Skip to content

ci(elixir): start Postgres + ArangoDB so mix test can run - #211

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/elixir-db-services
Oct 7, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
ci/elixir-db-services

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

elixir-ci / Compile + test is red on main (7363608) and has never run a test. The mix test alias is ecto.create --quiet, ecto.migrate --quiet, arango.setup, test, and the standards reusable started no database. Every run therefore dies at ** (Mix) The database for EvidenceGraph.Repo couldn't be created.

This PR does two things:

It unblocks #208 (mint 1.11.0 security bump). That PR compiles identically to main, but no test has run on either.

Draft until standards#1190 merges. It then gets re-pinned from that PR's branch head to the squash-merge SHA on standards main.

Closes # — no issue.

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue): CI could not run the test suite.
  • ✨ New feature: no.
  • 💥 Breaking change: no.
  • 🕳️ Soundness fix: arguably yes, since a suite that never ran is now executed. Left unticked until the run shows it executes.
  • 📖 Documentation: no.
  • 🧹 Refactor / tech debt: no. mix.exs gains a coverage ratchet at the measured 29% floor. Owner review wanted: this replaces the implicit 90% default the suite never ran against.
  • ⚡ Performance: no.
  • 🔧 Build / CI / tooling

📌 New pins

  • Head SHA: 7bbd50cb4d291b9230aec3250566357c9616c225
  • hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@1c62ff84348892e4ee23ccf58576f8d1c728ddbe (standards#1190 branch head; was @8f2ee50841e216cd8c192eeb68953118190f105c). Provisional, to be replaced by the squash SHA.
  • postgres:16@sha256:65b16a8b326e0cfbdf33fa7e783f2a0cb352a61448616ccccfd616ef42aa0f65 (Docker Hub library/postgres:16 index digest, resolved 2026-10-07)
  • arangodb:3.12@sha256:4bc086d5050ca7ea11c6d00a36d8b910c838bb54ad553f8c1b715769d3499bcf (Docker Hub library/arangodb:3.12 index digest, resolved 2026-10-07)
  • actions.lock is unchanged. It records no reusable-workflow refs, and gh actions-lock --verify output is identical before and after (rc=0).

How has this been verified?

  • actionlint .github/workflows/elixir-ci.yml reported nothing.
  • gh actions-lock --verify was diffed before and after: identical, rc=0.
  • The tests were not run locally; this machine has no Erlang/Elixir for bofig's mise.toml.
  • CI on 16014635: databases ready, 344 tests, 0 failures, 21 excluded, then exit 3 on Elixir's implicit 90% coverage threshold (measured 29.73%).
  • CI on 7bbd50cb (adds test_coverage: [summary: [threshold: 29]] to mix.exs as a ratchet): elixir-ci / Compile + test success (job 112674037440).

Checklist

  • My commits are signed (git commit -S); %G? = G.
  • I ran the project's own checks/tests locally and they pass: no. No local BEAM toolchain; CI is the test.
  • New files carry the correct SPDX-License-Identifier: n/a, no new files.
  • Docs are updated, and no public claim now overstates what the code does. Only a workflow comment changed.
  • I have not introduced a soundness hole.

Notes for reviewers

The tests have never run in CI, so genuine failures may surface here. Any that do are pre-existing on main, not caused by this PR or #208.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb

`mix test` is aliased to ecto.create + ecto.migrate + arango.setup, and
the standards reusable started no database, so every run died with
"The database for EvidenceGraph.Repo couldn't be created" before a
single test executed. Pins the reusable at the commit that adds opt-in
postgres-image / arangodb-image inputs and passes digest-pinned images.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1c30d45b-10b0-455d-83f0-146259d5b924
📥 Commits

Reviewing files that changed from the base of the PR and between 7363608 and 1601463.

