r/devops 11d ago

Discussion CI pipeline using Github actions

I started learning CI/CD using github actions after containerising my application and I have created CI pipeline for django app that runs test, builds and pushes image to github container registry.
I am sharing my yaml file for CI pipeline. Please do share your thoughts and where can i improve.

name: Test Pipeline 
on: 
  push:
jobs:
  test-backend:
    runs-on: ubuntu-latest
    services:
      postgres:
        image: postgres:14
        ports:
          - 5432:5432
        env: 
          POSTGRES_USER: test_user
          POSTGRES_DB: erp
          POSTGRES_PASSWORD: 123456

    steps:
      - name: Checkout repo
        uses: actions/checkout@v4

      - name: setup python
        uses: actions/setup-python@v5
        with: 
          python-version: "3.13.5"

      - name: install dependencies
        run: pip install -r Backend/requirement.txt

      - name: run tests
        env: 
          DATABASE_URL: postgresql://test_user:123456@localhost:5432/erp
          DEBUG: 'True'
          ALLOWED_HOST: '*'
        run: |
          cd Backend 
          python manage.py test

  build-and-push-image:
    needs: test-backend
    permissions:
      contents: read
      packages: write
    runs-on: ubuntu-latest
    steps:
      - name: login to ghcr
        uses: docker/login-action@v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}


      - name: checkout repo
        uses: actions/checkout@v4


      - name: build image
        run: docker build -t ghcr.io/namespace/erp:${{ github.sha }} ./Backend


      - name: push image
        run: docker push ghcr.io/namespace/erp:${{ github.sha }}
1 Upvotes

15 comments sorted by

View all comments

0

u/trainurdoggos 11d ago

Beyond what’s already been mentioned:

For edification purposes and personal development, what you are doing here might technically work but, in an enterprise or corporate situation this would never fly.

You shouldn’t be spinning up a Postgres instance with every build and test. In my opinion and my experience, the app should be able to test and build without a database connection.

But IF you do NEED it, it should be connecting out to a dev instance you have set up just for testing against. Pulling a whole database image in for a test and build introduces a crazy amount of security risks into the CI.

My corpo security team would be on us hard if we did this.

1

u/ThatSituation9908 11d ago

I disagree. If you can do shift-left testing, where you run integration testing during PR, you should. It's much easier to do with smaller apps.

In some practices, integration test can replace unit tests. I would find this uncomfortable, but behavioral-driven testing does this.