Skip to content

chore: remove the appliance code that moved to cryptos-appliance #436

chore: remove the appliance code that moved to cryptos-appliance

chore: remove the appliance code that moved to cryptos-appliance #436

Workflow file for this run

name: Go CI (format, lint, vet, test, build)
# Go validation on a GitHub-hosted Linux runner. Mirrors `task ci`
# (fmt + proto lint + generated-code check + lint + vet + test + build). Runs on PRs and pushes to main.
# Skip when a change touches only non-Go files (Markdown, docs, or issue
# templates). A mixed change still runs, since paths-ignore only skips when
# every changed file matches.
on:
push:
branches: [main]
paths-ignore:
- "**.md"
- "docs/**"
- ".github/ISSUE_TEMPLATE/**"
pull_request:
branches: [main]
types: [opened, synchronize, reopened, ready_for_review]
paths-ignore:
- "**.md"
- "docs/**"
- ".github/ISSUE_TEMPLATE/**"
permissions:
contents: read
# One run per PR per workflow: a new push cancels the older PR run. Pushes to
# main are never cancelled, so every main commit keeps a result.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
go-validation:
name: Go validation (format, lint, vet, test, build)
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache: true
- name: Install go-task
run: go install github.com/go-task/task/v3/cmd/task@latest
- name: Install golangci-lint
# Built from source with this job's Go (>= the go.mod version) so its
# analyzers can load code that requires that Go; a prebuilt binary
# built with an older Go panics on newer language/std usage.
run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2
- name: Install buf
# task ci lints the node API protos and regenerates gen/go to check it
# is current. The release binary is checked against the SHA-256 its
# release publishes (sha256.txt); bump both together.
env:
BUF_VERSION: 1.73.0
BUF_SHA256: 8f2986298ad08f0cc1bf999b9797b7c383adf32d7edf0f73d6f1e1a701baeac1
run: |
set -euo pipefail
bin="$RUNNER_TEMP/bin"
mkdir -p "$bin"
curl -sSfL -o "$bin/buf" \
"https://github.com/bufbuild/buf/releases/download/v${BUF_VERSION}/buf-Linux-x86_64"
echo "${BUF_SHA256} $bin/buf" | sha256sum -c -
chmod +x "$bin/buf"
echo "$bin" >> "$GITHUB_PATH"
- name: Install swtpm
# The TPM-held RSA CA end-to-end test needs a TPM that implements
# RSA-3072. The in-process simulator stops at RSA-2048, and the test
# fails rather than skips under CI when swtpm is missing.
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends swtpm
- name: Build sscep for the SCEP interoperability tests
# internal/scep runs a real SCEP client against the server and fails
# under CI when it has none. Built from the pinned release tarball,
# checksum-checked, since no prebuilt binary is published.
env:
SSCEP_VERSION: 0.10.0
SSCEP_SHA256: 489cc8e093986776eb3f15082bf766778f707176f3cd604bf0ef1008da06b8e5
run: |
cd "$RUNNER_TEMP"
curl -fsSL -o sscep.tar.gz "https://github.com/certnanny/sscep/archive/refs/tags/v${SSCEP_VERSION}.tar.gz"
echo "${SSCEP_SHA256} sscep.tar.gz" | sha256sum -c -
tar xzf sscep.tar.gz
cmake -S "sscep-${SSCEP_VERSION}" -B sscep-build -DCMAKE_BUILD_TYPE=Release
cmake --build sscep-build
echo "CRYPTOS_TEST_SSCEP=$RUNNER_TEMP/sscep-build/sscep" >> "$GITHUB_ENV"
- name: Run task ci
run: task ci
- name: Check tree is clean
run: git diff --exit-code