|
| 1 | +name: cron Jobs |
| 2 | + |
| 3 | +on: |
| 4 | + schedule: |
| 5 | + - cron: '0 9 * * *' # Daily at 09:00 UTC |
| 6 | + |
| 7 | +defaults: |
| 8 | + run: |
| 9 | + shell: bash |
| 10 | + |
| 11 | +permissions: |
| 12 | + contents: read |
| 13 | + |
| 14 | +jobs: |
| 15 | + bench-tests: |
| 16 | + name: Run E2E Tests with Grafana Bench |
| 17 | + runs-on: ubuntu-24.04 |
| 18 | + timeout-minutes: 60 |
| 19 | + |
| 20 | + # ensure job never runs on forks |
| 21 | + if: ${{ github.event_name != 'schedule' || github.repository_owner == 'grafana' }} |
| 22 | + |
| 23 | + # this job needs OIDC to fetch Vault secrets |
| 24 | + permissions: |
| 25 | + contents: read |
| 26 | + id-token: write |
| 27 | + |
| 28 | + steps: |
| 29 | + - uses: actions/checkout@v6 |
| 30 | + with: |
| 31 | + # Avoid leaving a token in the repo checkout; prefer explicit auth for publishing steps |
| 32 | + persist-credentials: false |
| 33 | + |
| 34 | + - name: Get secrets from Vault |
| 35 | + id: get-secrets |
| 36 | + uses: grafana/shared-workflows/actions/get-vault-secrets@get-vault-secrets/v1.3.0 |
| 37 | + with: |
| 38 | + # Grafana auth (used by @grafana/plugin-e2e) |
| 39 | + # + Prometheus creds for Bench metrics reporting |
| 40 | + common_secrets: | |
| 41 | + PLAYWRIGHT_GRAFANA_PASSWORD=data-sources/e2e:grafana-pw |
| 42 | + PLAYWRIGHT_GRAFANA_USERNAME=data-sources/e2e:grafana-username |
| 43 | + PROMETHEUS_PASSWORD=grafana-bench:prometheus_token |
| 44 | + PROMETHEUS_URL=grafana-bench:prometheus_url |
| 45 | + PROMETHEUS_USER=grafana-bench:prometheus_user |
| 46 | +
|
| 47 | + # Repo-specific backend secrets (naming varies by datasource) |
| 48 | + repo_secrets: | |
| 49 | + DS_INSTANCE_HOST=ds-instance:host |
| 50 | + DS_INSTANCE_PASSWORD=ds-instance:password |
| 51 | + DS_INSTANCE_PORT=ds-instance:port |
| 52 | + DS_INSTANCE_USERNAME=ds-instance:username |
| 53 | +
|
| 54 | + # Keep secrets in step output; we’ll pass them to Bench explicitly |
| 55 | + export_env: false |
| 56 | + |
| 57 | + - name: Wait for Grafana to be reachable |
| 58 | + uses: grafana/plugin-actions/wait-for-grafana@wait-for-grafana/v1.0.2 |
| 59 | + with: |
| 60 | + # Use /login so “reachable” also implies the app is up |
| 61 | + url: "https://datasourcese2e.grafana-dev.net/login" |
| 62 | + timeout: 300 # 5 minutes |
| 63 | + interval: 10 # 10 seconds |
| 64 | + |
| 65 | + - name: Run Grafana Bench tests |
| 66 | + run: | |
| 67 | + set -euo pipefail |
| 68 | + docker run \ |
| 69 | + -e PROMETHEUS_URL="${{ fromJSON(steps.get-secrets.outputs.secrets).PROMETHEUS_URL }}" \ |
| 70 | + -e PROMETHEUS_USER="${{ fromJSON(steps.get-secrets.outputs.secrets).PROMETHEUS_USER }}" \ |
| 71 | + -e PROMETHEUS_PASSWORD="${{ fromJSON(steps.get-secrets.outputs.secrets).PROMETHEUS_PASSWORD }}" \ |
| 72 | + --network=host \ |
| 73 | + --rm \ |
| 74 | + --volume "$PWD:/tests" \ |
| 75 | + us-docker.pkg.dev/grafanalabs-global/docker-grafana-bench-prod/grafana-bench-playwright:v0.6.11 test \ |
| 76 | + --grafana-admin-password "${{ fromJSON(steps.get-secrets.outputs.secrets).PLAYWRIGHT_GRAFANA_PASSWORD }}" \ |
| 77 | + --grafana-admin-user "${{ fromJSON(steps.get-secrets.outputs.secrets).PLAYWRIGHT_GRAFANA_USERNAME }}" \ |
| 78 | + --grafana-url "https://datasourcese2e.grafana-dev.net" \ |
| 79 | + --grafana-version "rrc-instant" \ |
| 80 | + --prometheus-metrics \ |
| 81 | + --prometheus-strict-lint \ |
| 82 | + --pw-execute "npm run e2e" \ |
| 83 | + --pw-prepare "npm ci --no-audit --fund=false; npx playwright install" \ |
| 84 | + --test-env 'CI=true,DS_INSTANCE_HOST=${{ fromJSON(steps.get-secrets.outputs.secrets).DS_INSTANCE_HOST }},DS_INSTANCE_PASSWORD=${{ fromJSON(steps.get-secrets.outputs.secrets).DS_INSTANCE_PASSWORD }},DS_INSTANCE_PORT=${{ fromJSON(steps.get-secrets.outputs.secrets).DS_INSTANCE_PORT }},DS_INSTANCE_USERNAME=${{ fromJSON(steps.get-secrets.outputs.secrets).DS_INSTANCE_USERNAME }},DS_PDC_NETWORK_NAME=datasources-pdc-network-aws-datasourcese2e' \ |
| 85 | + --test-runner playwright \ |
| 86 | + --test-verbose |
0 commit comments