From 74588fbd5d8be6e7a33ce21859aa3d957476a69b Mon Sep 17 00:00:00 2001 From: LathanDevers Date: Mon, 3 Aug 2026 14:03:56 +0200 Subject: [PATCH] feat: add workflow git --- .gitea/workflows/deploy-environments.yml | 84 ++++++++++++++++++++++++ .gitea/workflows/deploy.yml | 61 ----------------- .gitea/workflows/enforce-git-flow.yml | 39 +++++++++++ .gitea/workflows/quality-checks.yml | 54 +++++++++++++++ 4 files changed, 177 insertions(+), 61 deletions(-) create mode 100644 .gitea/workflows/deploy-environments.yml delete mode 100644 .gitea/workflows/deploy.yml create mode 100644 .gitea/workflows/enforce-git-flow.yml create mode 100644 .gitea/workflows/quality-checks.yml diff --git a/.gitea/workflows/deploy-environments.yml b/.gitea/workflows/deploy-environments.yml new file mode 100644 index 0000000..5e61411 --- /dev/null +++ b/.gitea/workflows/deploy-environments.yml @@ -0,0 +1,84 @@ +name: Déploiement AEGIS Portal + +on: + push: + branches: + - dev + - test + - acc + - master + +jobs: + build-and-deploy: + runs-on: ubuntu-latest + env: + GIT_SSL_NO_VERIFY: "true" + NODE_TLS_REJECT_UNAUTHORIZED: "0" + + steps: + - name: Patch DNS local pour Gitea Runner + run: sudo echo "10.10.40.31 git.bunker.lan" | sudo tee -a /etc/hosts + + - name: Configuration de Git pour SSL + run: git config --global http.sslVerify false + + - name: Récupération du code + uses: actions/checkout@v4 + + - name: Configuration de Node.js + uses: actions/setup-node@v4 + with: + node-version: 22 + + - name: Installation des dépendances + run: npm ci + + - name: Compilation de la Build + env: + VITE_APP_ENV: ${{ github.ref_name }} + run: npm run build + + - name: Installation de lftp + run: sudo apt-get update && sudo apt-get install -y lftp + + - name: Routage et Déploiement FTP + env: # 1. On charge tous les secrets de manière sécurisée + SERVER: ${{ secrets.FTP_SERVER }} + DEV_U: ${{ secrets.DEV_FTP_USER }} + DEV_P: ${{ secrets.DEV_FTP_PASSWORD }} + TEST_U: ${{ secrets.TEST_FTP_USER }} + TEST_P: ${{ secrets.TEST_FTP_PASSWORD }} + ACC_U: ${{ secrets.ACC_FTP_USER }} + ACC_P: ${{ secrets.ACC_FTP_PASSWORD }} + PROD_U: ${{ secrets.PROD_FTP_USER }} + PROD_P: ${{ secrets.PROD_FTP_PASSWORD }} + BRANCH: ${{ github.ref_name }} + run: | + # 2. On attribue les bons identifiants selon la branche + if [ "$BRANCH" == "master" ]; then + TARGET_USER=$PROD_U; TARGET_PASS=$PROD_P; DOMAIN="aegis.gise.be" + elif [ "$BRANCH" == "acc" ]; then + TARGET_USER=$ACC_U; TARGET_PASS=$ACC_P; DOMAIN="acc-aegis.gise.be" + elif [ "$BRANCH" == "test" ]; then + TARGET_USER=$TEST_U; TARGET_PASS=$TEST_P; DOMAIN="test-aegis.gise.be" + else + TARGET_USER=$DEV_U; TARGET_PASS=$DEV_P; DOMAIN="dev-aegis.gise.be" + fi + + echo "Déploiement de la branche [$BRANCH] vers le domaine [$DOMAIN]..." + + # 3. Exécution du script FTP (notez le chemin adapté à HestiaCP) + cat << EOF > script.lftp + set ftp:passive-mode true + set ftp:ssl-allow no + set ssl:verify-certificate no + set net:timeout 5 + set net:max-retries 2 + set dns:fatal-timeout 2 + open -u "${TARGET_USER}","${TARGET_PASS}" "${SERVER}" + cd home/${FTP_USER} + mirror -R --delete --verbose dist/ ./ + quit + EOF + + lftp -f script.lftp \ No newline at end of file diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml deleted file mode 100644 index 4eb6716..0000000 --- a/.gitea/workflows/deploy.yml +++ /dev/null @@ -1,61 +0,0 @@ -name: Deploy Aegis Portal - -on: - push: - branches: - - master # Branche principale confirmée - -jobs: - build-and-deploy: - runs-on: ubuntu-latest - - # 1. On désactive la vérification SSL pour tout le conteneur du job (Node.js et Git) - env: - GIT_SSL_NO_VERIFY: "true" - NODE_TLS_REJECT_UNAUTHORIZED: "0" - - steps: - - name: Patch DNS local pour Gitea Runner - run: sudo echo "10.10.40.31 git.bunker.lan" | sudo tee -a /etc/hosts - - # 2. On force l'exécutable Git interne à ignorer la