-
Notifications
You must be signed in to change notification settings - Fork 21
207 lines (197 loc) · 5.96 KB
/
Copy pathstatic.yml
File metadata and controls
207 lines (197 loc) · 5.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
name: static checks
on:
workflow_dispatch:
push:
branches:
- main
pull_request:
jobs:
flake-check:
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: nix flake check
run: |
nix -L flake check
generate:
runs-on: ubuntu-24.04
timeout-minutes: 60
permissions:
contents: write
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ !github.event.pull_request.head.repo.fork && github.head_ref || '' }}
token: ${{ !github.event.pull_request.head.repo.fork && secrets.NUNKI_CI_COMMIT_PUSH_PR || github.token }}
persist-credentials: true
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run code generations & tidying
run: |
nix run ".#${SET}.scripts.generate"
- name: Check for modifications, commit changes on renovate PRs
uses: ./.github/actions/pushdiff
with:
error: Generated code needs to be updated, check the GitHub run summary for the diff.
suggested-fix: Run \`nix run ".#${SET}.scripts.generate"\` to run code generation.
renovate-commit-msg: "fixup: update generated code"
govulncheck:
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: true
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run govulncheck
run: |
nix run ".#${SET}.scripts.govulncheck"
golangci-lint:
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
strategy:
fail-fast: false
matrix:
goos: [linux, darwin]
env:
SET: base
GOOS: ${{ matrix.goos }}
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run golangci-lint
run: |
nix run ".#${SET}.scripts.golangci-lint"
go-licenses:
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run go-licenses
run: |
nix run ".#${SET}.scripts.go-licenses-check"
sdk-wasm-compat:
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Compile SDK for Wasm
env:
GOOS: js
GOARCH: wasm
run: |
cat <<EOF > ./main.go
package main
import _ "github.com/edgelesssys/contrast/sdk"
func main() {}
EOF
go build -tags contrast_unstable_api -o main.wasm ./main.go
- name: Check Wasm code size
run: |
if [ "$(stat -c%s main.wasm)" -gt 25000000 ]; then
echo "Compiled SDK exceeds size limit of 25MB"
exit 1
fi
cli-build:
runs-on: ubuntu-24.04
timeout-minutes: 60
permissions:
contents: read
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Build CLI
run: |
nix build ".#${SET}.contrast.cli"
darwin-cli-build:
needs: cli-build
runs-on: macos-latest
timeout-minutes: 60
permissions:
contents: read
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Build darwin formatter
run: |
nix build .#formatter.aarch64-darwin
- name: Build darwin CLI
run: |
nix build ".#${SET}.contrast.cli"
sev-snp-measure-consistency:
runs-on: ubuntu-24.04
timeout-minutes: 30
permissions:
contents: read
env:
SET: base
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- uses: ./.github/actions/setup_nix
with:
githubToken: ${{ secrets.GITHUB_TOKEN }}
cachixToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
- name: Run sev-snp-measure-consistency
run: |
nix run ".#${SET}.scripts.sev-snp-measure-consistency"