name: notification-platform # Verification tiers for the Notification Delivery Platform. # # The PR tier is deliberately free of any external provider. A gate that depends on a third-party # sandbox fails for reasons that have nothing to do with the change under review, and a gate people # learn to re-run is not a gate. Real provider smoke tests live in the secret-protected tier, where # a failure is an environment signal rather than a merge blocker. # # Every job that invokes Gradle validates the wrapper first with the repository's pinned action; # the wrapper JAR is executable code fetched at build time, so validating it is what keeps a # compromised wrapper from turning any workflow run into arbitrary code execution. on: pull_request: paths: # The filter used to stop at the four notification source trees, so a change to the # composition root, the settings binding, the schema migrations, or the evidence manifest # ran none of this — and those are exactly the surfaces that decide whether the platform # assembles, binds and migrates at all. - 'src/application-core/src/**/notification/**' - 'src/adapter/outbound/notification/**' - 'src/adapter/outbound/persistence-jpa/src/**/notification/**' - 'src/adapter/outbound/persistence-jpa/src/main/resources/db/migration/jpa/notification-platform/**' - 'src/adapter/inbound/web/src/**/notification/**' - 'src/app-bootstrap/src/**/notification/**' - 'src/app-bootstrap/src/main/resources/application*.yml' - 'src/gradle/notification-*.gradle' - 'src/config/architecture/modules.json' - 'src/.env' - 'docs/notification/**' - 'infra/notification/**' - '.github/workflows/notification-platform.yml' # Every Gradle job here installs its toolchain through this composite action, so a change to # it changes what this gate runs. - '.github/actions/setup-gradle-java/action.yml' push: branches: [ main ] schedule: # Nightly: the chaos tier, which is slower and inherently less deterministic than the PR tier. - cron: '0 17 * * *' workflow_dispatch: permissions: contents: read concurrency: group: notification-platform-${{ github.ref }} cancel-in-progress: true jobs: pr: name: contract (Java 21, no external provider) runs-on: ubuntu-latest timeout-minutes: 30 steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # actions/checkout@v4.2.2 - name: Validate Gradle wrapper id: gradle-wrapper-validation uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # gradle/actions@v6 - uses: ./.github/actions/setup-gradle-java - name: Compile and format check working-directory: src run: ./gradlew :application-core:compileJava :adapter:outbound:notification:compileJava --console=plain - name: Application contracts working-directory: src run: ./gradlew :application-core:test --console=plain - name: Provider contract suite working-directory: src run: ./gradlew :adapter:outbound:notification:test --console=plain - name: Persistence and web working-directory: src run: ./gradlew :adapter:outbound:persistence-jpa:test :adapter:inbound:web:test --console=plain # The PR tier never touched a database, so every claim about migrations, claim atomicity and # lease fencing rested on a fake. Docker is available on this runner; the lane fails closed # when the container cannot start, because a skipped contract reports success for a database # nobody tested. - name: Notification schema and claim contracts (real PostgreSQL) working-directory: src run: ./gradlew :adapter:outbound:persistence-jpa:jpaPlatformContractTest --console=plain - name: Notification migration upgrade (real PostgreSQL) working-directory: src run: ./gradlew :adapter:outbound:persistence-jpa:jpaPlatformMigrationTest --console=plain - name: Architecture gates working-directory: src run: | ./gradlew verifyCleanArchitectureDependencies --console=plain ./gradlew :app-bootstrap:test --tests 'dev.caskeleton.bootstrap.architecture.*' --console=plain - name: Configuration surface working-directory: src run: | ./gradlew verifyEnvKeys verifyPublicPathSnapshot --console=plain ./gradlew verifyNotificationApiSurface verifyNotificationConfiguration --console=plain # A support grade is a promise about production behaviour. This refuses one the pipeline # cannot back — the check that would have caught five channels reading "Stable" while no # request had ever left the process. - name: Evidence manifest working-directory: src run: ./gradlew verifyNotificationEvidence --console=plain - name: Static analysis working-directory: src run: ./gradlew :adapter:outbound:notification:check -x test --console=plain nightly-chaos: name: chaos (ambiguity, restart recovery, callback burst) if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest timeout-minutes: 60 steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # actions/checkout@v4.2.2 - name: Validate Gradle wrapper id: gradle-wrapper-validation uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # gradle/actions@v6 - uses: ./.github/actions/setup-gradle-java # This job is named for ambiguity, restart recovery and callback burst. It used to run a # unit-test filter and then `test` — neither of which restarts anything or bursts anything — # so the job name was the only place those three properties existed. - name: Ambiguity and fault harness working-directory: src run: ./gradlew :adapter:outbound:notification:test --tests '*ChaosSecurity*' --tests '*CrossProviderContractSuite*' --console=plain - name: Concurrency and rotation races working-directory: src run: ./gradlew :adapter:outbound:notification:test --tests '*ConcurrencyTest' --tests '*ProviderRuntimeStateTest' --console=plain - name: Restart recovery and lease fencing (real PostgreSQL) working-directory: src run: ./gradlew :adapter:outbound:persistence-jpa:jpaPlatformContractTest :adapter:outbound:persistence-jpa:jpaPlatformFailureTest --console=plain - name: Full suite working-directory: src run: ./gradlew test --console=plain # A filter that matches nothing passes. Each --tests filter above names a class that exists # today; if one is renamed the job must fail rather than quietly stop covering it. - name: Every named suite actually ran working-directory: src run: | set -euo pipefail for suite in ChaosSecurity CrossProviderContractSuite ConcurrencyTest ProviderRuntimeStateTest; do if ! find . -path '*/build/test-results/*' -name "*${suite}*.xml" | grep -q .; then echo "no test results for ${suite}: the filter matched nothing and the job passed vacuously" >&2 exit 1 fi done # There is no provider-sandbox job. It ran only on workflow_dispatch and could not succeed by # any path: with no credentials its first step exit 1-ed, and with credentials the only test it # ran was ProviderSandboxSmokeTest, whose body is an unconditional fail() saying a real sandbox # call is not implemented. Its credential check read secrets.NOTIFICATION_SANDBOX_CREDENTIALS, # which nothing in this repository consumes — the test reads NOTIFICATION_SANDBOX_ENABLED — so # any non-empty string satisfied it and was then dropped. # # The unimplemented state is still stated in two places that do not depend on a workflow: # ProviderSandboxSmokeTest itself, and the unsatisfied provider-wire-qualified claim in # docs/notification/evidence-manifest.json, which verifyNotificationEvidence enforces inside # check. When a real sandbox call is implemented, the job comes back with it.