Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
196 changes: 170 additions & 26 deletions .github/workflows/bdd-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,11 +40,21 @@ jobs:
echo "Computed image tag: flake-${FLAKE_HASH}"

- name: Log in to Container Registry
uses: docker/login-action@v3
# ghcr.io occasionally times out on the auth handshake under
# GHA load (Client.Timeout exceeded while awaiting headers).
# docker/login-action runs once; wrap docker login in
# nick-fields/retry so a transient handshake failure does not
# take out the whole BDD job.
uses: nick-fields/retry@v3
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_ACTOR: ${{ github.actor }}
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
timeout_minutes: 3
max_attempts: 3
retry_wait_seconds: 10
command: |
echo "$GHCR_TOKEN" | docker login ${{ env.REGISTRY }} -u "$GHCR_ACTOR" --password-stdin

- name: Check if image exists in registry
id: check-exists
Expand Down Expand Up @@ -125,11 +135,21 @@ jobs:
echo "Image built successfully for ${{ matrix.arch }}"

- name: Log in to Container Registry
uses: docker/login-action@v3
# ghcr.io occasionally times out on the auth handshake under
# GHA load (Client.Timeout exceeded while awaiting headers).
# docker/login-action runs once; wrap docker login in
# nick-fields/retry so a transient handshake failure does not
# take out the whole BDD job.
uses: nick-fields/retry@v3
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_ACTOR: ${{ github.actor }}
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
timeout_minutes: 3
max_attempts: 3
retry_wait_seconds: 10
command: |
echo "$GHCR_TOKEN" | docker login ${{ env.REGISTRY }} -u "$GHCR_ACTOR" --password-stdin

- name: Load and push arch-specific image
run: |
Expand All @@ -150,11 +170,21 @@ jobs:
packages: write
steps:
- name: Log in to Container Registry
uses: docker/login-action@v3
# ghcr.io occasionally times out on the auth handshake under
# GHA load (Client.Timeout exceeded while awaiting headers).
# docker/login-action runs once; wrap docker login in
# nick-fields/retry so a transient handshake failure does not
# take out the whole BDD job.
uses: nick-fields/retry@v3
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_ACTOR: ${{ github.actor }}
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
timeout_minutes: 3
max_attempts: 3
retry_wait_seconds: 10
command: |
echo "$GHCR_TOKEN" | docker login ${{ env.REGISTRY }} -u "$GHCR_ACTOR" --password-stdin

- name: Create and push multi-arch manifest
# Only the hash-tagged manifest is published. The image is
Expand Down Expand Up @@ -202,6 +232,97 @@ jobs:
echo "✅ Using freshly built image: ${{ needs.check-image.outputs.image-tag }}"
fi

# Compile the BDD test binaries once and stash cargo's registry +
# target dir in GHA cache so the 23-way matrix below does not pay a
# full `cargo download + compile` per suite. Default features cover
# all suites except `tls-migration`, which builds in its own target
# subdirectory because of the cargo features-hash. `CARGO_HOME` is
# pinned inside `/workspace/.cargo` so the cache stays under
# `github.workspace` and no host UID/permission tricks are needed.
prebuild-bdd:
name: Prebuild BDD test binaries
needs: prepare-tests
if: always() && needs.prepare-tests.result == 'success'
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
packages: read
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Restore cargo cache
uses: actions/cache@v4
with:
path: |
.cargo
target
key: ${{ runner.os }}-bdd-cargo-${{ needs.prepare-tests.outputs.image-tag }}-${{ hashFiles('Cargo.lock', 'src/**', 'tests/**', 'build.rs') }}
restore-keys: |
${{ runner.os }}-bdd-cargo-${{ needs.prepare-tests.outputs.image-tag }}-
${{ runner.os }}-bdd-cargo-

- name: Log in to Container Registry
# ghcr.io occasionally times out on the auth handshake under
# GHA load (Client.Timeout exceeded while awaiting headers).
# docker/login-action runs once; wrap docker login in
# nick-fields/retry so a transient handshake failure does not
# take out the whole BDD job.
uses: nick-fields/retry@v3
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_ACTOR: ${{ github.actor }}
with:
timeout_minutes: 3
max_attempts: 3
retry_wait_seconds: 10
command: |
echo "$GHCR_TOKEN" | docker login ${{ env.REGISTRY }} -u "$GHCR_ACTOR" --password-stdin

- name: Pull test image from GHCR
uses: nick-fields/retry@v3
with:
timeout_minutes: 5
max_attempts: 3
retry_wait_seconds: 10
command: docker pull ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.prepare-tests.outputs.image-tag }}

