Repository navigation
feat(app): unified Studio installation permissions for DAB and Marketplace #6135
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: acceptance | |
| on: | |
| pull_request: | |
| types: [ opened, synchronize, ready_for_review ] | |
| merge_group: | |
| types: [ checks_requested ] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: false # don't cancel ongoing runs to ensure fixtures are completed and resources terminated | |
| jobs: | |
| # Gate all downstream jobs behind a single check so PRs from forks (no access to the | |
| # tool environment) and draft PRs do not trigger the expensive acceptance suite. | |
| # PRs from forks are to be tested by the reviewer(s) / maintainer(s) before merging. | |
| not-a-fork: | |
| runs-on: | |
| group: databrickslabs-protected-runner-group | |
| labels: linux-ubuntu-latest | |
| if: github.event_name == 'pull_request' && !github.event.pull_request.draft && !github.event.pull_request.head.repo.fork | |
| steps: | |
| - run: echo "Not a fork PR, proceeding" | |
| integration: | |
| needs: not-a-fork | |
| environment: tool | |
| runs-on: | |
| group: larger-runners | |
| labels: larger | |
| permissions: | |
| # Access to the integration testing infrastructure. | |
| id-token: write | |
| # Write test results to the PR. | |
| pull-requests: write | |
| steps: | |
| - name: Checkout Code | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup environment | |
| uses: ./.github/actions/setup-env | |
| - name: Pre-build DQX wheel | |
| uses: ./.github/actions/prebuild-wheel | |
| # Integration tests are run from within tests/integration folder. | |
| # Create .coveragerc with correct relative path to source code. | |
| - name: Prepare code coverage configuration for integration tests | |
| run: | | |
| cat > tests/integration/.coveragerc << EOF | |
| [run] | |
| source = ../../src | |
| relative_files = true | |
| parallel = true | |
| EOF | |
| # Run tests from `tests/integration` as defined in .codegen.json | |
| # and generate code coverage for modules defined in .coveragerc | |
| # Run 10 tests in parallel: https://github.com/databrickslabs/sandbox/blob/main/acceptance/ecosystem/pytest_run.py | |
| - name: Run integration tests and generate test coverage report | |
| uses: databrickslabs/sandbox/acceptance@83461e5dd7021feabb1a9ca3ee10d6f46b72092a # acceptance/v0.4.6 | |
| with: | |
| vault_uri: ${{ secrets.VAULT_URI }} | |
| timeout: 2h | |
| codegen_path: tests/integration/.codegen.json | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| ARM_CLIENT_ID: ${{ secrets.ARM_CLIENT_ID }} | |
| ARM_TENANT_ID: ${{ secrets.ARM_TENANT_ID }} | |
| COVERAGE_FILE: ${{ github.workspace }}/.coverage # make sure the coverage report is preserved | |
| - name: Merge coverage reports and convert them to XML | |
| run: make combine-coverage | |
| - name: Publish test coverage | |
| uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0 | |
| with: | |
| use_oidc: true | |
| files: coverage-combined.xml | |
| flags: integration | |
| integration_serverless: | |
| needs: not-a-fork | |
| environment: tool | |
| runs-on: | |
| group: larger-runners | |
| labels: larger | |
| permissions: | |
| id-token: write | |
| pull-requests: write | |
| env: | |
| DATABRICKS_SERVERLESS_COMPUTE_ID: auto | |
| steps: | |
| - name: Checkout Code | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup environment | |
| uses: ./.github/actions/setup-env | |
| - name: Pre-build DQX wheel | |
| uses: ./.github/actions/prebuild-wheel | |
| # Integration tests are run from within tests/integration folder. | |