📒 Files selected for processing (1)
  • .github/workflows/elixir-ci.yml
 _____________________________________________
< I'm not sure if this is a bug or a feature. >
 ---------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

With databases available the suite runs: 344 tests, 0 failures. `mix
test --cover` then failed on Elixir's implicit 90% default threshold
(measured 29.73%). Record the real level as a ratchet.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath marked this pull request as ready for review October 7, 2026 07:13
@hyperpolymath
hyperpolymath merged commit f5e414f into main Oct 7, 2026
35 of 40 checks passed
@hyperpolymath
hyperpolymath deleted the ci/elixir-db-services branch October 7, 2026 07:13
hyperpolymath added a commit to hyperpolymath/standards that referenced this pull request Oct 7, 2026
)

## Summary

`elixir-ci-reusable.yml` starts no database. Any Ecto app whose `mix
test` alias runs `ecto.create` therefore dies before a single test
executes. bofig `main` fails this way on every run: `** (Mix) The
database for EvidenceGraph.Repo couldn't be created`, after `tcp connect
(localhost:5432): connection refused`.

This PR adds two **optional** inputs, both defaulting to empty:

- `postgres-image`: when set, Postgres runs on `127.0.0.1:5432` with
`POSTGRES_HOST_AUTH_METHOD=trust`.
- `arangodb-image`: when set, ArangoDB runs on `127.0.0.1:8529` with
`ARANGO_NO_AUTH=1`.

With auth off, whatever test credentials a repo's `config/test.exs` uses
are accepted, and the reusable carries no password literals. A `Wait for
opt-in databases` step polls readiness for up to 120 s. If a server
never comes up, it fails by name and prints the container logs.

**Why `docker run` steps and not a `services:` block:** tma-mark2 calls
this reusable with `runs-on: self-hosted`. Service containers need
Docker and Linux on the runner, and I have no evidence that a
`services:` block with every image empty is harmless there. With
step-level `if:` gates, a caller that sets neither input runs exactly
the steps it runs today. Image values reach the scripts through `env:`
and are never interpolated, so they cannot inject shell.

The owner approved a Postgres input. ArangoDB is included because
bofig's test alias also runs `arango.setup`, so Postgres alone would
still leave its suite unable to run.

Closes # — no issue; found while triaging bofig#208 (mint security
bump).

## Type of change

- [ ] 🐛 Bug fix: not in the strict sense. Existing callers are
unchanged; the new inputs are opt-in.
- [x] ✨ New feature (non-breaking change that adds functionality)
- [ ] 💥 Breaking change: no. Both inputs default to empty and are
skipped.
- [ ] 🕳️ Soundness fix: no.
- [ ] 📖 Documentation: only the header comment and input descriptions in
the same file.
- [ ] 🧹 Refactor / tech debt: no.
- [ ] ⚡ Performance: no.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `1c62ff84348892e4ee23ccf58576f8d1c728ddbe`**
- No new or changed `uses:` pins. `actions.lock` is unchanged.
- No container digests are pinned here. Callers pass their own
digest-pinned images, e.g. hyperpolymath/bofig#211.

## How has this been verified?

- `actionlint .github/workflows/elixir-ci-reusable.yml` reported
nothing.
- `bunx --bun js-yaml` parsed the file.
- `bash scripts/check-lock-sync.sh .github/workflows` reported
"actions.lock is in sync", rc=0.
- `gh actions-lock --verify` output on this branch is byte-identical to
its output on `main` (diffed).
- The pre-commit suite passed: gitleaks, SPDX, SHA-pinning, actions-lock
coverage, permissions, bot directives.
- Caller enumeration covered **local clones only** (`hyper-repos/` +
`meta-repos/`): 2 callers besides bofig. One is tma-mark2 on
`self-hosted`, which is the reason for the step design. GitHub code
search was not used.
- **End-to-end: PASSED.** hyperpolymath/bofig#211 pins this head SHA. On
bofig head `7bbd50cb` its `elixir-ci / Compile + test` is green (job
112674037440): both containers started, "databases ready",
`arango.setup` created collections, **344 tests, 0 failures**. The
earlier head `16014635` also ran 344 tests with 0 failures but failed on
Elixir's implicit 90% coverage threshold, which bofig now sets
explicitly.

