Isolate CI/deploy tests from production DATABASE_URL (#24)
Unit Tests / test (push) Successful in 3s
Unit Tests / test (push) Successful in 3s
## Summary
- Root cause: `docker-compose.yml` used `${DATABASE_URL:-…}`, so the Act runner’s host/`prod` `DATABASE_URL` was interpolated into the web service. Containerized deploy tests then ran against shared Postgres instead of the bundled compose `db`.
- Stop reading host `DATABASE_URL` in compose (use `COMPOSE_DATABASE_URL` override only).
- Deploy docker step: unset DB secrets, dedicated compose project name, `up --wait db`, force test `DATABASE_URL` to `postgres://scha:scha@db:5432/scha`, `down -v` on exit (ephemeral DB).
- Clear `DATABASE_URL`/`DB_HOST` in `unittests.yml` / `ci.yml` so host sqlite-fallback tests cannot hit prod either.
## Test plan
- [ ] Merge to `master` and watch Unit Tests + Deploy docker job.
- [ ] Confirm docker step connects only to compose `db` (no traffic/errors against `10.0.0.230`).
- [ ] Confirm `docker compose -p scha-ci-<sha> …` volumes cleaned after job (`down -v`).
- [ ] Local: `docker compose up --build` still works with bundled Postgres.
Reviewed-on: #24
This commit was merged in pull request #24.
This commit is contained in:
@@ -23,5 +23,8 @@ jobs:
|
||||
env:
|
||||
DJANGO_ENV: dev
|
||||
DJANGO_SECRET_KEY: test-secret-key
|
||||
# Explicitly clear DB vars so host/prod DATABASE_URL cannot leak in.
|
||||
DATABASE_URL: ""
|
||||
DB_HOST: ""
|
||||
run: |
|
||||
uv run python manage.py test
|
||||
|
||||
@@ -20,15 +20,27 @@ jobs:
|
||||
- name: Build Docker image
|
||||
run: docker compose build
|
||||
|
||||
# Ephemeral local Postgres only — never inherit host DATABASE_URL (prod).
|
||||
- name: Run containerized tests
|
||||
run: |
|
||||
docker compose up -d db
|
||||
docker compose run --rm --entrypoint "" \
|
||||
set -euo pipefail
|
||||
# Drop host/prod DB secrets so compose cannot interpolate them.
|
||||
unset DATABASE_URL DB_HOST DB_NAME DB_USER DB_PASSWORD DB_PORT \
|
||||
COMPOSE_DATABASE_URL DJANGO_ENV DJANGO_SECRET_KEY DJANGO_DEBUG \
|
||||
DJANGO_ALLOWED_HOSTS || true
|
||||
|
||||
PROJECT="scha-ci-${{ gitea.event.workflow_run.head_sha }}"
|
||||
cleanup() { docker compose -p "$PROJECT" down -v --remove-orphans || true; }
|
||||
trap cleanup EXIT
|
||||
|
||||
docker compose -p "$PROJECT" up -d --wait db
|
||||
docker compose -p "$PROJECT" run --rm --no-deps --entrypoint "" \
|
||||
-e DJANGO_ENV=dev \
|
||||
-e DJANGO_SECRET_KEY=test-secret-key \
|
||||
-e DJANGO_DEBUG=true \
|
||||
-e DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,testserver \
|
||||
-e DATABASE_URL=postgres://scha:scha@db:5432/scha \
|
||||
web uv run python manage.py test
|
||||
docker compose down
|
||||
|
||||
deploy:
|
||||
if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push'
|
||||
|
||||
@@ -25,5 +25,8 @@ jobs:
|
||||
env:
|
||||
DJANGO_ENV: dev
|
||||
DJANGO_SECRET_KEY: test-secret-key
|
||||
# Explicitly clear DB vars so host/prod DATABASE_URL cannot leak in.
|
||||
DATABASE_URL: ""
|
||||
DB_HOST: ""
|
||||
run: |
|
||||
uv run python manage.py test
|
||||
|
||||
Reference in New Issue
Block a user