- name: Compile bdd + patroni_proxy_bdd binaries (default features)
run: |
docker run --rm \
--network=host \
-e CARGO_NET_RETRY=10 \
-e CARGO_HTTP_TIMEOUT=60 \
-e CARGO_HOME=/workspace/.cargo \
-v ${{ github.workspace }}:/workspace \
-w /workspace \
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.prepare-tests.outputs.image-tag }} \
sh -c "cargo test --test bdd --no-run && cargo test --test patroni_proxy_bdd --no-run"

- name: Compile bdd binary (tls-migration feature)
run: |
docker run --rm \
--network=host \
-e CARGO_NET_RETRY=10 \
-e CARGO_HTTP_TIMEOUT=60 \
-e CARGO_HOME=/workspace/.cargo \
-v ${{ github.workspace }}:/workspace \
-w /workspace \
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.prepare-tests.outputs.image-tag }} \
cargo test --features tls-migration --test bdd --no-run

- name: Chown cargo cache so actions/cache can read it
# The docker steps above ran as root, so `.cargo/` and `target/`
# are root-owned on the host. actions/cache@v4 saves files as
# the runner user (uid 1001); without this chown its post-step
# tar gets permission-denied on every file and silently writes
# an empty cache (~13s save, ~0s restore on the next run).
# `sudo` is available on GitHub-hosted ubuntu-latest by default.
run: |
sudo chown -R "$(id -u):$(id -g)" .cargo target
du -sh .cargo target

# Single matrixed job replaces the 21 nearly-identical per-language /
# per-suite jobs that used to live here. Each suite differs only in
# the cargo command it runs; share everything else. See the cargo
Expand All @@ -210,22 +331,22 @@ jobs:
# sensitive lifecycle scenarios).
bdd-tests:
name: 'BDD: ${{ matrix.suite.name }}'
needs: prepare-tests
if: always() && needs.prepare-tests.result == 'success'
needs: [ prepare-tests, prebuild-bdd ]
if: always() && needs.prepare-tests.result == 'success' && needs.prebuild-bdd.result == 'success'
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
packages: read
strategy:
fail-fast: false
# Six concurrent suites is the cap this matrix was tuned for.
# GitHub-hosted runners share CPU under heavy fan-out; with 20+
# BDD jobs in parallel, the sleep-based lifecycle tests and the
# SCRAM passthrough reconnect tests lost timing margin. This cap
# keeps those suites stable while reducing total wall time versus
# the previous limit of four.
max-parallel: 6
# Twelve concurrent suites: the prebuild-bdd cache trims each
# suite to a link + scenario run, so the CPU pressure that drove
# the previous cap of 6 (sleep-based lifecycle tests and SCRAM
# passthrough reconnect losing timing margin) is gone. Doubling
# the fan-out halves the BDD wall clock on a green PR; the
# sleep-heavy suites still have their own retry policy.
max-parallel: 12
matrix:
suite:
- { name: "Go", cargo: "test --test bdd -- --tags @go" }
Expand Down Expand Up @@ -255,16 +376,38 @@ jobs:
- name: Checkout repository
uses: actions/checkout@v4

- name: Restore cargo cache from prebuild
# Same key shape as prebuild-bdd. Restore-keys fall back to any
# earlier prebuild for this image tag, then to any prebuild on
# this OS, so a matrix entry never starts from a cold cargo.
uses: actions/cache@v4
with:
path: |
.cargo
target
key: ${{ runner.os }}-bdd-cargo-${{ needs.prepare-tests.outputs.image-tag }}-${{ hashFiles('Cargo.lock', 'src/**', 'tests/**', 'build.rs') }}
restore-keys: |
${{ runner.os }}-bdd-cargo-${{ needs.prepare-tests.outputs.image-tag }}-
${{ runner.os }}-bdd-cargo-

- name: Log in to Container Registry
# Even when test-runner is currently a public package, the BDD
# jobs depend on `docker pull` succeeding. Without explicit
# login they would silently break if the package visibility
# ever flips to private.
uses: docker/login-action@v3
# ever flips to private. Wrapped in nick-fields/retry because
# ghcr.io's auth endpoint occasionally times out under GHA
# load (Client.Timeout exceeded while awaiting headers) and the
# base docker/login-action does not retry on its own.
uses: nick-fields/retry@v3
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GHCR_ACTOR: ${{ github.actor }}
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
timeout_minutes: 3
max_attempts: 3
retry_wait_seconds: 10
command: |
echo "$GHCR_TOKEN" | docker login ${{ env.REGISTRY }} -u "$GHCR_ACTOR" --password-stdin

