-
Notifications
You must be signed in to change notification settings - Fork 0
33 lines (28 loc) · 1.09 KB
/
Copy pathstackql-assert-example.yml
File metadata and controls
33 lines (28 loc) · 1.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
# Example workflow using the stackql-assert marketplace action
name: clickhouse-assurance
on:
workflow_dispatch:
env:
CLICKHOUSE_CLOUD_API_KEY: ${{ secrets.CLICKHOUSE_CLOUD_API_KEY }}
CLICKHOUSE_CLOUD_API_SECRET: ${{ secrets.CLICKHOUSE_CLOUD_API_SECRET }}
CLICKHOUSE_ORG_ID: ${{ secrets.CLICKHOUSE_ORG_ID }}
jobs:
assure:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# inline query: fail the build if any service allows 0.0.0.0/0
- name: no open access lists
uses: stackql/stackql-assert@v2
with:
test_query: |
SELECT s.name
FROM clickhouse.services.services s, json_each(s.ip_access_list) a
WHERE json_extract(a.value, '$.source') = '0.0.0.0/0'
expected_rows: 0
# query from a file: the production warehouse exists and is running
- name: prod warehouse is running
uses: stackql/stackql-assert@v2
with:
test_query_file_path: .github/queries/prod-warehouse-running.iql
expected_results_str: '[{"name":"rta-prod-warehouse","state":"running"}]'