name: PR Checks on: pull_request: branches: - main env: REGISTRY: privaterepo.sitaru.org BACKEND_IMAGE_NAME: ${{ gitea.repository }}-backend FRONTEND_IMAGE_NAME: ${{ gitea.repository }}-frontend PIPELINE_IMAGE_NAME: ${{ gitea.repository }}-pipeline jobs: frontend-checks: name: Frontend Typecheck + Tests runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Node.js uses: actions/setup-node@v4 with: node-version: 22 cache: npm cache-dependency-path: nextjs-app/package-lock.json - name: Install dependencies working-directory: nextjs-app run: npm ci - name: Typecheck working-directory: nextjs-app run: npm run typecheck - name: Unit tests working-directory: nextjs-app run: npm test backend-checks: name: Backend Smoke runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Python uses: actions/setup-python@v5 with: python-version: "3.12" - name: Install dependencies run: pip install -r requirements.txt - name: Import smoke test run: python -c "from backend.app import app; print('backend imports OK')" build-backend: name: Build Backend (no push) runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: buildkitd-config-inline: | [registry."docker.io"] mirrors = ["10.0.1.224:6000"] [registry."10.0.1.224:6000"] http = true insecure = true - name: Log in to Gitea Container Registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ gitea.actor }} password: ${{ secrets.REGISTRY_TOKEN }} - name: Build Backend Docker image uses: docker/build-push-action@v5 with: context: . file: ./Dockerfile push: false cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ env.BACKEND_IMAGE_NAME }}:buildcache build-frontend: name: Build Frontend (no push) runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: buildkitd-config-inline: | [registry."docker.io"] mirrors = ["10.0.1.224:6000"] [registry."10.0.1.224:6000"] http = true insecure = true - name: Log in to Gitea Container Registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ gitea.actor }} password: ${{ secrets.REGISTRY_TOKEN }} - name: Build Frontend Docker image uses: docker/build-push-action@v5 with: context: ./nextjs-app file: ./nextjs-app/Dockerfile push: false build-args: | FASTAPI_URL=http://backend:80/api build-pipeline: name: Build Pipeline (no push) runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 with: buildkitd-config-inline: | [registry."docker.io"] mirrors = ["10.0.1.224:6000"] [registry."10.0.1.224:6000"] http = true insecure = true - name: Log in to Gitea Container Registry uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} username: ${{ gitea.actor }} password: ${{ secrets.REGISTRY_TOKEN }} - name: Build Pipeline Docker image uses: docker/build-push-action@v5 with: context: ./pipeline file: ./pipeline/Dockerfile push: false cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ env.PIPELINE_IMAGE_NAME }}:buildcache ai-review: name: AI Code Review (Claude) runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v4 with: fetch-depth: 0 - name: Set up Python uses: actions/setup-python@v5 with: python-version: "3.12" - name: Set up Node.js uses: actions/setup-node@v4 with: node-version: 22 - name: Install Claude Code run: npm install -g @anthropic-ai/claude-code - name: Review PR diff with Claude Code env: CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} GITEA_TOKEN: ${{ secrets.REGISTRY_TOKEN }} GITEA_SERVER_URL: ${{ gitea.server_url }} GITEA_REPOSITORY: ${{ gitea.repository }} PR_NUMBER: ${{ gitea.event.pull_request.number }} BASE_REF: ${{ gitea.event.pull_request.base.ref }} run: python scripts/ci/ai_review.py