Table of contents
| title |
|---|
| DevOps pipeline |
The project is split into a meta-repository and two Git submodules:
backend/contains the Node.js API and its own GitLab pipeline.frontend/contains the Vue application and its own GitLab pipeline.- The root repository,
discourse, contains the Docker Compose development environment and a pipeline for validating its configuration.
The pipelines run automatically for merge requests and for commits to the default branch. They are validation pipelines: they lint, format-check, run tests, and scan the code.
Root repository pipeline
The root pipeline has one stage:
lint
lint-yaml-filesrunsyamllintagainstdocker-compose.ymland the root.gitlab-ci.yml. (checks YAML syntax)lint-docker-composerunsdclintagainst the repository and fails if there are Docker Compose warnings. (finds Compose configuration problems)
This pipeline checks that the local development orchestration is valid.
Backend pipeline
The backend pipeline has four stages:
lint- Runs ESLint on the backend JavaScript files. (finds JavaScript errors and style problems)
- Runs Hadolint against
backend/Dockerfile.dev. (finds Dockerfile mistakes and bad practices) - Runs Yamllint against the backend pipeline file. (checks YAML syntax and style)
format- Runs Prettier in check mode. (checks code formatting)
test- Runs the Node test suite with
npm test.
- Runs the Node test suite with
security- Runs Trivy filesystem scans for vulnerabilities and configuration problems.
Before its jobs run, the backend pipeline uses npm ci to install the exact dependency versions listed in package-lock.json. Its tests mock database calls, so the CI test job does not require PostgreSQL or Garage to be running.
Frontend pipeline
Frontend pipeline has three stages:
lint- Runs the JavaScript and Vue lint checks with
npm run lint. (finds frontend errors and style problems) - Runs Hadolint against
frontend/Dockerfile.dev. (finds Dockerfile mistakes and bad practices) - Runs Trivy filesystem scans for vulnerabilities and configuration problems.
- Runs Yamllint against the frontend pipeline file. (checks YAML syntax and style)
- Runs the JavaScript and Vue lint checks with
format- Runs Prettier in check mode (checks code formatting).
security- The Trivy scan is the security job for the frontend pipeline.
Before the lint and format jobs run, npm ci installs the exact dependency versions listed in package-lock.json.
Local development
The docker-compose.yml file in discourse is used for local development. It starts the frontend, backend, PostgreSQL, Garage S3 storage, and Garage UI, and uses service health checks to control startup order.