Files
opensourcepos/.github/workflows/install-script-test.yml
T
jekkos 9baa396445 fix(install): address CodeRabbit review round 2
- Workflow: use github.ref for the concurrency group so distinct PRs from the
  same source branch don't cancel each other
- Workflow: extract the generated DB password from the installer's 'Password:'
  output and verify the 'ospos' account can authenticate with DB_PASS
- Installer: set the MariaDB root password and FLUSH PRIVILEGES in one session,
  pass the root password via a private 0600 defaults file (no argv exposure),
  and scope the SQL account to the 'localhost' client host
- Docs: interactive mode requires a tty (download-then-run, not a pipe);
  clarify SSL_EMAIL needs a public hostname to enable Let's Encrypt
2026-09-30 15:52:54 +02:00

140 lines
5.0 KiB
YAML

name: Install Script Test
on:
push:
paths:
- 'scripts/install-ubuntu.sh'
- '.github/workflows/install-script-test.yml'
pull_request:
paths:
- 'scripts/install-ubuntu.sh'
- '.github/workflows/install-script-test.yml'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
install-test:
name: Test Install Script (${{ matrix.scenario }})
runs-on: ubuntu-22.04
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
include:
- scenario: default
db_pass: ''
- scenario: custom-password
db_pass: 'TestPass123!'
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Make install script executable
run: chmod +x scripts/install-ubuntu.sh
- name: Run install script
env:
DB_PASS: ${{ matrix.db_pass }}
run: |
set -o pipefail
echo "Running install script with scenario: ${{ matrix.scenario }}"
sudo -E bash scripts/install-ubuntu.sh 2>&1 | tee install-output.log
echo "Install completed successfully"
- name: Wait for services to stabilize
run: sleep 10
- name: Verify Apache is running
run: |
echo "Checking Apache status..."
sudo systemctl status apache2 --no-pager
sudo systemctl is-active apache2
- name: Verify MariaDB is running
run: |
echo "Checking MariaDB status..."
sudo systemctl status mariadb --no-pager
sudo systemctl is-active mariadb
- name: Verify Apache HTTP response
run: |
echo "Testing HTTP response on port 80..."
HTTP_CODE=$(curl -s -o /dev/null -w "%{http_code}" http://localhost/)
echo "HTTP Response Code: $HTTP_CODE"
if [ "$HTTP_CODE" = "200" ] || [ "$HTTP_CODE" = "302" ]; then
echo "Apache is responding correctly"
elif [ "$HTTP_CODE" = "500" ]; then
echo "HTTP 500 - Application error. Checking .env configuration..."
# Never print secret values (password, encryption key) to the log;
# show only non-secret keys and confirm the sensitive ones are present.
sudo cat /var/www/ospos/.env 2>/dev/null | grep -E "database\.default\.(hostname|database|username)|CI_ENVIRONMENT" | head -10
sudo grep -q '^encryption\.key=.' /var/www/ospos/.env 2>/dev/null && echo "encryption.key is set" || echo "WARNING: encryption.key is NOT set"
sudo cat /var/www/ospos/writable/logs/*.log 2>/dev/null | tail -20 || true
curl -s -L http://localhost/ | head -50
exit 1
else
echo "Unexpected HTTP code: $HTTP_CODE"
exit 1
fi
- name: Verify OSPOS login page
run: |
echo "Checking OSPOS login page..."
# Follow redirects (-L): the root path may 302 to the login route, so
# fetch the final page to actually see the login form.
curl -s -L http://localhost/ | grep -qi "login\|password\|username" && echo "Login page content found" || {
echo "Login page verification failed"
curl -s -L http://localhost/ | head -50
exit 1
}
- name: Verify database exists
env:
DB_PASS: ${{ matrix.db_pass != '' && matrix.db_pass || '' }}
run: |
echo "Verifying database..."
# Extract the generated password from install output if using default.
# The installer prints " Password: <value>" (the first such line is the DB
# password; a later one is the app login password), so anchor on it and take
# the first match.
if [ -z "${{ matrix.db_pass }}" ]; then
GENERATED_PASS=$(grep -oP '^\s*Password: \K[^\s]+' install-output.log | head -n 1 || true)
if [ -n "$GENERATED_PASS" ]; then
DB_PASS="$GENERATED_PASS"
fi
fi
# Check database exists
sudo mysql -u root -e "SHOW DATABASES LIKE 'ospos';" | grep -q ospos && echo "Database 'ospos' exists" || {
echo "Database 'ospos' not found"
sudo mysql -u root -e "SHOW DATABASES;"
exit 1
}
# Check tables exist (use the app account so the scenario actually proves
# `ospos` can authenticate with the configured DB_PASS, not just root)
TABLE_COUNT=$(sudo mysql -u ospos -p"$DB_PASS" ospos -e "SHOW TABLES;" | wc -l)
echo "Found $TABLE_COUNT tables in database"
if [ "$TABLE_COUNT" -gt 5 ]; then
echo "Database tables verified"
else
echo "Not enough tables found"
exit 1
fi
- name: Upload install log
uses: actions/upload-artifact@v4
if: always()
with:
name: install-log-${{ matrix.scenario }}
path: install-output.log
retention-days: 7