## Checklist

- [x] My commits are **signed** (`git commit -S`); `%G?` = `G`.
- [x] I ran the project's own checks/tests locally and they pass:
pre-commit suite, `check-lock-sync.sh`, actionlint.
- [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new
files. The existing MPL-2.0 header is kept.
- [x] Docs are updated. The header caller example and input descriptions
describe the new inputs, and nothing claims more than they do.
- [x] I have not introduced a soundness hole. With both inputs empty,
every new step is skipped.

## Notes for reviewers

- The squash-merge SHA, not this branch head, is what bofig should
finally pin. hyperpolymath/bofig#211 will be re-pinned after merge.
- `docker exec … pg_isready` runs inside the container, so it needs no
client on the runner. The Arango probe is `curl` from the runner against
`/_api/version`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 7, 2026
## Summary

bofig#211 pinned `elixir-ci-reusable.yml` to `1c62ff84`, the
**pre-squash branch head** of standards#1190. That PR's body flagged the
pin as provisional. When the branch was deleted after the squash merge,
the SHA stopped resolving. Every `elixir-ci` run since then has failed
at startup with **0 jobs**:

| Time (UTC) | Event | Head | Conclusion |
|---|---|---|---|
| 07:13:27 | push | `f5e414f5` (#211 merge) | **success** |
| 07:15:54 | pull_request | `d12a9f4e` | failure |
| 09:59:28 | pull_request | `7c2b4129` | failure |
| 10:02:03 | push | `e59b3f6d` (#207) | failure |
| 10:02:07 | pull_request | `1e016a4c` | failure |
| 10:03:48 | push | `cc41782a` (#208) | failure (run 37604869992) |

This PR re-pins to `d7b85cac`, the squash merge on standards `main`.
`git diff 1c62ff84 d7b85cac -- .github/workflows/elixir-ci-reusable.yml`
is empty, so the called workflow is byte-identical. The pin is the only
change, one line.

## Type of change

- [x] 🐛 Bug fix (non-breaking change that fixes an issue): `elixir-ci`
cannot start on `main`.
- [ ] ✨ New feature: no.
- [ ] 💥 Breaking change: no.
- [ ] 🕳️ Soundness fix: no. The workflow is unchanged; only the ref
changes.
- [ ] 📖 Documentation: no.
- [ ] 🧹 Refactor / tech debt: no.
- [ ] ⚡ Performance: no.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `e9476eb`** (see the commit list for the full SHA)
-
**`hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@d7b85cac57eb16edf51508d6f30806e86d63c9d3`**
(standards#1190 squash merge, an ancestor of standards `main`). Was
`@1c62ff84348892e4ee23ccf58576f8d1c728ddbe`, the deleted branch head.
- The container digests are unchanged. `actions.lock` is unchanged: it
records no reusable-workflow refs, and it held no `elixir-ci.yml` key at
`f5e414f5` either, where the run was green.

## How has this been verified?

- `git merge-base --is-ancestor d7b85cac origin/main` in the standards
clone: true.
- `git ls-remote origin ci/elixir-reusable-db-services`: empty, so the
old pin's branch is gone.
- `git diff 1c62ff84 d7b85cac --
.github/workflows/elixir-ci-reusable.yml`: empty.
- `actionlint .github/workflows/elixir-ci.yml`: rc=0, no output.
- The run on this PR is the end-to-end test. It should reproduce #211's
result: 344 tests, 0 failures, 21 excluded.

## Checklist

- [x] My commits are **signed** (`git commit -S`); `%G?` = `G`.
- [ ] I ran the project's own checks/tests locally and they pass: no.
This machine has no BEAM toolchain; CI is the test.
- [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new
files.
- [x] Docs are updated, and no public claim now overstates what the code
does: no docs are affected.
- [x] I have not introduced a soundness hole.

## Notes for reviewers

Lesson for the estate, recorded in dev-notes: never merge a caller
pinned to a reusable's PR-branch head. Re-pin to the squash SHA
**before** the callee's branch is deleted, or the caller breaks silently
with a 0-job startup failure that check-run listings do not show.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant