Repository navigation
feat: harden AWS integration security and deployment evidence #179
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: ["main", "copilot/**"] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| lint-test-benchmark: | |
| name: Lint, Test, and Benchmark | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| cache-dependency-path: | | |
| requirements.txt | |
| requirements-dev.txt | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| python -m pip install -r requirements.txt -r requirements-dev.txt | |
| - name: Validate Compose demo configuration | |
| run: docker compose -f docker-compose.yml config | |
| - name: Format check | |
| run: black --check . --line-length=100 | |
| - name: Lint | |
| run: ruff check . | |
| - name: Type check | |
| run: | | |
| mypy models.py utils.py event_bus.py location_store.py matching_engine.py pricing_engine.py consumer.py \ | |
| --ignore-missing-imports | |
| - name: Run tests | |
| run: pytest --cov=. --cov-report=term-missing | |
| - name: Run benchmark harness | |
| run: python benchmarks/ride_sharing_benchmarks.py --iterations 250 --driver-count 100 --output benchmark-results.json | |
| - name: Validate benchmark JSON | |
| run: python -m json.tool benchmark-results.json > /tmp/benchmark-results.pretty.json | |
| - name: Upload benchmark artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: ride-sharing-benchmark-results | |
| path: benchmark-results.json | |
| - name: Workflow summary | |
| if: always() | |
| run: | | |
| { | |
| echo "## CI Summary" | |
| echo "" | |
| echo "- Python: 3.11" | |
| echo "- Checks: black, ruff, mypy, pytest" | |
| echo "- Benchmark artifact: benchmark-results.json" | |
| } >> "$GITHUB_STEP_SUMMARY" | |
| broker-integration: | |
| name: Broker adapter integration | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| cache-dependency-path: | | |
| requirements.txt | |
| requirements-dev.txt | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| python -m pip install -r requirements.txt -r requirements-dev.txt | |
| - name: Start Kafka, Redis, and RabbitMQ | |
| run: docker compose -f tests/integration/docker-compose.yml up --detach | |
| - name: Allow broker startup | |
| run: sleep 45 | |
| - name: Run broker integration tests | |
| run: pytest -m integration | |
| - name: Stop broker services | |
| if: always() | |
| run: docker compose -f tests/integration/docker-compose.yml down --volumes | |
| load-balancer-integration: | |
| name: Driver API load-balancer integration | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Validate NGINX configuration | |
| run: | | |
| docker run --rm \ | |
| -v "$PWD/nginx/driver-location-load-balancer.conf:/etc/nginx/nginx.conf:ro" \ | |
| nginx:1.27.5-alpine nginx -t | |
| - name: Start three driver API replicas behind the gateway | |
| env: | |
| EXPOSE_INSTANCE_ID: "true" | |
| run: | | |
| docker compose up --build --detach --scale driver-location-api=3 api-gateway | |
| - name: Verify readiness through the public gateway | |
| run: | | |
| for attempt in $(seq 1 45); do | |
| if curl --fail --silent --show-error http://localhost:8000/driver-location/ready > /dev/null; then | |
| exit 0 | |
| fi | |
| sleep 2 | |
| done | |
| echo "Gateway never became ready" >&2 | |
| docker compose ps | |
| docker compose logs --no-color driver-location-api api-gateway redis | |
| exit 1 | |
| - name: Verify the gateway reads shared Redis state | |
| run: | | |
| docker compose exec -T redis redis-cli HSET driver-locations ci-driver \ | |
| '{"driver_id":"ci-driver","lat":40.7128,"lon":-74.0060,"timestamp":"2026-01-01T00:00:00Z","status":"available"}' | |
| curl --fail --silent --show-error http://localhost:8000/driver-location/drivers/ci-driver \ | |
| | python -c "import json, sys; assert json.load(sys.stdin)['driver_id'] == 'ci-driver'" | |
| - name: Verify requests reach multiple replicas | |
| run: | | |
| for request in $(seq 1 18); do | |
| curl --fail --silent --show-error --dump-header - --output /dev/null \ | |
| http://localhost:8000/driver-location/health \ | |
| | tr -d '\r' | awk -F': ' 'tolower($1) == "x-instance-id" {print $2}' | |
| done | sort -u > /tmp/driver-api-replicas.txt | |
| cat /tmp/driver-api-replicas.txt | |
| test "$(wc -l < /tmp/driver-api-replicas.txt)" -ge 2 | |
| - name: Verify one backend loss does not take down readiness | |
| run: | | |
| docker ps --filter label=com.docker.compose.service=driver-location-api --format '{{.ID}}' \ | |
| | head -n 1 | xargs --no-run-if-empty docker stop | |
| for attempt in $(seq 1 15); do | |
| if curl --fail --silent --show-error http://localhost:8000/driver-location/ready > /dev/null; then | |
| exit 0 | |
| fi | |
| sleep 1 | |
| done | |
| echo "Gateway did not remain ready after one replica stopped" >&2 | |
| exit 1 | |
| - name: Stop Compose services | |
| if: always() | |
| run: docker compose down --volumes |