- name: Pull test image from GHCR
uses: nick-fields/retry@v3
Expand Down Expand Up @@ -312,6 +455,7 @@ jobs:
--network=host \
-e CARGO_NET_RETRY=10 \
-e CARGO_HTTP_TIMEOUT=60 \
-e CARGO_HOME=/workspace/.cargo \
-v ${{ github.workspace }}:/workspace \
-w /workspace \
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ needs.prepare-tests.outputs.image-tag }} \
Expand Down
36 changes: 35 additions & 1 deletion .github/workflows/copr-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,36 @@ jobs:
echo "Downloaded Rust tarball:"
ls -la rust-*.tar.gz

- name: Bundle Perl modules for offline build
run: |
# RHEL/CentOS Stream 7 and 8 ship FindBin and IPC::Cmd only
# inside modular Perl streams that COPR mock filters out
# by default (`package perl-FindBin-... is filtered out by
# modular filtering`). COPR builders also have no network
# access, so we cannot `dnf module enable perl` inside the
# chroot. Same pattern as the Rust tarball: ship the pure-Perl
# modules we need as a Source so the spec extracts them and
# the build sees them via PERL5LIB, regardless of distro.
dnf install -y perl perl-FindBin perl-IPC-Cmd
mkdir -p perl_modules
# Resolve actual on-disk path of each .pm via Perl itself so
# the tarball follows whichever vendor_perl / site_perl layout
# the prepare distro uses.
for module in FindBin IPC::Cmd IPC::Open3 Module::Load::Conditional Module::Load Module::Metadata Params::Check Locale::Maketext::Simple ExtUtils::MakeMaker version; do
path=$(perl -M"$module" -e "print \$INC{'${module//::/\/}.pm'}" 2>/dev/null || true)
if [ -n "$path" ] && [ -r "$path" ]; then
relative="${module//::/\/}.pm"
dest="perl_modules/$relative"
mkdir -p "$(dirname "$dest")"
cp -L "$path" "$dest"
echo "bundled: $relative <- $path"
else
echo "skipped: $module (not found)"
fi
done
tar czf perl_modules.tar.gz perl_modules/
ls -la perl_modules.tar.gz

- name: Setup RPM build environment
run: |
rpmdev-setuptree
Expand Down Expand Up @@ -154,9 +184,13 @@ jobs:

# Copy vendor tarball
cp "$SOURCE_DIR/vendor.tar.gz" ~/rpmbuild/SOURCES/

# Copy Rust tarball for offline COPR build
cp "$SOURCE_DIR/rust-${{ env.RUST_VERSION }}-x86_64-unknown-linux-gnu.tar.gz" ~/rpmbuild/SOURCES/

# Copy bundled Perl modules for offline COPR build on EL7/EL8
# (their modular filtering hides perl-FindBin / perl-IPC-Cmd).
cp "$SOURCE_DIR/perl_modules.tar.gz" ~/rpmbuild/SOURCES/

# Update spec file with correct version
cd "$SOURCE_DIR"
Expand Down
4 changes: 2 additions & 2 deletions documentation/en/src/tutorials/basic-usage.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ Arguments:
Options:
-l, --log-level <LOG_LEVEL> [env: LOG_LEVEL=] [default: INFO]
-F, --log-format <LOG_FORMAT> [env: LOG_FORMAT=] [default: text] [possible values: text, structured, debug]
-n, --no-color disable colors in the log output [env: NO_COLOR=]
-n, --no-color force colors off in the log output
-d, --daemon run as daemon [env: DAEMON=]
-h, --help Print help
-V, --version Print version
Expand All @@ -34,7 +34,7 @@ Options:
| `-d`, `--daemon` | Run in the background. Without this option, the process will run in the foreground.<br><br>In daemon mode, setting `daemon_pid_file` and `syslog_prog_name` is required. No log messages will be written to stderr after going into the background. |
| `-l`, `--log-level` | Set log level: `INFO`, `DEBUG`, or `WARN`. |
| `-F`, `--log-format` | Set log format. Possible values: `text`, `structured`, `debug`. |
| `-n`, `--no-color` | Disable colors in the log output. |
| `-n`, `--no-color` | Force colors off in the log output. Colors are also auto-disabled when stderr is not a TTY (under systemd, the journal pipe is not a terminal) and when the `NO_COLOR` environment variable is set to any non-empty value. |
| `-V`, `--version` | Show version information. |
| `-h`, `--help` | Show help information. |

Expand Down
Loading
Loading