name: ci on: pull_request: push: branches: [main] jobs: api: runs-on: ubuntu-latest services: postgres: image: postgres:16-alpine env: { POSTGRES_USER: rarelens, POSTGRES_PASSWORD: rarelens, POSTGRES_DB: rarelens } ports: ["5432:5432"] options: --health-cmd "pg_isready -U rarelens" --health-interval 5s --health-retries 10 steps: - uses: actions/checkout@v4 - uses: astral-sh/setup-uv@v3 - run: uv pip install --system -e "api[dev]" - run: cd api && ruff check . && mypy app - run: cd api && pytest -q env: { DATABASE_URL: postgresql+asyncpg://rarelens:rarelens@localhost:5432/rarelens } web: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: 22, cache: npm, cache-dependency-path: web/package-lock.json } - run: cd web && npm ci && npm run check && npm test && npm run build pipeline: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: nf-core/setup-nextflow@v2 - run: cd pipeline && nextflow run main.nf -profile docker --vcf ../data/example.vcf.gz -stub-run terraform: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: hashicorp/setup-terraform@v3 - run: cd infra/terraform && terraform init -backend=false && terraform fmt -check && terraform validate images: if: github.ref == 'refs/heads/main' needs: [api, web, pipeline] runs-on: ubuntu-latest permissions: { contents: read, id-token: write } strategy: matrix: { component: [api, web, pipeline, ml] } steps: - uses: actions/checkout@v4 - uses: google-github-actions/auth@v2 with: workload_identity_provider: ${{ secrets.GCP_WIF_PROVIDER }} service_account: ${{ secrets.GCP_CI_SA }} - run: gcloud auth configure-docker europe-west2-docker.pkg.dev --quiet - uses: docker/build-push-action@v6 with: context: ${{ matrix.component }} push: true tags: europe-west2-docker.pkg.dev/${{ secrets.GCP_PROJECT }}/rarelens/${{ matrix.component }}:${{ github.sha }}