vérification de l'autorité locale - - name: Configuration de Git pour SSL - run: git config --global http.sslVerify false - - - name: Récupération du code - uses: actions/checkout@v4 - - - name: Configuration de Node.js - uses: actions/setup-node@v4 - with: - node-version: 22 - - - name: Installation des dépendances (React/Vite) - run: npm ci - - - name: Compilation de la Build (Aegis) - run: npm run build - - - name: Installation de lftp - run: sudo apt-get update && sudo apt-get install -y lftp - - - name: Déploiement FTP (10.10.40.12) - env: - FTP_USER: ${{ secrets.FTP_USER }} # Le compte FTP enfermé dans aegis.gise.be - FTP_PASSWORD: ${{ secrets.FTP_PASSWORD }} - FTP_SERVER: ${{ secrets.FTP_SERVER }} # Doit contenir : 10.10.40.12 - run: | - cat << EOF > script.lftp - set ftp:passive-mode true - set ftp:ssl-allow no - set ssl:verify-certificate no - set net:timeout 5 - set net:max-retries 2 - set dns:fatal-timeout 2 - open -u "${FTP_USER}","${FTP_PASSWORD}" "${FTP_SERVER}" - cd home/${FTP_USER} - mirror -R --delete --verbose dist/ ./ - quit - EOF - - lftp -f script.lftp \ No newline at end of file diff --git a/.gitea/workflows/enforce-git-flow.yml b/.gitea/workflows/enforce-git-flow.yml new file mode 100644 index 0000000..0c27d93 --- /dev/null +++ b/.gitea/workflows/enforce-git-flow.yml @@ -0,0 +1,39 @@ +name: Sécurité - Architecture Git-Flow + +on: + pull_request: + branches: + - test + - acc + - master + +jobs: + validate-flow: + runs-on: ubuntu-latest + steps: + - name: Vérification du flux de promotion + run: | + TARGET_BRANCH="${{ github.base_ref }}" + SOURCE_BRANCH="${{ github.head_ref }}" + + echo "Tentative de promotion : $SOURCE_BRANCH ➔ $TARGET_BRANCH" + + # Règle 1 : Vers TEST (Doit venir de DEV) + if [ "$TARGET_BRANCH" == "test" ] && [ "$SOURCE_BRANCH" != "dev" ]; then + echo "ERREUR : L'environnement TEST ne peut recevoir que du code de DEV." + exit 1 + fi + + # Règle 2 : Vers ACC (Doit venir de TEST) + if [ "$TARGET_BRANCH" == "acc" ] && [ "$SOURCE_BRANCH" != "test" ]; then + echo "ERREUR : L'environnement d'ACCEPTATION ne peut recevoir que du code de TEST." + exit 1 + fi + + # Règle 3 : Vers PROD (Doit venir de ACC) + if [ "$TARGET_BRANCH" == "master" ] && [ "$SOURCE_BRANCH" != "acc" ]; then + echo "ERREUR : La PRODUCTION ne peut recevoir que du code validé en ACCEPTATION (acc)." + exit 1 + fi + + echo "Flux réglementaire respecté ! Promotion autorisée." \ No newline at end of file diff --git a/.gitea/workflows/quality-checks.yml b/.gitea/workflows/quality-checks.yml new file mode 100644 index 0000000..7b034f8 --- /dev/null +++ b/.gitea/workflows/quality-checks.yml @@ -0,0 +1,54 @@ +name: 🔍 Contrôle Qualité & Sécurité (QA) + +on: + pull_request: + branches: + - dev + - test + - acc + - master + push: + branches: + - dev + +jobs: + quality-gate: + name: 🛡️ Quality Gate & Security Check + runs-on: ubuntu-latest + + env: + GIT_SSL_NO_VERIFY: "true" + NODE_TLS_REJECT_UNAUTHORIZED: "0" + + steps: + - name: Récupération du code source + uses: actions/checkout@v4 + + - name: Configuration de Node.js (v22) + uses: actions/setup-node@v4 + with: + node-version: 22 + cache: 'npm' + + - name: Installation des dépendances + run: npm ci + + # Étape 1 : ESLint (Syntaxe et conventions) + - name: 🧹 Analyse Linter (ESLint) + run: npm run lint + + # Étape 2 : Verification stricte des types TypeScript (sans émettre de fichiers) + - name: 📐 Verification des Types TypeScript + run: npx tsc --noEmit + + # Étape 3 : Exécution des tests unitaires + - name: 🧪 Tests Unitaires (Vitest) + run: npm run test -- --run + + # Étape 4 : Audit des vulnérabilités npm (Niveau High/Critical) + - name: 🔐 Audit de Sécurité des Dépendances + run: npm audit --audit-level=high + + # Étape 5 : Validation de la compilation ViteJS + - name: 🏗️ Validation du Build de Production + run: npm run build \ No newline at end of file