# Oikos CI (Gitea Actions). Gates the deploy webhook on a green run (plan M1). # Mirrors `make lint`, `make test`, and the generated-code drift guard. name: ci on: push: branches: [main] pull_request: jobs: build-test: runs-on: ubuntu-latest services: postgres: image: timescale/timescaledb:2.17.2-pg16 env: POSTGRES_DB: oikos POSTGRES_USER: oikos POSTGRES_PASSWORD: oikos_dev ports: - 5432:5432 options: >- --health-cmd "pg_isready -U oikos" --health-interval 5s --health-timeout 5s --health-retries 10 env: OIKOS_TEST_DATABASE_URL: postgres://oikos:oikos_dev@postgres:5432/oikos?sslmode=disable steps: - uses: actions/checkout@v4 - uses: actions/setup-go@v5 with: go-version: "1.26" cache: true - name: go vet run: go vet ./... - name: golangci-lint uses: golangci/golangci-lint-action@v6 with: version: latest args: --timeout 5m continue-on-error: true # advisory until the lint baseline is clean - name: govulncheck run: | go install golang.org/x/vuln/cmd/govulncheck@latest govulncheck ./... || true # advisory - name: generated code is up to date run: make generate-check - name: build run: go build ./... - name: test (race + coverage) run: go test -race -covermode=atomic -coverprofile=coverage.out -timeout 300s ./... - name: coverage gates (policy + learning ≥ 80%, others ≥ 60%) run: | go tool cover -func=coverage.out | tail -1 # Note: policy/ and learning/ packages land in Phase 3; enforce # their 80% gate then. For now, report total coverage. docker-build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: docker build (verify image builds; no push) run: docker build -f compose/oikos/Dockerfile -t oikos:ci .