mirror of
https://github.com/apache/superset.git
synced 2026-08-05 05:22:37 +00:00
Adds a per-job/step Gantt chart (rendered as a mermaid diagram in the run summary) to the 15 substantive CI workflows -- the 13 setup-backend consumers plus superset-frontend.yml and docker.yml, the other two heaviest CI paths. Skips trivial bot/label/notification workflows that run in seconds and have nothing worth visualizing. For single-job (or single-heavy-job-in-a-linear-chain) workflows, the step is registered first, before checkout, so its post-processing hook -- which is what actually renders the timeline -- captures the full job including other steps' own cleanup. For workflows with multiple independent parallel jobs, added a dedicated `actions-timeline` terminal job (`needs: [...]`, `if: always()`) instead of duplicating the step into each parallel job: the action fetches every job of the whole run from the GitHub API regardless of which job it executes in, so one copy that runs after every sibling job completes produces one authoritative timeline, while N copies dropped into N parallel jobs would each race to render an incomplete gantt before their siblings finish. `expand-composite-actions: true` is set everywhere so setup-backend's internal steps (Python setup, uv install, apt package caching, dependency install) show up as their own bars rather than one opaque blob -- directly useful given the last two PRs' worth of composite-action changes. `actions: read` is added wherever needed to read job/step timing from the Actions API, either to the workflow's top-level `permissions:` (when the job in question has no job-level override) or directly into the relevant job's own `permissions:` block (when one already exists, since a job-level block replaces rather than merges with the workflow-level one).
143 lines
5.5 KiB
YAML
143 lines
5.5 KiB
YAML
name: Docs Deployment
|
|
|
|
on:
|
|
# Deploy after integration tests complete on master
|
|
# zizmor: ignore[dangerous-triggers] - runs in base-branch context after a trusted upstream workflow; scoped to master
|
|
workflow_run:
|
|
workflows: ["Python-Integration"]
|
|
types: [completed]
|
|
branches: [master]
|
|
|
|
# Also allow manual trigger and direct pushes to docs
|
|
push:
|
|
paths:
|
|
- "docs/**"
|
|
- "README.md"
|
|
branches:
|
|
- "master"
|
|
|
|
workflow_dispatch: {}
|
|
|
|
# Serialize deploys: the action pushes to apache/superset-site without
|
|
# rebasing, so concurrent runs race on the final push and the loser fails
|
|
# with `! [rejected] asf-site -> asf-site (fetch first)`. Cancel any
|
|
# in-progress run as soon as a newer one starts — the destination repo
|
|
# isn't touched until the final push step, so canceling mid-build is safe,
|
|
# and the freshest content always wins.
|
|
concurrency:
|
|
group: docs-deploy-asf-site
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
|
|
jobs:
|
|
config:
|
|
runs-on: ubuntu-26.04
|
|
outputs:
|
|
has-secrets: ${{ steps.check.outputs.has-secrets }}
|
|
steps:
|
|
- name: "Check for secrets"
|
|
id: check
|
|
shell: bash
|
|
run: |
|
|
if [ -n "${SUPERSET_SITE_BUILD}" ]; then
|
|
echo "has-secrets=1" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
env:
|
|
SUPERSET_SITE_BUILD: ${{ (secrets.SUPERSET_SITE_BUILD != '' && secrets.SUPERSET_SITE_BUILD != '') || '' }}
|
|
build-deploy:
