DoDiODev opened a new pull request, #9069:
URL: https://github.com/apache/devlake/pull/9069

   ### Summary
   
   This PR consolidates CI and deployment pins that had drifted away from the 
versions DevLake is actually developed and operated against. It replaces 
floating database image tags in the E2E workflow and the Kubernetes sample 
manifest, refreshes the builder-image publish workflow, migrates the YAML lint 
job to the maintained Super-Linter namespace, and lifts every mockery 
installation site to a single current version.
   
   There are **no Go module changes, no schema or migration-script changes, no 
API changes and no frontend changes**. Nothing here alters product behaviour: 
the diff is limited to CI workflows, the Kubernetes sample manifest, the 
builder images and the mockery bootstrap.
   
   <details>
   <summary>10 changed files, +14 / −14</summary>
   
   ```
   .github/workflows/build-builder.yml
   .github/workflows/golangci-lint.yml
   .github/workflows/test-e2e.yml
   .github/workflows/test.yml
   .github/workflows/yaml-lint.yml
   backend/Dockerfile.local
   backend/Makefile
   backend/scripts/install-mockery.sh
   devops/deployment/k8s/k8s-deploy.yaml
   devops/docker/lake-builder/Dockerfile
   ```
   
   </details>
   
   ---
   
   ### 1. `build(ci): pin active database images`
   
   | File | Before | After | Rationale |
   |---|---|---|---|
   | `.github/workflows/test-e2e.yml` | `mysql:8` | `mysql:8.4.11` | Floating 
major tag; the active dev/remote E2E stacks run 8.4.11. |
   | `.github/workflows/test-e2e.yml` | `postgres:14.2` | `postgres:18.4` | 
Four majors behind the version DevLake is operated on. |
   | `devops/deployment/k8s/k8s-deploy.yaml` | `mysql:8` | `mysql:8.4.11` | 
Same floating tag in the sample deployment. |
   
   Historical artefacts under `devops/releases/**` are intentionally left 
untouched.
   
   ### 2. `ci(builder): refresh runner and login action`
   
   | File | Before | After | Rationale |
   |---|---|---|---|
   | `build-builder.yml` | `runs-on: ubuntu-20.04` | `ubuntu-24.04` | 
`ubuntu-20.04` is retired on GitHub-hosted runners. |
   | `build-builder.yml` | `docker/login-action@f054a8b…` | 
`docker/login-action@dbcb8138…` `# v4.6.0` | The pinned commit dates from 
2021-06-22. Still an immutable SHA, now with a version comment. |
   
   Buildx was evaluated and deliberately **not** introduced: the workflow's 
direct `docker build` has no concrete need for it, and mixing that in would 
hide a build-system change behind a pin refresh.
   
   ### 3. `ci: migrate YAML lint to Super-Linter v8`
   
   | File | Before | After | Rationale |
   |---|---|---|---|
   | `yaml-lint.yml` | `github/super-linter/slim@v4` | 
`super-linter/super-linter/slim@4ce20838…` `# v8.7.0` | The 
`github/super-linter` repository ends at v7; the maintained continuation lives 
under `super-linter/super-linter`. |
   
   The narrow `FILTER_REGEX_INCLUDE` scope 
(`workspace/(docker-compose.yml|deployment/k8s/k8s-deploy.yaml)`) is preserved 
unchanged, so the job keeps linting exactly the same two files. The v8 action 
needs no additional environment variables or permissions for this scope.
   
   ### 4. `build(deps): bump mockery to 3.7.4`
   
   Follow-up to #9029, which introduced mockery v3.7.2. All active installation 
sites move in lockstep so the CI bootstrap, the Makefile target and the builder 
images cannot drift apart:
   
   | File | Site |
   |---|---|
   | `.github/workflows/test.yml` | bootstrap step before the unit tests |
   | `.github/workflows/golangci-lint.yml` | bootstrap step before `make mock` 
in the lint job |
   | `backend/scripts/install-mockery.sh` | `MOCKERY_VERSION` + both release 
SHA-256 sums |
   | `backend/Makefile` | `go-dep` target |
   | `backend/Dockerfile.local` | local builder image |
   | `devops/docker/lake-builder/Dockerfile` | published builder image |
   
   The two pinned archive checksums were verified against the official 
`vektra/mockery` v3.7.4 `checksum.txt`:
   
   ```
   d5eef52e238a4262b78ab5a93811826a8bfcff7b0128133c6597e3bf2f0f7337  
mockery_3.7.4_Linux_x86_64.tar.gz
   fe591f9ef5ada76c3dee4b8f451aad6748d002e9713fab4bad26b194ff826c4b  
mockery_3.7.4_Linux_arm64.tar.gz
   ```
   
   `make mock` under v3.7.4 regenerates all 65 mock files with an identical 
tree hash, so **no generated code is part of this PR**. The v3 configuration 
files `.mockery.core.yml` and `.mockery.helpers.yml` are unchanged, as is their 
required ordering (helper mocks import generated core mocks).
   
   Both third-party action pins were re-verified against their tags before 
opening:
   
   ```
   docker/login-action        v4.6.0  -> 
dbcb813823bdd20940b903addbd779551569679f
   super-linter/super-linter  v8.7.0  -> 
4ce20838b8ab83717e78138c5b3a1407148e0918
   ```
   
   ---
   
   ### Validation
   
   - YAML parser over all five changed workflows and the K8s manifest
   - `kubectl apply --dry-run=client --validate=false` on the K8s manifest
   - `bash -n backend/scripts/install-mockery.sh`
   - SHA-256 comparison against the official mockery v3.7.4 release 
`checksum.txt`
   - `make mock` with mockery v3.7.4: 65 files regenerated, **zero diff**
   - `make build`: all plugins, mocks, Swagger generation and the server
   - `make unit-test-go`: exit code 0, 554 passing packages, no failures
   
   Two fork-CI runs, both **9/9 green**, covering `builder image`, `lint (go)`, 
`migration-script-lint`, `unit-test`, `e2e (mysql)`, `e2e (postgres)`, 
`config-ui`, `check Apache license header` and `check grafana dashboards`:
   
   | Run | Base | Result |
   |---|---|---|
   | 
[32739264272](https://github.com/DoDiODev/devlake/actions/runs/32739264272) | 
on top of #9061 | 9/9 |
   | 
[32741016217](https://github.com/DoDiODev/devlake/actions/runs/32741016217) | 
on top of plain `main` | 9/9 |
   
   An `e2e (postgres)` job was **added** to the fork-CI harness for this proof, 
because the previous harness only ran MySQL and therefore never exercised the 
`postgres:18.4` pin. The builder image is rebuilt from 
`devops/docker/lake-builder/Dockerfile` on the branch, so both runs also 
validate the mockery 3.7.4 installation.
   
   ### Note on an earlier `Error 1091`
   
   An early fork-CI run of this branch failed in `e2e (mysql)` on `Error 1091` 
in the Jira `TestMigrationSchema`. That was **not** caused by the MySQL pin: a 
baseline run without any of these files reproduced it identically. The root 
cause was the GORM `v1.31` upgrade in #9061 and was fixed there. The run on the 
plain `main` baseline confirms the `mysql:8.4.11` pin itself is sound.
   
   This PR is **independent of #9061** — it applies cleanly to `main` and is 
CI-verified on that base.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to