diff --git a/.github/workflows/README.md b/.github/workflows/README.md new file mode 100644 index 0000000..4a07a00 --- /dev/null +++ b/.github/workflows/README.md @@ -0,0 +1,50 @@ +# GitHub Workflows — Nova Platform CI/CD Catalog + +This directory contains the 7 GitHub Actions workflows for the Nova +platform. 3 are byte-identical Gitea mirrors (generated from +`workflows-src/` by `scripts/sync_workflows.py`, P8/REQ-172); 4 are +GitHub-only (Gitea act_runner feature gaps). + +## Shared workflows (byte-identical Gitea + GitHub) + +These 3 are generated from `workflows-src/` by +`scripts/sync_workflows.py`; the `.gitea/workflows/` mirror is kept +byte-identical. Run `python3 scripts/sync_workflows.py --check` to verify +no drift. + +| Workflow | Trigger | Inputs | Required Secrets | Purpose | +|----------|---------|--------|------------------|---------| +| `ci.yml` | `pull_request: [main]` | — | — | Lint + test + check-only (runs on every PR) | +| `deploy.yml` | `workflow_call` (reusable) + `push: [main]` | `contract` (string, required), `mode` (string, default `deploy`), `changeRequestId` (string), `environment` (string) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_KMS_KEY_ID`, `NOVA_LAMBDA_URL` | Reusable deploy workflow (invoked by consumer repos via `uses: acdl/.github/workflows/deploy.yml@v1.15`) | +| `modules-lifecycle.yml` | `pull_request: [main]` + `workflow_dispatch` | `lifecycle_mode` (string, default `plan` — `plan` or `full`) | `NOVA_AWS_ACCESS_KEY_ID`, `NOVA_AWS_SECRET_ACCESS_KEY`, `NOVA_AWS_DEFAULT_REGION`, `NOVA_AWS_ACCOUNT_ID` | L1 + L2 module lifecycle pipeline (plan-only default; full apply/modify/destroy on override) | + +## GitHub-only workflows (no Gitea mirror) + +These 4 have no Gitea counterpart (Gitea act_runner lacks the features +they require — reusable workflows, matrix `needs`, release API). See +`.gitea/workflows/README.md` for the limitation rationale. + +| Workflow | Trigger | Inputs | Required Secrets | Purpose | +|----------|---------|--------|------------------|---------| +| `platform-test.yml` | `pull_request: [main]` | — | — | Lint + unit + integration + schema-validation (replaces `ci.yml` for PRs) | +| `primitives-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L1 primitives (matrix) | +| `patterns-plan.yml` | `pull_request: [main]` | — | `NOVA_AWS_*` | Plan-only for all L2 modules (matrix) | +| `release.yml` | `push: [main]` | — | `NOVA_GITEA_TOKEN` (for Gitea release API) | Semver tag + MAJOR.MINOR/MAJOR floating-tag maintenance + release creation on merge to main | + +## Reusable deploy workflow (`deploy.yml`) + +Consumer repos invoke the deploy workflow via a versioned tag: + +```yaml +jobs: + deploy: + uses: acdl/.github/workflows/deploy.yml@v1.15 + with: + contract: .nova/contract.yml + environment: dev + secrets: inherit +``` + +The workflow checks out the consumer repo + the Nova platform repo, runs +`scripts/run_platform.sh`, and posts deploy outputs as a PR comment + +to SSM Parameter Store. \ No newline at end of file diff --git a/tests/test_docs_coverage.py b/tests/test_docs_coverage.py index d8ea3a7..0534565 100644 --- a/tests/test_docs_coverage.py +++ b/tests/test_docs_coverage.py @@ -34,4 +34,15 @@ class TestDocsCoverage: assert "How to Write an Adapter" in content assert "How to Wire" in content assert "How to Test" in content - assert "Existing Adapters" in content \ No newline at end of file + assert "Existing Adapters" in content + +def test_github_workflows_readme_catalogs_all_workflows(): + """P16 (REQ-180): .github/workflows/README.md catalogs all 7 workflows.""" + from pathlib import Path + readme = Path(__file__).resolve().parent.parent / ".github" / "workflows" / "README.md" + assert readme.is_file(), ".github/workflows/README.md missing" + text = readme.read_text() + for wf in ["ci.yml", "deploy.yml", "modules-lifecycle.yml", + "platform-test.yml", "primitives-plan.yml", "patterns-plan.yml", + "release.yml"]: + assert wf in text, f"{wf} not cataloged in .github/workflows/README.md"