name: ci on: pull_request: push: branches: [main] jobs: api: runs-on: ubuntu-latest services: postgres: image: postgres:16-alpine env: { POSTGRES_USER: rarelens, POSTGRES_PASSWORD: rarelens, POSTGRES_DB: rarelens } ports: ["5432:5432"] options: --health-cmd "pg_isready -U rarelens" --health-interval 5s --health-retries 10 steps: - uses: actions/checkout@v4 - uses: astral-sh/setup-uv@v3 - run: uv pip install --system -e "api[dev]" - run: cd api && ruff check . && mypy app - run: cd api && pytest -q env: DATABASE_URL: postgresql+asyncpg://rarelens:rarelens@localhost:5432/rarelens REQUIRE_DB: "1" ml: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: astral-sh/setup-uv@v3 - run: uv pip install --system -e "ml[dev]" - run: cd ml && pytest -q web: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: { node-version: 22, cache: npm, cache-dependency-path: web/package-lock.json } - run: cd web && npm ci && npm run check && npm test && npm run build pipeline: runs-on: ubuntu-latest services: postgres: image: postgres:16-alpine env: { POSTGRES_USER: rarelens, POSTGRES_PASSWORD: rarelens, POSTGRES_DB: rarelens } ports: ["5432:5432"] options: --health-cmd "pg_isready -U rarelens" --health-interval 5s --health-retries 10 steps: - uses: actions/checkout@v4 - uses: astral-sh/setup-uv@v3 - run: uv pip install --system -r pipeline/requirements.txt pytest - run: cd pipeline && pytest -q tests env: DATABASE_URL: postgresql://rarelens:rarelens@localhost:5432/rarelens REQUIRE_DB: "1" - uses: nf-core/setup-nextflow@v2 # Stub run checks wiring and channel shapes only; no containers or VEP cache needed. - run: cd pipeline && nextflow run main.nf -stub-run --vcf tests/data/tiny.vcf terraform: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: hashicorp/setup-terraform@v3 - run: cd infra/terraform && terraform init -backend=false && terraform fmt -check && terraform validate images: if: github.ref == 'refs/heads/main' needs: [api, ml, web, pipeline] runs-on: ubuntu-latest permissions: { contents: read, id-token: write } strategy: matrix: include: - { component: api, context: api, dockerfile: api/Dockerfile } - { component: web, context: web, dockerfile: web/Dockerfile } - { component: ml, context: ml, dockerfile: ml/Dockerfile } - { component: pipeline, context: pipeline, dockerfile: pipeline/Dockerfile } - { component: loader, context: pipeline, dockerfile: pipeline/loader.Dockerfile } env: REGISTRY: europe-west2-docker.pkg.dev/${{ secrets.GCP_PROJECT }}/rarelens steps: - uses: actions/checkout@v4 - uses: google-github-actions/auth@v2 with: workload_identity_provider: ${{ secrets.GCP_WIF_PROVIDER }} service_account: ${{ secrets.GCP_CI_SA }} - run: gcloud auth configure-docker europe-west2-docker.pkg.dev --quiet - uses: docker/build-push-action@v6 with: context: ${{ matrix.context }} file: ${{ matrix.dockerfile }} push: true # Only the pipeline driver uses it: pins the loader image from the same commit. build-args: LOADER_IMAGE=${{ env.REGISTRY }}/loader:${{ github.sha }} tags: ${{ env.REGISTRY }}/${{ matrix.component }}:${{ github.sha }}