: actions/checkout@v2
- id: integration-test
uses: ./.github/actions/integration_tests
with:
boundary_policy: ${{ secrets.AWS_PERMISSIONS_BOUNDARY_ARN }}
env_suffix: ${{ github.event.pull_request.number }}
role_to_assume: ${{ secrets.AWS_ROLE_ARN }}
# Repo owner has commented /ok-to-test on a (fork-based) pull request
integration-fork:
runs-on: ubuntu-latest
if:
github.event_name == 'repository_dispatch' &&
github.event.client_payload.slash_command.sha != '' &&
contains(github.event.client_payload.pull_request.head.sha, github.event.client_payload.slash_command.sha)
permissions:
id-token: write
checks: write
contents: write
steps:
# Check out merge commit
- name: Fork based /ok-to-test checkout
uses: actions/checkout@v2
with:
ref: 'refs/pull/${{ github.event.client_payload.pull_request.number }}/merge'
- id: integration-test
uses: ./.github/actions/integration_tests
with:
boundary_policy: ${{ secrets.AWS_PERMISSIONS_BOUNDARY_ARN }}
env_suffix: ${{ github.event.client_payload.pull_request.number }}
role_to_assume: ${{ secrets.AWS_ROLE_ARN }}
# Update check run called "integration-fork"
- uses: actions/github-script@v1
id: update-check-run
if: ${{ always() }}
env:
number: ${{ github.event.client_payload.pull_request.number }}
job: ${{ github.job }}
# Conveniently, job.status maps to https://developer.github.com/v3/checks/runs/#update-a-check-run
conclusion: ${{ job.status }}
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const { data: pull } = await github.pulls.get({
...context.repo,
pull_number: process.env.number
});
const ref = pull.head.sha;
const { data: checks } = await github.checks.listForRef({
...context.repo,
ref
});
const check = checks.check_runs.filter(c => c.name === process.env.job);
const { data: result } = await github.checks.update({
...context.repo,
check_run_id: check[0].id,
status: 'completed',
conclusion: process.env.conclusion
});
return result;