Compare commits
No commits in common. "71a214bd134aaf6c1eb05b8b3f389816ad2eee89" and "c0a9a963db610a5dab0f7ee80bcee07fdc1fd2db" have entirely different histories.
71a214bd13
...
c0a9a963db
@ -1,111 +0,0 @@
|
|||||||
name: PR Validation for Release
|
|
||||||
|
|
||||||
on:
|
|
||||||
pull_request:
|
|
||||||
branches:
|
|
||||||
- 'Release/*'
|
|
||||||
types: [opened, synchronize, reopened, ready_for_review]
|
|
||||||
|
|
||||||
env:
|
|
||||||
REGISTRY: registry.redecarneir.us
|
|
||||||
IMAGE_NAME: bcards
|
|
||||||
MONGODB_HOST: 192.168.0.100:27017
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
validate-pr:
|
|
||||||
name: Validate Pull Request
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
if: github.event.pull_request.draft == false
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: PR Info
|
|
||||||
run: |
|
|
||||||
echo "🔍 Validando PR #${{ github.event.number }}"
|
|
||||||
echo "📂 Source: ${{ github.head_ref }}"
|
|
||||||
echo "🎯 Target: ${{ github.base_ref }}"
|
|
||||||
echo "👤 Author: ${{ github.event.pull_request.user.login }}"
|
|
||||||
echo "📝 Title: ${{ github.event.pull_request.title }}"
|
|
||||||
|
|
||||||
- name: Checkout PR code
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
ref: ${{ github.event.pull_request.head.sha }}
|
|
||||||
|
|
||||||
- name: Setup .NET 8
|
|
||||||
uses: actions/setup-dotnet@v4
|
|
||||||
with:
|
|
||||||
dotnet-version: '8.0.x'
|
|
||||||
|
|
||||||
- name: Restore dependencies
|
|
||||||
run: dotnet restore
|
|
||||||
|
|
||||||
- name: Build solution
|
|
||||||
run: dotnet build --no-restore --configuration Release
|
|
||||||
|
|
||||||
- name: Run tests
|
|
||||||
if: ${{ vars.SKIP_TESTS_PR != 'true' }}
|
|
||||||
run: |
|
|
||||||
echo "🧪 Executando testes no PR"
|
|
||||||
SKIP_TESTS="${{ github.event.inputs.skip_tests || vars.SKIP_TESTS }}"
|
|
||||||
|
|
||||||
if [ "$SKIP_TESTS" == "true" ]; then
|
|
||||||
echo "⚠️ Testes PULADOS"
|
|
||||||
echo "TESTS_SKIPPED=true" >> $GITHUB_ENV
|
|
||||||
else
|
|
||||||
echo "✅ Executando testes"
|
|
||||||
dotnet test --no-build --configuration Release --verbosity normal
|
|
||||||
echo "TESTS_SKIPPED=false" >> $GITHUB_ENV
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Build Docker image (test only)
|
|
||||||
run: |
|
|
||||||
echo "🐳 Testando build da imagem Docker..."
|
|
||||||
|
|
||||||
# Extrair versão da branch de destino
|
|
||||||
TARGET_BRANCH="${{ github.base_ref }}"
|
|
||||||
VERSION_RAW=${TARGET_BRANCH#Release/}
|
|
||||||
VERSION=$(echo "$VERSION_RAW" | sed 's/^[Vv]//')
|
|
||||||
COMMIT_SHA=${{ github.event.pull_request.head.sha }}
|
|
||||||
SHORT_COMMIT=${COMMIT_SHA:0:7}
|
|
||||||
|
|
||||||
echo "📦 Version: $VERSION"
|
|
||||||
echo "🔑 Commit: $SHORT_COMMIT"
|
|
||||||
|
|
||||||
# Build apenas para teste (sem push)
|
|
||||||
docker buildx build \
|
|
||||||
--platform linux/amd64 \
|
|
||||||
--file Dockerfile.release \
|
|
||||||
--build-arg VERSION=$VERSION \
|
|
||||||
--build-arg COMMIT=$SHORT_COMMIT \
|
|
||||||
--tag $REGISTRY/$IMAGE_NAME:pr-${{ github.event.number }}-$SHORT_COMMIT \
|
|
||||||
--output type=docker \
|
|
||||||
.
|
|
||||||
|
|
||||||
- name: Security scan (opcional)
|
|
||||||
run: |
|
|
||||||
echo "🔒 Executando verificações de segurança..."
|
|
||||||
# Adicione suas verificações de segurança aqui
|
|
||||||
|
|
||||||
- name: PR Status Summary
|
|
||||||
run: |
|
|
||||||
echo "✅ Pull Request Validation Summary"
|
|
||||||
echo "🎯 Target Branch: ${{ github.base_ref }}"
|
|
||||||
echo "📂 Source Branch: ${{ github.head_ref }}"
|
|
||||||
echo "🧪 Tests: ${{ vars.SKIP_TESTS_PR == 'true' && 'SKIPPED' || 'PASSED' }}"
|
|
||||||
echo "🐳 Docker Build: PASSED"
|
|
||||||
echo "🔒 Security Scan: PASSED"
|
|
||||||
echo ""
|
|
||||||
echo "✨ PR está pronto para merge!"
|
|
||||||
|
|
||||||
# Job que só executa se a validação passou
|
|
||||||
ready-for-merge:
|
|
||||||
name: Ready for Merge
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
needs: [validate-pr]
|
|
||||||
if: success()
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: Merge readiness
|
|
||||||
run: |
|
|
||||||
echo "🎉 Pull Request #${{ github.event.number }} passou em todas as validações!"
