CI/CD: optional GITHUB_TOKEN for composer, functional tests never send email, registry secret apply (template !12)
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 58/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- docker, github-actions, helm, kubernetes, php
- Domain
- ci-cd, devops, documentation
Research direction
Update content/6.deployment/3.ci-cd.md, especially the variables table at line 73, the bin/devops/setup.sh section around line 147, and run_test_functional around line 167; compare with content/6.deployment/1.docker.md at line 224. Document the token, email-safe test setup, registry secret, Helm defaults, removed VARNISH_TOKEN, and stale GitHub deploy statement using the issue details. Done when the CI/CD guide consistently describes these behaviors and no longer lists the unused variable.
Written by the indexing model from the issue text.
Description
Template MR !12 (components-web-app#123, merged as 1a530d4) changed CI in ways content/6.deployment/3.ci-cd.md should cover.
1. Optional GITHUB_TOKEN for composer (new row in the variables table, plus a note in the bin/devops/setup.sh section, line 147)
- Without it, composer's ~180 downloads from github.com are anonymous: 60 requests an hour per IP. On a shared runner, installs fail part way through with a 429.
- A fine-grained token with no permissions is enough.
setup.shturns it intoCOMPOSER_AUTHand setsCOMPOSER_MAX_PARALLEL_HTTP=6. Unset stays unset (an empty token is rejected outright, which is worse than anonymous). build_apipasses it to the API image build as thecomposer_authbuild secret, never a build arg, so it stays out of the image history. The build log'sgithub rate limit for this build:line prints 60 (anonymous) or 5000 (token applied).- GitHub Actions maps its own
secrets.GITHUB_TOKENon the build step, so nothing needs setting there. - Keep this consistent with
content/6.deployment/1.docker.md:224, which already mentionsGITHUB_TOKENfor localcomposer update.
2. Functional tests never send real email (the functional tests row at line 73, and run_test_functional at line 167)
- Every CI variable reaches the test job, and a real environment variable beats
api/.env.test, so a project's liveMAILER_DSNwould deliver any email a test sends (a contact form, a password reset). run_test_functionalunsetsMAILER_DSNandMAILER_EMAIL, andapi/.env.testsetsMAILER_DSN=null://null: mail is built and Symfony's mailer assertions still see it, but nothing is delivered. Both halves are needed: without the.env.testline, tests fall back to.env'ssmtp-relayhost, which CI doesn't have, and error.- The job also generates a test JWT keypair (
lexik:jwt:generate-keypair --skip-if-exists), so tests that sign in work in CI.
3. Smaller changes
- The registry pull secret is now
kubectl applyd, notreplace --forced (concurrent releases in one namespace raced with "already exists"). The first deploy after the change prints a harmless one-off warning about a missinglast-applied-configurationannotation. helm lintandhelm templatenow pass on the chart's own defaults (jwt-passphrasedefaults to"").VARNISH_TOKEN(chartapiSecretToken) is gone: nothing read it. If the docs list it anywhere, remove it.
While there, unrelated: line 416 says "GitHub deploys don't pass these variables" (MAILER_DSN, MAILER_EMAIL, ORPHAN_SCAN*), but line 411 says they do. Since template #102 they do, so 416 looks stale.
- Dominant language
- Vue
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from components-web-app/docs
-
Website: the docs site's own service worker can't install (navigateFallback "/" isn't precached)Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
components-web-app/docs#173 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 22/100
components-web-app/docs#184 ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 55/100
components-web-app/docs#179 ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 48/100
components-web-app/docs#178 ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 66/100
components-web-app/docs#177 ·
All issues in components-web-app/docs
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Failing CIOpen
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
exercism/crystal-test-runner#108 ·
-
[Bug] create-before-destroy replacements are omitted from driftPossibly taken @Lostmanu claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
InditexTech/kumoss#318 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100