| # Create .coveragerc with correct relative path to source code. | |
| - name: Prepare code coverage configuration for integration tests | |
| run: | | |
| cat > tests/integration/.coveragerc << EOF | |
| [run] | |
| source = ../../src | |
| relative_files = true | |
| parallel = true | |
| EOF | |
| - name: Run integration tests on serverless cluster | |
| uses: databrickslabs/sandbox/acceptance@83461e5dd7021feabb1a9ca3ee10d6f46b72092a # acceptance/v0.4.6 | |
| with: | |
| vault_uri: ${{ secrets.VAULT_URI }} | |
| timeout: 2h | |
| codegen_path: tests/integration/.codegen.json | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| ARM_CLIENT_ID: ${{ secrets.ARM_CLIENT_ID }} | |
| ARM_TENANT_ID: ${{ secrets.ARM_TENANT_ID }} | |
| DATABRICKS_SERVERLESS_COMPUTE_ID: ${{ env.DATABRICKS_SERVERLESS_COMPUTE_ID }} | |
| COVERAGE_FILE: ${{ github.workspace }}/.coverage # make sure the coverage report is preserved | |
| - name: Merge coverage reports and convert them to XML | |
| run: make combine-coverage | |
| - name: Publish test coverage | |
| uses: codecov/codecov-action@b9fd7d16f6d7d1b5d2bec1a2887e65ceed900238 # v4.6.0 | |
| with: | |
| use_oidc: true | |
| files: coverage-combined.xml | |
| flags: integration-serverless | |
| e2e: | |
| needs: not-a-fork | |
| environment: tool | |
| runs-on: | |
| group: larger-runners | |
| labels: larger | |
| permissions: | |
| id-token: write | |
| pull-requests: write | |
| steps: | |
| - name: Checkout Code | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup environment | |
| uses: ./.github/actions/setup-env | |
| - name: Pre-build DQX wheel | |
| uses: ./.github/actions/prebuild-wheel | |
| # Required for DAB (Databricks Asset Bundle) e2e tests | |
| - name: Install Databricks CLI | |
| uses: databricks/setup-cli@596b0a354ba14aa59921aca1b02bd67c2b0a81a5 # v0.297.2 | |
| - name: Run e2e tests | |
| uses: databrickslabs/sandbox/acceptance@83461e5dd7021feabb1a9ca3ee10d6f46b72092a # acceptance/v0.4.6 | |
| with: | |
| vault_uri: ${{ secrets.VAULT_URI }} | |
| timeout: 2h | |
| codegen_path: tests/e2e/.codegen.json | |
| env: | |
| REF_NAME: ${{ github.ref_name }} # NOTE: end-to-end tests use this to pip install from the current PR branch | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| ARM_CLIENT_ID: ${{ secrets.ARM_CLIENT_ID }} | |
| ARM_TENANT_ID: ${{ secrets.ARM_TENANT_ID }} | |
| e2e_serverless: | |
| needs: not-a-fork | |
| environment: tool | |
| runs-on: | |
| group: larger-runners | |
| labels: larger | |
| permissions: | |
| id-token: write | |
| pull-requests: write | |
| env: | |
| DATABRICKS_SERVERLESS_COMPUTE_ID: auto | |
| steps: | |
| - name: Checkout Code | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup environment | |
| uses: ./.github/actions/setup-env | |
| - name: Pre-build DQX wheel | |
| uses: ./.github/actions/prebuild-wheel | |
| # Required for DAB (Databricks Asset Bundle) e2e tests | |
| - name: Install Databricks CLI | |
| uses: databricks/setup-cli@596b0a354ba14aa59921aca1b02bd67c2b0a81a5 # v0.297.2 | |
| - name: Run e2e tests on serverless cluster | |
| uses: databrickslabs/sandbox/acceptance@83461e5dd7021feabb1a9ca3ee10d6f46b72092a # acceptance/v0.4.6 | |
| with: | |
| vault_uri: ${{ secrets.VAULT_URI }} | |
| timeout: 2h | |
| codegen_path: tests/e2e/.codegen.json | |
| env: | |
| REF_NAME: ${{ github.ref_name }} # NOTE: end-to-end tests use this to pip install from the current PR branch | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| ARM_CLIENT_ID: ${{ secrets.ARM_CLIENT_ID }} | |
| ARM_TENANT_ID: ${{ secrets.ARM_TENANT_ID }} | |
| DATABRICKS_SERVERLESS_COMPUTE_ID: ${{ env.DATABRICKS_SERVERLESS_COMPUTE_ID }} |