Switch deploy target to GCP Cloud Run gen2 #22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy to Staging | |
| on: | |
| push: | |
| branches: | |
| - main | |
| workflow_dispatch: | |
| jobs: | |
| test: | |
| name: Test | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| actions: read | |
| checks: write | |
| pull-requests: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: ["3.12"] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up Python ${{ matrix.python-version }} | |
| id: python-setup | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install Poetry | |
| run: pip install poetry | |
| - name: Install dependencies | |
| run: poetry install | |
| - name: Lint with flake8 | |
| run: | | |
| poetry run flake8 ./evaluation_function --count --select=E9,F63,F7,F82 --show-source --statistics | |
| poetry run flake8 ./evaluation_function --count --exit-zero --max-complexity=10 --max-line-length=127 --statistics | |
| - name: Run tests | |
| if: always() | |
| run: poetry run pytest --junit-xml=./reports/pytest.xml --tb=auto -v | |
| - name: Upload test results | |
| uses: actions/upload-artifact@v4 | |
| if: always() | |
| with: | |
| name: test-results-${{ matrix.python-version }} | |
| path: ./reports/pytest.xml | |
| if-no-files-found: warn | |
| deploy: | |
| needs: test | |
| permissions: | |
| contents: write | |
| packages: write | |
| id-token: write | |
| uses: lambda-feedback/evaluation-function-workflows/.github/workflows/deploy.yml@main | |
| with: | |
| template-repository-name: "lambda-feedback/evaluation-function-boilerplate-python" | |
| # gcp -> Cloud Run gen2 (see gcp_deploy.yml). gen2 gives full-Linux | |
| # compatibility so shimmy's nsjail sandbox (SANDBOX_ENABLED=true in the | |
| # Dockerfile) can create user namespaces -- AWS Lambda cannot. | |
| build-platforms: "gcp" | |
| environment: "staging" | |
| lfs: false | |
| secrets: | |
| aws-key-id: ${{ secrets.LAMBDA_CONTAINER_PIPELINE_AWS_ID }} | |
| aws-secret-key: ${{ secrets.LAMBDA_CONTAINER_PIPELINE_AWS_SECRET}} | |
| function-admin-api-key: ${{ secrets.FUNCTION_ADMIN_API_KEY}} | |
| gcp_credentials: ${{ secrets.GCP_DEPLOY }} |