Context
#536 added a Docker-backed integration test for the cockroachdb plugin (plugins/cockroachdb/database_credentials_integration_test.go), opt-in via COCKROACHDB_INTEGRATION=1. It was initially enabled in the shared Test job, which made every PR pull cockroachdb/cockroach from Docker Hub.
Problem
There's no convention for plugin tests that need real dependencies (containers, CLIs). Running them in the shared Test job makes every PR depend on Docker Hub (availability, rate limits) and adds pull time. Adding a workflow per plugin doesn't scale.
Proposal
- One shared
Integration workflow, triggered on plugins/**, that runs integration tests only for the plugin packages a PR changed (e.g. git diff --name-only HEAD^1 HEAD -- plugins/ on the PR merge commit).
- A single repo-wide opt-in instead of per-plugin env vars. Either:
- a shared env var (e.g.
SHELL_PLUGINS_INTEGRATION=1), which keeps files visible to go vet and golangci-lint, or
- a
//go:build integration tag, which needs lint/vet configured to use the tag so the files don't rot.
- Keep it a non-required check, since path-filtered workflows that don't run leave required checks pending.
- Migrate the cockroachdb test to the convention once it exists.
Context
#536 added a Docker-backed integration test for the cockroachdb plugin (
plugins/cockroachdb/database_credentials_integration_test.go), opt-in viaCOCKROACHDB_INTEGRATION=1. It was initially enabled in the sharedTestjob, which made every PR pullcockroachdb/cockroachfrom Docker Hub.Problem
There's no convention for plugin tests that need real dependencies (containers, CLIs). Running them in the shared
Testjob makes every PR depend on Docker Hub (availability, rate limits) and adds pull time. Adding a workflow per plugin doesn't scale.Proposal
Integrationworkflow, triggered onplugins/**, that runs integration tests only for the plugin packages a PR changed (e.g.git diff --name-only HEAD^1 HEAD -- plugins/on the PR merge commit).SHELL_PLUGINS_INTEGRATION=1), which keeps files visible togo vetand golangci-lint, or//go:build integrationtag, which needs lint/vet configured to use the tag so the files don't rot.