mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
* chore(lens): remove deployment screenshots * refactor(lens)!: rename internal engine package and API * fix(lens): pin worker image for renamed API * test(lens): cover fresh and populated rename migrations * fix(lens): protect db-push upgrades and restore routing and CI * fix(lens): resolve migration tables across schemas and include database driver
66 lines
2.4 KiB
YAML
66 lines
2.4 KiB
YAML
name: Lens Worker Image
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main, litellm_oss_branch, "litellm_**"]
|
|
paths:
|
|
- deploy/lens/**
|
|
- litellm/proxy/lens/**
|
|
- .github/workflows/lens-worker.yml
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- deploy/lens/**
|
|
- litellm/proxy/lens/**
|
|
- .github/workflows/lens-worker.yml
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
lens-worker-image:
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
|
|
with:
|
|
persist-credentials: false
|
|
- name: Build Lens worker
|
|
run: docker build -f deploy/lens/Dockerfile -t lens-worker:${{ github.sha }} .
|
|
- name: Verify standalone imports with a read-only filesystem
|
|
run: |
|
|
docker run --rm --network none --read-only --cap-drop ALL --tmpfs /tmp:rw,noexec,nosuid,size=1g \
|
|
--security-opt no-new-privileges --entrypoint python \
|
|
lens-worker:${{ github.sha }} -c '
|
|
import os
|
|
import lens.worker
|
|
from lens.trace_store import trace_store
|
|
assert os.getuid() == 65532
|
|
with trace_store() as store:
|
|
assert store.count() == 0
|
|
'
|
|
- name: Verify recovery after temporary storage fills
|
|
run: |
|
|
docker run --rm --network none --read-only --cap-drop ALL \
|
|
--tmpfs /tmp:rw,noexec,nosuid,size=64k --security-opt no-new-privileges \
|
|
-v "$PWD/tests/proxy_behavior/lens/worker_storage_smoke.py:/app/storage_smoke.py:ro" \
|
|
--entrypoint python lens-worker:${{ github.sha }} /app/storage_smoke.py
|
|
- name: Publish versioned Lens worker
|
|
if: github.event_name != 'pull_request' && github.repository == 'BerriAI/litellm'
|
|
env:
|
|
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
REGISTRY_USER: ${{ github.actor }}
|
|
IMAGE: ghcr.io/berriai/litellm-lens-worker:sha-${{ github.sha }}
|
|
run: |
|
|
printf '%s' "$REGISTRY_TOKEN" | docker login ghcr.io -u "$REGISTRY_USER" --password-stdin
|
|
docker tag lens-worker:${{ github.sha }} "$IMAGE"
|
|
docker push "$IMAGE"
|
|
printf 'Lens worker image: `%s`\n' "$IMAGE" >> "$GITHUB_STEP_SUMMARY"
|