Skip to content

ci: add runtime smoke test that boots each image and checks health - #179

Open
amitkojha05 wants to merge 3 commits into
keitaroinc:masterfrom
amitkojha05:ci/smoke-test
Open

amitkojha05 wants to merge 3 commits into
keitaroinc:masterfrom
amitkojha05:ci/smoke-test

Conversation

@amitkojha05

@amitkojha05 amitkojha05 commented Oct 5, 2026 •

Copy link
Copy Markdown

Problem

CI lints, builds, and Trivy-scans the images, but never starts one. A change that builds cleanly but breaks startup (a bad Alpine package pin, a failing ckan db init, a broken prerun.py or start_ckan.sh) passes every check and ships to Docker Hub and GHCR. This also means the weekly update_dockerfiles.yml package-bump PRs are never verified at runtime.

Change

One new smoke_test job in .github/workflows/ci.yml. It runs per CKAN version through the existing matrix_generator, on pull requests only, like lint and build.

For each version it:

  1. Reads the full CKAN version from the Dockerfile's ENV IMAGE_TAG (for example 2.12 -> 2.12.0).
  2. Builds the image with docker/build-push-action (load: true, push: false) and tags it ghcr.io/keitaroinc/ckan:<IMAGE_TAG>, the name the compose ckan service references, so compose uses the PR's build instead of pulling the published image. It reads the same GitHub Actions layer cache (cache-from: type=gha) that the build job populates.
  3. Checks that docker compose config resolves to that image. compose/config/.global-env pins CKAN_VERSION=2.12.0, so this step fails the job if the shell override ever stops taking effect, rather than silently testing the wrong version.
  4. Brings up the repo's own compose/ stack (db, solr, redis, ckan), so there are no separate service images to keep in sync.
  5. Polls /api/3/action/status_show, the endpoint the Dockerfile HEALTHCHECK uses, for up to 5 minutes. On timeout it prints the recent CKAN logs and fails.
  6. On any failure, a separate step dumps docker compose ps -a and logs for all services, so a db or Solr startup failure is diagnosable too.
  7. Always tears the stack down with docker compose down -v.

The job also sets timeout-minutes: 30 and permissions: contents: read.

No existing jobs or files are modified.

Testing

Tested locally on 2.10, 2.11 and 2.12: for each, CKAN boots and /api/3/action/status_show returns "success": true. The Smoke Test job will also run in CI for all three versions once a maintainer approves the workflow run.

Notes

  • The job is PR-only to match lint and build. Removing the if: github.event_name == 'pull_request' line would also run it on the weekly schedule to catch upstream drift. Happy to do that if you prefer.
  • It is an amd64-only runtime check, because arm64 under emulation would be too slow. The build job still covers both architectures.

@amitkojha05

Copy link
Copy Markdown
Author

Hi @Filip3mac @mihajlo-kuzmanoski , this PR adds a CI job, so the workflow is waiting for a maintainer to approve the run. Could one of you approve it so the Smoke Test results show up for 2.10, 2.11 and 2.12?If anything fails, I'll fix it right away. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant