Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,47 @@ jobs:
- name: Check uv.lock matches pyproject.toml
run: pip install uv && uv lock --check

docker:
name: docker image
runs-on: ubuntu-latest
timeout-minutes: 20
# Blocking, because nothing built the image before this job existed and a
# broken build shipped unnoticed for six days: dependabot bumped the base to
# python:3.14-slim (#3) while the production stage still copied
# python3.11/site-packages, so every build — including the documented
# `docker compose up --build` — failed on a path that no longer existed.

steps:
- uses: actions/checkout@v7

- uses: docker/setup-buildx-action@v4

- name: Build
uses: docker/build-push-action@v7
with:
context: .
push: false
load: true
tags: verikan:ci
cache-from: type=gha
cache-to: type=gha,mode=max

# Building is not enough. The production stage copies site-packages and
# src/ in separate COPY lines, so a wrong path can still produce an image
# that builds and then fails to import. Boot it and require both health
# endpoints — /api/v1/health also proves the API router mounted, which
# web.py swallows as a warning rather than a crash.
- name: Smoke-test
run: |
docker run -d --name verikan-ci -p 8080:8080 verikan:ci
for _ in $(seq 1 60); do
curl -sf localhost:8080/health >/dev/null 2>&1 && break
sleep 2
done
curl -sf localhost:8080/health || { docker logs verikan-ci; exit 1; }
curl -sf localhost:8080/api/v1/health || { docker logs verikan-ci; exit 1; }
docker rm -f verikan-ci

types:
name: types & formatting (advisory)
runs-on: ubuntu-latest
Expand Down
1 change: 1 addition & 0 deletions .serena/memories/tech_stack.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
- Python `>=3.12`; CI matrix 3.12 + 3.14. `target-version = "py312"`, mypy `python_version = "3.12"`. Do not use 3.13+-only syntax.
- **3.11 was dropped deliberately.** `tests/unit/test_query_stream.py::test_cancelled_stream_reader_cancels_worker` deadlocks on 3.11 only: `gateway/query_stream.py::query_events` does `worker.cancel()` then `await worker` inside `anyio.CancelScope(shield=True)` in its `finally`, and on 3.11 that shielded await never completes when the *consumer* task is cancelled. Introduced by `fa50bfb` (PR #7). The suite passes on 3.12 and 3.14. If anyone proposes restoring 3.11, that deadlock is the blocker.
- 3.14 is in the matrix because the Dockerfile ships `python:3.14-slim`. Bump the two together or the deployed interpreter goes untested.
- **A blocking `docker` CI job builds the image and boots it** (`/health` + `/api/v1/health`). It exists because nothing built the image before: dependabot bumped the base to `python:3.14-slim` (#3) while `Dockerfile` still copied `python3.11/site-packages`, so every build — including the documented `docker compose up --build` — failed for six days on a path that no longer existed. The production stage copies site-packages and `src/` separately, so the build succeeding is not sufficient; the smoke test is the part that catches a bad copy.
- FastAPI + uvicorn + Jinja2 templates; Pydantic v2 (`pydantic-settings` for `core/config.py`).
- LangGraph for agent orchestration; `anthropic` SDK directly (no LangChain LLM wrappers).
- pandas / numpy for computation; `nbformat` + `nbclient` + `ipykernel` for notebook generation and execution.
Expand Down
1 change: 1 addition & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ boundary, or make it a manual script.
| `ruff format --check` | No — advisory | Pre-existing drift across many files |
| `mypy src/` | No — advisory | ~90 pre-existing errors, mostly missing annotations |
| `uv lock --check` | **Yes** | `uv.lock` must match `pyproject.toml` — no backlog, so it's a gate |
| `docker build` + smoke test | **Yes** | Builds the image and boots it; nothing watched it before, so a base-image bump broke the build for six days |

The advisory job reports so the debt stays visible, but it does not block your pull request.
Don't add *new* type errors; fixing ones you touch is welcome. **Please don't reformat files
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Data Concierge - Production Dockerfile
# Optimized for Google Cloud Run

FROM python:3.14-slim as builder

Check warning on line 4 in Dockerfile

View workflow job for this annotation

GitHub Actions / docker image

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

# Install build dependencies
RUN apt-get update && apt-get install -y --no-install-recommends \
Expand Down Expand Up @@ -44,7 +44,7 @@
pip install --no-cache-dir .

# Production stage
FROM python:3.14-slim as production

Check warning on line 47 in Dockerfile

View workflow job for this annotation

GitHub Actions / docker image

The 'as' keyword should match the case of the 'from' keyword

FromAsCasing: 'as' and 'FROM' keywords' casing do not match More info: https://docs.docker.com/go/dockerfile/rule/from-as-casing/

# Install runtime dependencies only
RUN apt-get update && apt-get install -y --no-install-recommends \
Expand All @@ -59,7 +59,7 @@
WORKDIR /app

# Copy installed packages from builder
COPY --from=builder /usr/local/lib/python3.11/site-packages /usr/local/lib/python3.11/site-packages
COPY --from=builder /usr/local/lib/python3.14/site-packages /usr/local/lib/python3.14/site-packages
COPY --from=builder /usr/local/bin /usr/local/bin

# NOTE: qsv arrives with the /usr/local/bin copy above — a second explicit
Expand Down