Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1,7 +1,32 @@
Dockerfile
.git
.github
.docker
.bundle
.env
.env.*
!.env.example
.npmrc
.gem/credentials
.ssh
.aws
.config/gcloud
build
coverage
dist
log
node_modules
tmp
vendor
student-work
config/master.key
config/credentials
config/credentials.yml.enc
**/*.key
**/*.pem
**/*.p12
**/*.pfx
**/*.jks
**/*.keystore
test
test_files
11 changes: 11 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Optional values for development through the legacy root docker-compose.yml.
# Copy to .env. Database authentication remains the safe default. Never commit
# an institution credential or reuse a production registration.
DF_AUTH_METHOD=database
DF_AAF_ISSUER_URL=
DF_AAF_AUDIENCE_URL=http://localhost:3000
DF_AAF_CALLBACK_URL=http://localhost:3000/api/auth/jwt
DF_AAF_IDENTITY_PROVIDER_URL=
DF_AAF_UNIQUE_URL=
DF_AAF_AUTH_SIGNOUT_URL=
DF_SECRET_KEY_AAF=
14 changes: 14 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Set update schedule for GitHub Actions and Ruby dependencies

version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
# Check for updates to GitHub Actions every week
interval: "weekly"
- package-ecosystem: "bundler"
directory: "/"
schedule:
# Check for updates to Ruby gems every week
interval: "weekly"
25 changes: 16 additions & 9 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,16 +13,23 @@ name: "CodeQL"

on:
push:
branches: ["development"]
pull_request:
# The branches below must be a subset of the branches above
branches: ["development"]
branches: ["11.0.x", "development"]
# CodeQL is a required check, so it must report for pull requests targeting
# any protected shared branch rather than only the branches listed above.
pull_request: {}
schedule:
- cron: "45 20 * * 3"

# A push to an open pull request would otherwise start a second analysis while
# the first is still running. Cancel the superseded run so only the newest head
# of each ref is analysed.
concurrency:
group: codeql-${{ github.ref }}
cancel-in-progress: true

jobs:
analyze:
name: Analyze
name: CodeQL
runs-on: ubuntu-latest
permissions:
actions: read
Expand All @@ -38,11 +45,11 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
Expand All @@ -55,7 +62,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
uses: github/codeql-action/autobuild@v3
uses: github/codeql-action/autobuild@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3

# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
Expand All @@ -68,4 +75,4 @@ jobs:
# ./location_of_script_within_repo/buildscript.sh

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@6d786de4d6f3531a740e445b53a42b622bbbace8 # v3
75 changes: 30 additions & 45 deletions .github/workflows/deployment.yml
Original file line number Diff line number Diff line change
@@ -1,45 +1,36 @@
name: create-doubtfire-deployment
name: Legacy image validation (non-publishing)
on:
push:
tags:
- "v*"
# branches:
# - '*.x'
# - 'development'
# - 'main'
deployment:
workflow_dispatch:

permissions:
contents: read

jobs:
docker-deploy-development-image:
if: github.repository_owner == 'doubtfire-lms'
environment: doubtfire
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to DockerHub
uses: docker/login-action@v3
if: github.event_name != 'pull_request'
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- name: Setup meta for development image
id: docker_meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
with:
images: lmsdoubtfire/doubtfire-api
tags: |
type=semver,pattern={{major}}.{{minor}}.x-dev
type=sha,prefix=manual-
- name: Build and push api server
id: docker_build
uses: docker/build-push-action@v5
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
push: ${{ github.event_name != 'pull_request' }}
push: false
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
labels: ${{ steps.docker_meta.outputs.labels }}
- name: Image digest
run: echo ${{ steps.docker_build.outputs.digest }}
docker-api-server:
Expand All @@ -48,18 +39,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to DockerHub
uses: docker/login-action@v3
if: github.event_name != 'pull_request'
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- name: Setup meta for api server
id: docker_meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
with:
images: lmsdoubtfire/apiServer
tags: |
Expand All @@ -68,15 +53,18 @@ jobs:
type=semver,pattern=prod-{{version}}
type=semver,pattern=prod-{{major}}.{{minor}}
type=semver,pattern=prod-{{major}}
type=sha,prefix=manual-
- name: Build and push api server
id: docker_build
uses: docker/build-push-action@v5
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
file: deployApi.Dockerfile
context: .
push: ${{ github.event_name != 'pull_request' }}
push: false
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
labels: ${{ steps.docker_meta.outputs.labels }}
sbom: true
provenance: mode=max
- name: Image digest
run: echo ${{ steps.docker_build.outputs.digest }}
docker-app-server:
Expand All @@ -85,18 +73,12 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Login to DockerHub
uses: docker/login-action@v3
if: github.event_name != 'pull_request'
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- name: Setup meta for app server
id: docker_meta
uses: docker/metadata-action@v5
uses: docker/metadata-action@c299e40c65443455700f0fdfc63efafe5b349051 # v5
with:
images: lmsdoubtfire/appServer
tags: |
Expand All @@ -105,14 +87,17 @@ jobs:
type=semver,pattern=prod-{{version}}
type=semver,pattern=prod-{{major}}.{{minor}}
type=semver,pattern=prod-{{major}}
type=sha,prefix=manual-
- name: Build and push app server
id: docker_build
uses: docker/build-push-action@v5
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
file: deployAppSvr.Dockerfile
context: .
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
push: ${{ github.event_name != 'pull_request' }}
labels: ${{ steps.docker_meta.outputs.labels }}
push: false
sbom: true
provenance: mode=max
- name: Image digest
run: echo ${{ steps.docker_build.outputs.digest }}
56 changes: 56 additions & 0 deletions .github/workflows/production-images.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
name: Production image builds

on:
pull_request:
push:
branches:
- "*.x"
workflow_dispatch:

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
build:
name: Build ${{ matrix.name }}
runs-on: ubuntu-latest
timeout-minutes: 60
strategy:
fail-fast: false
matrix:
include:
- name: API
dockerfile: deployApi.Dockerfile
cache_scope: production-api
- name: app worker
dockerfile: deployAppSvr.Dockerfile
cache_scope: production-app
- name: TeX Live helper
dockerfile: texlive.Dockerfile
cache_scope: production-texlive
- name: JPlag helper
dockerfile: jplag.Dockerfile
cache_scope: production-jplag

steps:
- name: Check out source
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Build production image without publishing
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
file: ${{ matrix.dockerfile }}
platforms: linux/amd64
push: false
sbom: true
provenance: mode=max
cache-from: type=gha,scope=${{ matrix.cache_scope }}
cache-to: type=gha,mode=max,scope=${{ matrix.cache_scope }}
Loading