Skip to content

Port pti blackbox tests to bakery - #819

Draft
bschwedler wants to merge 14 commits into
mainfrom
port-pti-blackbox-tests
Draft

bschwedler wants to merge 14 commits into
mainfrom
port-pti-blackbox-tests

Conversation

@bschwedler

Copy link
Copy Markdown
Contributor

Add functional tests for Bakery's Jinja2 macros that build real images and run goss against them, replacing the pti blackbox tests. The unit tests only check rendered shell text, and the with-macros build only checked that one Ubuntu image built, so macro regressions showed up in product repos first.

The new macros-functional context builds four images (macros-syspkg, macros-python, macros-r, macros-quarto), with one variant per scenario, on Ubuntu 22.04, 24.04, 26.04 and Rocky Linux 9, 10 (amd64). It runs in a new blackbox CI job via bakery-build.yml, and locally with just test-macros. Pro Drivers and Jupyter kernel registration aren't ported because no macro exists for them.

Bugs it surfaced, fixed here:

  • python.run_install_packages and r.run_install_packages deleted their package files after the first version, which broke multi-version installs.
  • quarto.install() with TinyTeX didn't install perl, so tlmgr failed and --update-path only warned.
  • Committed rendered fixtures were never checked against their templates, and check_build_artifacts didn't assert.

The three with-macros image builds (two pytest scenarios and the bakery CI job) are removed as redundant. release now needs blackbox instead of bakery, so tags are still gated on bakery-build.yml working end to end.

Product repos will see new rendered output after upgrading: perl in TinyTeX installs, and package-file cleanup only after the last version.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Test Results

2 343 tests  +4   2 343 ✅ +4   7m 33s ⏱️ -13s
    1 suites ±0       0 💤 ±0 
    1 files   ±0       0 ❌ ±0 

Results for commit 27da00a. ± Comparison against base commit d2f095c.

♻️ This comment has been updated with latest results.

Comment thread .github/workflows/ci.yml Fixed
Comment thread .github/workflows/ci.yml Fixed
Image build tests build the committed rendered files, never freshly
rendered ones, so a macro change that isn't re-rendered into a fixture
still passes CI. The new test re-renders each fixture context into a
temp dir and fails if anything differs from what is committed.

Also assert in check_build_artifacts, which previously called
docker.image.exists() and discarded the result.
Port pti's blackbox tests to Bakery: build images that use the Jinja2
macros and assert their behavior with goss, instead of only asserting
rendered shell text. One image per macro module (syspkg, python, r,
quarto), one variant per scenario, across Ubuntu 22.04/24.04/26.04 and
Rocky Linux 9/10 so the dnf macros and rhel paths are covered.

- goss.yaml includes test/scenarios/<variant>.yaml at runtime, since
  non-Containerfile templates render once per version with no variant
  or OS. OS differences branch on IMAGE_OS_FAMILY inside scenarios.
- Per-OS Containerfiles are identical and branch on Image.OS, so every
  scenario runs the same macros on every OS. A unit test enforces
  that, and that each variant has a scenario file.
- Assertions avoid arch-specific paths so arm64 can be added later by
  listing it under each OS's platforms.
- Python and R pin two versions each so multi-version macro loops are
  exercised.
- check-yaml now skips goss scenario files, which use Go template
  blocks that are not valid YAML until goss renders them.
python.run_install_packages() and r.run_install_packages() emit one RUN
per version, and each RUN ended by deleting the requirements/package
list files. Every version after the first then failed because its
input files were already gone. Only the last version's RUN now removes
them.

r.run_install_packages() also gains the clean parameter that
python.run_install_packages() already had.

Found by the macros-functional python/packages scenario, which pins two
Python versions; pti only ever tested one.
Add a Blackbox Tests job that builds and goss-tests the macros-functional
context through the reusable bakery-build.yml workflow. It has no needs,
so it runs in parallel with the Test job, and fans out one runner per
image. The CI gate requires it.

- blackbox-clean-caches prunes this context's build caches, matching
  the other suites.
- just test-macros runs the same build and dgoss locally and accepts
  bakery filter flags.
- README documents the layout, adding scenarios, adding arm64, and the
  pti tests that were dropped.
A full local run builds 55 images with several GB of layers, and left
them behind along with their build cache. The recipe now builds with a
dedicated buildx builder and, on exit (pass or fail), removes the
images it built and that builder, which discards its build cache
without touching any other builder's cache.

Arguments are now passed positionally so filter values with spaces,
such as --image-os 'Rocky Linux 9', survive quoting.
tlmgr is a Perl script that needs core modules (File::Find) missing
from the perl-base in Debian-like base images and absent entirely on
Rocky. Without perl, tlmgr fails, and quarto's --update-path only warns
("Unable to determine a path to use when installing TeX Live"), so the
build succeeds with TinyTeX off the PATH and tlmgr unusable.

Found by the macros-functional quarto/tinytex scenario. with-macros
had the same broken install; its goss never ran tlmgr. connect-content
works only because its package lists install perl themselves.
`just test` deselects `image_build` tests, not `slow` tests. Also
document the new `just test-macros` recipe.
CI built the with-macros image three times per run: two pytest
image_build scenarios and the `bakery` job. The blackbox job covers
the same ground on a wider macro surface, five OSes, and the same
bakery-build.yml workflow, so all three are redundant.

- Drop the `bakery` CI job and its cache-clean job
- Drop the with-macros build and dgoss pytest scenarios
- Keep with-macros as a render fixture for update/create tests and
  the drift check

`release` needed `bakery` so that a tag only publishes once the
tagged bakery works end to end in bakery-build.yml, the reusable
workflow product repos call. `blackbox` is now the only job that
runs bakery-build.yml, so it takes over that gate.
Run all macro scenarios for an OS on one runner so builds reuse base
image layers instead of repeating those pulls in image-specific jobs.
Name each job for its OS and guard the matrix against fixture drift.
Use a short, scope-neutral job name so the suite can grow beyond macro scenarios while remaining distinct from unit tests and image builds.
Retain existing cleanup behavior in the shared Python and R macros,
and avoid adding Perl to every TinyTeX image. Exercise file-based
installs on one version and install Perl only in the TinyTeX test
fixture.
Preserve shared package-list files for every version in multi-version
Python and R installs, then remove them after the final RUN. Expose the
same clean control for R. Keep Perl out of Quarto's TinyTeX install path
and limit its blackbox scenario to verifying TinyTeX installation.
@bschwedler
bschwedler force-pushed the port-pti-blackbox-tests branch from a65de1f to 27da00a Compare September 30, 2026 16:56

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Blackbox tests from posit-dev/pti are ported over to bakery

2 participants