|
|
needs: config
|
|
# For workflow_run triggers, only deploy when the triggering run originated
|
|
# from this repository (not a fork), ensuring the checked-out code and any
|
|
# local actions executed with deploy credentials are trusted.
|
|
if: >-
|
|
needs.config.outputs.has-secrets &&
|
|
(github.event_name != 'workflow_run' ||
|
|
github.event.workflow_run.head_repository.full_name == github.repository)
|
|
name: Build & Deploy
|
|
runs-on: ubuntu-26.04
|
|
steps:
|
|
- uses: Kesin11/actions-timeline@7bf79990b7c09f5dfb570ac30b814ca597bd538e # v3.1.1
|
|
with:
|
|
expand-composite-actions: true
|
|
|
|
- name: "Checkout ${{ github.event.workflow_run.head_sha || github.sha }}"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha || github.sha }}
|
|
persist-credentials: false
|
|
submodules: recursive
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version-file: "./docs/.nvmrc"
|
|
- name: Setup Python
|
|
uses: ./.github/actions/setup-backend/
|
|
- uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 # v5.6.0
|
|
with:
|
|
distribution: "zulu"
|
|
java-version: "21"
|
|
- name: Install Graphviz
|
|
uses: awalsh128/cache-apt-pkgs-action@553a35bb8ebd9fcabcb1c9451aa4c98e1b4ca8a9 # v1.6.3
|
|
with:
|
|
packages: graphviz
|
|
version: 1.0
|
|
- name: Compute Entity Relationship diagram (ERD)
|
|
env:
|
|
SUPERSET_SECRET_KEY: not-a-secret
|
|
run: |
|
|
python scripts/erd/erd.py
|
|
curl -L http://sourceforge.net/projects/plantuml/files/1.2023.7/plantuml.1.2023.7.jar/download > ~/plantuml.jar
|
|
java -jar ~/plantuml.jar -v -tsvg -r -o "${{ github.workspace }}/docs/static/img/" "${{ github.workspace }}/scripts/erd/erd.puml"
|
|
- name: yarn install
|
|
working-directory: docs
|
|
run: |
|
|
yarn install --check-cache
|
|
- name: Download database diagnostics (if triggered by integration tests)
|
|
if: github.event_name == 'workflow_run' && github.event.workflow_run.conclusion == 'success'
|
|
uses: dawidd6/action-download-artifact@b6e2e70617bc3265edd6dab6c906732b2f1ae151 # v21
|
|
continue-on-error: true
|
|
with:
|
|
workflow: superset-python-integrationtest.yml
|
|
run_id: ${{ github.event.workflow_run.id }}
|
|
name: database-diagnostics
|
|
path: docs/src/data/
|
|
- name: Try to download latest diagnostics (for push/dispatch triggers)
|
|
if: github.event_name != 'workflow_run'
|
|
uses: dawidd6/action-download-artifact@b6e2e70617bc3265edd6dab6c906732b2f1ae151 # v21
|
|
continue-on-error: true
|
|
with:
|
|
workflow: superset-python-integrationtest.yml
|
|
name: database-diagnostics
|
|
path: docs/src/data/
|
|
branch: master
|
|
search_artifacts: true
|
|
if_no_artifact_found: warn
|
|
- name: Use diagnostics artifact if available
|
|
working-directory: docs
|
|
run: |
|
|
if [ -f "src/data/databases-diagnostics.json" ]; then
|
|
echo "Using fresh diagnostics from integration tests"
|
|
mv src/data/databases-diagnostics.json src/data/databases.json
|
|
else
|
|
echo "Using committed databases.json (no artifact found)"
|
|
fi
|
|
- name: yarn build
|
|
working-directory: docs
|
|
run: |
|
|
yarn build
|
|
- name: deploy docs
|
|
uses: ./.github/actions/github-action-push-to-another-repository
|
|
env:
|
|
API_TOKEN_GITHUB: ${{ secrets.SUPERSET_SITE_BUILD }}
|
|
with:
|
|
source-directory: "./docs/build"
|
|
destination-github-username: "apache"
|
|
destination-repository-name: "superset-site"
|
|
target-branch: "asf-site"
|
|
commit-message: "deploying docs: ${{ github.event.head_commit.message || 'triggered by integration tests' }} (apache/superset@${{ github.event.workflow_run.head_sha || github.sha }})"
|
|
user-email: dev@superset.apache.org
|