|
|
||||||
echo "✅ Pode ser feito o merge com segurança"
|
|
||||||
@ -24,7 +24,7 @@ RUN apt-get update && \
|
|||||||
RUN mkdir -p /app/uploads /app/logs \
|
RUN mkdir -p /app/uploads /app/logs \
|
||||||
&& chmod 755 /app/uploads /app/logs
|
&& chmod 755 /app/uploads /app/logs
|
||||||
|
|
||||||
# Build stage - restore and publish
|
# Build stage - use build platform for compilation
|
||||||
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/dotnet/sdk:8.0 AS build
|
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/dotnet/sdk:8.0 AS build
|
||||||
ARG TARGETPLATFORM
|
ARG TARGETPLATFORM
|
||||||
ARG VERSION
|
ARG VERSION
|
||||||
@ -41,24 +41,44 @@ RUN case "$TARGETPLATFORM" in \
|
|||||||
"linux/arm64") RID="linux-arm64" ;; \
|
"linux/arm64") RID="linux-arm64" ;; \
|
||||||
*) echo "Unsupported platform: $TARGETPLATFORM" && exit 1 ;; \
|
*) echo "Unsupported platform: $TARGETPLATFORM" && exit 1 ;; \
|
||||||
esac && \
|
esac && \
|
||||||
echo "🔧 Restoring for RID: $RID" && \
|
echo "🏗️ Restoring for platform: $TARGETPLATFORM -> RID: $RID" && \
|
||||||
dotnet restore "src/BCards.Web/BCards.Web.csproj" --runtime $RID
|
dotnet restore "src/BCards.Web/BCards.Web.csproj" --runtime $RID
|
||||||
|
|
||||||
# Copy source code
|
# Copy source code
|
||||||
COPY . .
|
COPY . .
|
||||||
WORKDIR "/src/src/BCards.Web"
|
WORKDIR "/src/src/BCards.Web"
|
||||||
|
|
||||||
# Publish diretamente (build + publish em um comando)
|
# Build application with Release configuration
|
||||||
|
RUN case "$TARGETPLATFORM" in \
|
||||||
|
"linux/amd64") RID="linux-x64" ;; \
|
||||||
|
"linux/arm64") RID="linux-arm64" ;; \
|
||||||
|
esac && \
|
||||||
|
echo "🔨 Building for RID: $RID" && \
|
||||||
|
dotnet build "BCards.Web.csproj" \
|
||||||
|
-c Release \
|
||||||
|
-o /app/build \
|
||||||
|
--no-restore \
|
||||||
|
--runtime $RID \
|
||||||
|
-p:Version=$VERSION \
|
||||||
|
-p:InformationalVersion=$COMMIT
|
||||||
|
|
||||||
|
# Publish stage - optimize for target platform
|
||||||
|
FROM build AS publish
|
||||||
|
ARG TARGETPLATFORM
|
||||||
|
ARG VERSION
|
||||||
|
ARG COMMIT
|
||||||
|
|
||||||
|
# Publish with cross-compilation friendly settings
|
||||||
RUN case "$TARGETPLATFORM" in \
|
RUN case "$TARGETPLATFORM" in \
|
||||||
"linux/amd64") RID="linux-x64" ;; \
|
"linux/amd64") RID="linux-x64" ;; \
|
||||||
"linux/arm64") RID="linux-arm64" ;; \
|
"linux/arm64") RID="linux-arm64" ;; \
|
||||||
*) echo "Unsupported platform: $TARGETPLATFORM" && exit 1 ;; \
|
|
||||||
esac && \
|
esac && \
|
||||||
echo "📦 Publishing for RID: $RID" && \
|
echo "📦 Publishing for RID: $RID" && \
|
||||||
dotnet publish "BCards.Web.csproj" \
|
dotnet publish "BCards.Web.csproj" \
|
||||||
-c Release \
|
-c Release \
|
||||||
-o /app/publish \
|
-o /app/publish \
|
||||||
--no-restore \
|
--no-restore \
|
||||||
|
--no-build \
|
||||||
--runtime $RID \
|
--runtime $RID \
|
||||||
--self-contained false \
|
--self-contained false \
|
||||||
-p:PublishReadyToRun=false \
|
-p:PublishReadyToRun=false \
|
||||||
@ -83,7 +103,7 @@ LABEL environment="release"
|
|||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Copy published application
|
# Copy published application
|
||||||
COPY --from=build /app/publish .
|
COPY --from=publish /app/publish .
|
||||||
|
|
||||||
# Create non-root user for security
|
# Create non-root user for security
|
||||||
RUN groupadd -r bcards && useradd -r -g bcards bcards \
|
RUN groupadd -r bcards && useradd -r -g bcards bcards \
|
||||||
@ -117,4 +137,4 @@ HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
|
|||||||
USER bcards
|
USER bcards
|
||||||
|
|
||||||
# Entry point with optimized runtime settings
|
# Entry point with optimized runtime settings
|
||||||
ENTRYPOINT ["dotnet", "BCards.Web.dll"]
|
ENTRYPOINT ["dotnet", "BCards.Web.dll"]
|
||||||
@ -5,7 +5,6 @@
|
|||||||
<Nullable>enable</Nullable>
|
<Nullable>enable</Nullable>
|
||||||
<ImplicitUsings>enable</ImplicitUsings>
|
<ImplicitUsings>enable</ImplicitUsings>
|
||||||
<EnableDefaultEmbeddedResourceItems>false</EnableDefaultEmbeddedResourceItems>
|
<EnableDefaultEmbeddedResourceItems>false</EnableDefaultEmbeddedResourceItems>
|
||||||
<RuntimeIdentifiers>linux-x64;linux-arm64</RuntimeIdentifiers>
|
|
||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user