CI/CD Workflows
RUSEON Core uses GitHub Actions to enforce strict automated quality gates, security scanning, performance benchmarking, and multi-architecture binary distribution on every commit and pull request.
Workflow Catalog
1. Main CI Pipeline (test.yml)
Runs on every pull request and direct push to main and dev branches.
| Job | Key Actions & Tools | Quality Gate Requirement |
|---|---|---|
| Go Mod Hygiene | go mod tidy && git diff --exit-code | Zero uncommitted dependencies |
| Go Static Analysis | golangci-lint (5m timeout) | Zero lint warnings |
| Security Audit | gosec (SAST analysis) | Zero high/medium vulnerability findings |
| Binary Compilation | CGO_ENABLED=0 go build ./cmd/... | Clean compilation of server and CLI |
| Race & E2E Tests | go test -v -race -timeout=15m with MediaMTX + FFmpeg | 100% test pass rate |
| Coverage Gate | Codecov integration across 14 packages | No coverage regression |
| Frontend Checks | oxlint, tsc --noEmit, React Vitest suite, Vite build | Zero type errors, 100% component test pass |
2. Performance & Load Validation (performance.yml)
Ensures that code changes do not introduce latency regressions into the zero-copy streaming pipeline:
- Builds the release server binary.
- Deploys a mock multi-camera RTSP load generator.
- Executes k6 load test scenarios hitting HLS playlists, WebRTC WHEP negotiation endpoints, and
/livezprobes. - Generates dynamic badges reflecting real p95 response times (< 1.5 ms) and request success rates (99.99%+).
3. Nightly Deep E2E Tests (nightly.yml)
Runs automatically every day at 02:00 UTC on a scheduled cron:
- Executes long-running chaos ingestion scenarios (simulating 60 minutes of uninterrupted recording).
- Validates disk retention cleanup algorithms under simulated disk full conditions.
- Runs memory leak detection across prolonged WebRTC client sessions.
4. Release Automation (release.yml)
Triggered automatically when a semantic version tag (e.g., v1.4.0) is pushed to the repository:
- GoReleaser cross-compiles native binaries for:
linux/amd64,linux/arm64,linux/armv7windows/amd64,windows/arm64darwin/amd64,darwin/arm64(Apple Silicon)
- Builds and publishes multi-architecture Docker container images to GitHub Container Registry (
ghcr.io/rusegal/ruseon-core). - Generates SHA-256 checksums and automated release notes with changelog.
5. Documentation Deployment (deploy.yml)
Deploys this documentation site to GitHub Pages with fetch-depth: 0 to ensure that Git commit metadata accurately populates lastmod timestamps in the sitemap and page footers.
Running CI Checks Locally
You can replicate the exact CI checks on your local machine before pushing:
# 1. Module consistency
go mod tidy && git diff --exit-code
# 2. Linter
golangci-lint run
# 3. Security scan
gosec -exclude-dir=pkg/grpc/pb ./...
# 4. Tests with race detector
go test -v -race ./...
# 5. Frontend validation
cd web && npm run typecheck && npm run lint && npm run test:unit