Skip to content

feat: harden AWS integration security and deployment evidence #179

feat: harden AWS integration security and deployment evidence

feat: harden AWS integration security and deployment evidence #179

Workflow file for this run

name: CI
on:
push:
branches: ["main", "copilot/**"]
pull_request:
permissions:
contents: read
jobs:
lint-test-benchmark:
name: Lint, Test, and Benchmark
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: |
requirements.txt
requirements-dev.txt
- name: Install dependencies
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt -r requirements-dev.txt
- name: Validate Compose demo configuration
run: docker compose -f docker-compose.yml config
- name: Format check
run: black --check . --line-length=100
- name: Lint
run: ruff check .
- name: Type check
run: |
mypy models.py utils.py event_bus.py location_store.py matching_engine.py pricing_engine.py consumer.py \
--ignore-missing-imports
- name: Run tests
run: pytest --cov=. --cov-report=term-missing
- name: Run benchmark harness
run: python benchmarks/ride_sharing_benchmarks.py --iterations 250 --driver-count 100 --output benchmark-results.json
- name: Validate benchmark JSON
run: python -m json.tool benchmark-results.json > /tmp/benchmark-results.pretty.json
- name: Upload benchmark artifact
uses: actions/upload-artifact@v4
with:
name: ride-sharing-benchmark-results
path: benchmark-results.json
- name: Workflow summary
if: always()
run: |
{
echo "## CI Summary"
echo ""
echo "- Python: 3.11"
echo "- Checks: black, ruff, mypy, pytest"
echo "- Benchmark artifact: benchmark-results.json"
} >> "$GITHUB_STEP_SUMMARY"
broker-integration:
name: Broker adapter integration
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: |
requirements.txt
requirements-dev.txt
- name: Install dependencies
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt -r requirements-dev.txt
- name: Start Kafka, Redis, and RabbitMQ
run: docker compose -f tests/integration/docker-compose.yml up --detach
- name: Allow broker startup
run: sleep 45
- name: Run broker integration tests
run: pytest -m integration
- name: Stop broker services
if: always()
run: docker compose -f tests/integration/docker-compose.yml down --volumes
load-balancer-integration:
name: Driver API load-balancer integration
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Validate NGINX configuration
run: |
docker run --rm \
-v "$PWD/nginx/driver-location-load-balancer.conf:/etc/nginx/nginx.conf:ro" \
nginx:1.27.5-alpine nginx -t
- name: Start three driver API replicas behind the gateway
env:
EXPOSE_INSTANCE_ID: "true"
run: |
docker compose up --build --detach --scale driver-location-api=3 api-gateway
- name: Verify readiness through the public gateway
run: |
for attempt in $(seq 1 45); do
if curl --fail --silent --show-error http://localhost:8000/driver-location/ready > /dev/null; then
exit 0
fi
sleep 2
done
echo "Gateway never became ready" >&2
docker compose ps
docker compose logs --no-color driver-location-api api-gateway redis
exit 1
- name: Verify the gateway reads shared Redis state
run: |
docker compose exec -T redis redis-cli HSET driver-locations ci-driver \
'{"driver_id":"ci-driver","lat":40.7128,"lon":-74.0060,"timestamp":"2026-01-01T00:00:00Z","status":"available"}'
curl --fail --silent --show-error http://localhost:8000/driver-location/drivers/ci-driver \
| python -c "import json, sys; assert json.load(sys.stdin)['driver_id'] == 'ci-driver'"
- name: Verify requests reach multiple replicas
run: |
for request in $(seq 1 18); do
curl --fail --silent --show-error --dump-header - --output /dev/null \
http://localhost:8000/driver-location/health \
| tr -d '\r' | awk -F': ' 'tolower($1) == "x-instance-id" {print $2}'
done | sort -u > /tmp/driver-api-replicas.txt
cat /tmp/driver-api-replicas.txt
test "$(wc -l < /tmp/driver-api-replicas.txt)" -ge 2
- name: Verify one backend loss does not take down readiness
run: |
docker ps --filter label=com.docker.compose.service=driver-location-api --format '{{.ID}}' \
| head -n 1 | xargs --no-run-if-empty docker stop
for attempt in $(seq 1 15); do
if curl --fail --silent --show-error http://localhost:8000/driver-location/ready > /dev/null; then
exit 0
fi
sleep 1
done
echo "Gateway did not remain ready after one replica stopped" >&2
exit 1
- name: Stop Compose services
if: always()
run: docker compose down --volumes