-
Notifications
You must be signed in to change notification settings - Fork 4
226 lines (218 loc) · 8.27 KB
/
Copy pathci.yml
File metadata and controls
226 lines (218 loc) · 8.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
name: CI
on:
push:
# develop too: the agent loop pushes it directly, with no PR, so without
# this nothing checks its range until the release PR (R14)
branches: [master, develop]
# v + semver only (glob, so the release job re-checks it exactly)
tags: ['v[0-9]*.[0-9]*.[0-9]*']
pull_request:
workflow_dispatch:
# Default for every job; release and pypi declare the extra grants they need
permissions:
contents: read
jobs:
backend:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v7
with:
python-version: '3.12'
cache: pip
# The requirements files are pointers into pyproject.toml, where
# the dependency list actually lives
cache-dependency-path: |
pyproject.toml
requirements.txt
requirements-test.txt
# System libs opencv-python needs at import
- run: sudo apt-get update && sudo apt-get install -y libgl1 libglib2.0-0
# CPU wheels: an order of magnitude smaller than CUDA, and the suite
# is mocked - the two tests that run a real generation skip themselves
# when no accelerator is present
- name: Install torch (CPU)
run: pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cpu
- name: Install dependencies
# requirements.txt resolves pyproject.toml's dependencies + server
# extra; requirements-test.txt the dev extra. diffusers from git
# goes on afterwards so the resolver doesn't replace it with a
# release
run: |
pip install -c constraints-openapi.txt -r requirements.txt -r requirements-test.txt
pip install git+https://github.com/huggingface/diffusers
- name: Format check
run: ruff format --check dw dw_mcp tests scripts
- name: Lint
run: ruff check dw dw_mcp tests scripts
- name: Tests
run: pytest -q
# Guards the architecture metrics against drifting past the committed
# baseline (modules, size ceiling, cycles); see docs/stabilization/
- name: Architecture ratchet
run: python scripts/arch_metrics.py --check docs/stabilization/baseline.json
ui:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ui
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version-file: ui/.nvmrc
cache: npm
cache-dependency-path: ui/package-lock.json
- run: npm ci
# The UI's response types are generated from the server's OpenAPI
# document (scripts/dump_openapi.py writes it; the backend job's
# tests/test_api_contract.py fails when it is stale). A stale
# api-schema.ts fails here; a field the UI reads that the server no
# longer sends fails the type check below
- name: Response contract
run: npm run gen:api && git diff --exit-code src/lib/generated
- name: Format check
run: npx prettier --check src e2e scripts *.ts *.js
- name: Lint
run: npm run lint
- name: Architecture ratchet
run: npm run metrics -- --check ../docs/stabilization/ui/baseline.json
- name: Type check
run: npm run check
- name: Unit tests
run: npm test
- name: Build
run: npm run build
e2e:
# Playwright against a real dw.serve before develop moves - on PRs into
# develop or master, and on pushes to develop, since the agent loop
# pushes develop directly with no PR. The release PR (this repo's
# develop into master) is skipped: its every commit is a develop push,
# already run. The job carries the backend install as well as the browser
if: >-
(github.event_name == 'pull_request' &&
(github.base_ref == 'develop' || github.base_ref == 'master') &&
!(github.head_ref == 'develop' &&
github.event.pull_request.head.repo.full_name == github.repository)) ||
(github.event_name == 'push' && github.ref == 'refs/heads/develop')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v7
with:
python-version: '3.12'
cache: pip
cache-dependency-path: |
pyproject.toml
requirements.txt
requirements-test.txt
- run: sudo apt-get update && sudo apt-get install -y libgl1 libglib2.0-0
- name: Install torch (CPU)
run: pip install torch torchvision torchaudio --index-url https://download.pytorch.org/whl/cpu
- name: Install dependencies
run: |
pip install -c constraints-openapi.txt -r requirements.txt -r requirements-test.txt
pip install git+https://github.com/huggingface/diffusers
- uses: actions/setup-node@v7
with:
node-version-file: ui/.nvmrc
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Build the UI the fixture server serves
working-directory: ui
run: |
npm ci
npm run build
- name: Install Chromium
working-directory: ui
run: npx playwright install --with-deps chromium
- name: E2E tests
working-directory: ui
env:
DW_E2E_PYTHON: python
run: npx playwright test
- name: Upload the Playwright report
if: failure()
uses: actions/upload-artifact@v7
with:
name: playwright-report
path: |
ui/playwright-report/
ui/test-results/
retention-days: 7
wheel:
# The packaged artifact: SPA built into the wheel. Tags and manual runs
# only - the jobs above already prove the build on every push.
if: startsWith(github.ref, 'refs/tags/v') || github.event_name == 'workflow_dispatch'
needs: [backend, ui]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version-file: ui/.nvmrc
cache: npm
cache-dependency-path: ui/package-lock.json
- uses: actions/setup-python@v7
with:
python-version: '3.12'
- run: cd ui && npm ci
- run: pip install build
- run: bash scripts/build_dist.sh
- uses: actions/upload-artifact@v7
with:
name: diffusers-workflow-dist
path: dist/*
release:
# A v<semver> tag that passed the full test and build chain becomes a
# GitHub release carrying the wheel and sdist
if: startsWith(github.ref, 'refs/tags/v')
needs: wheel
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v7
- name: Check the tag against the declared versions
run: |
tag="${GITHUB_REF_NAME#v}"
if ! echo "$tag" | grep -Eq '^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$'; then
echo "Tag $GITHUB_REF_NAME is not v<semver>"; exit 1
fi
pyproject=$(python3 -c "import tomllib; print(tomllib.load(open('pyproject.toml','rb'))['project']['version'])")
if [ "$tag" != "$pyproject" ]; then
echo "Tag $tag != pyproject version $pyproject"
exit 1
fi
- uses: actions/download-artifact@v8
with:
name: diffusers-workflow-dist
path: dist
- name: Create GitHub release
env:
GH_TOKEN: ${{ github.token }}
# A pre-release marker in the tag (v1.2.3-rc1) marks the release too
run: |
prerelease=""
case "$GITHUB_REF_NAME" in *-*) prerelease="--prerelease";; esac
gh release create "$GITHUB_REF_NAME" dist/* \
--repo "$GITHUB_REPOSITORY" \
--title "$GITHUB_REF_NAME" \
--generate-notes --verify-tag $prerelease
pypi:
# Trusted publishing (OIDC) - register on pypi.org first: project
# diffusers-workflow, owner dkackman, repo diffusers-workflow,
# workflow ci.yml, environment pypi. No token or secret is stored.
needs: release
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/p/diffusers-workflow
permissions:
id-token: write
steps:
- uses: actions/download-artifact@v8
with:
name: diffusers-workflow-dist
path: dist
- uses: pypa/gh-action-pypi-publish@v1.14.2