diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..0c16e84 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1 @@ +* @PhilippTheServer @maltonoloco diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 6cfd6bb..7e9985d 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -210,6 +210,9 @@ jobs: run: | uv sync --extra dev + - name: 📄 Community files + run: test -f CODE_OF_CONDUCT.md && test -f CONTRIBUTING.md && test -f .github/CODEOWNERS + - name: 🔍 Run Ruff linting run: | source .venv/bin/activate diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..fc7df3c --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,72 @@ +# Code of Conduct + +OpenTaberna is built by people who care about getting things right, and who sometimes +get loud when they don't. That is fine. What is not fine is taking it out on each other. + +## The one rule that makes this project different + +**Swear at code all you like. Never swear at people.** + +Allowed: + +- "This function is a goddamn mess." +- "Who the hell thought a 400-line regex was a good idea? Let's rip it out." +- "This build is fucked again." + +Not allowed: + +- "You're an idiot for writing this." +- "Only a moron would ship this." +- Anything aimed at a person's intelligence, competence, identity or worth, whether it + contains swear words or not. + +Criticise the work, never the person who made it. Assume the author had a reason, ask +what it was, and then say how to make it better. If you would be embarrassed to say it to +their face in a room with everyone else present, don't write it. + +## What we expect + +- Be respectful of differing viewpoints and experience levels. +- Give feedback that is concrete and actionable, and take feedback the same way. +- Own your mistakes, apologise to the people affected, and learn from it. +- Focus on what is best for the project and the people using it. + +## What we do not tolerate + +- Insults, slurs or demeaning remarks about anyone, including profanity directed at a + person. +- Harassment, in public or in private, including continued contact after being asked to + stop. +- Discrimination based on age, body size, disability, ethnicity, sex characteristics, + gender identity and expression, level of experience, education, socio-economic status, + nationality, personal appearance, race, religion, or sexual identity and orientation. +- Sexualised language or imagery, and unwelcome sexual attention. +- Publishing others' private information without their explicit permission. +- Trolling, and deliberately derailing discussions. + +## Scope + +This applies in every OpenTaberna space — repositories, issues, pull requests, reviews, +chats — and when you represent the project elsewhere. + +## Reporting + +Report anything that breaks this code to the maintainers, @PhilippTheServer or +@maltonoloco. Reports are handled privately, and the reporter's identity is protected. + +## Enforcement + +Maintainers decide what counts as a breach and respond in proportion: + +1. **Correction** — a private note explaining what was wrong. A public apology may be + requested. +2. **Warning** — a formal warning with consequences for repeat behaviour. +3. **Temporary ban** — no interaction with the project for a set period. +4. **Permanent ban** — for repeated or severe breaches, including harassment. + +Maintainers may remove or edit comments, commits, code, issues and other contributions +that break this code. + +## Attribution + +Adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 2.1. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..d6de102 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,43 @@ +# Contributing + +Thanks for helping out. Read the [Code of Conduct](CODE_OF_CONDUCT.md) first — swearing +about code is fine, swearing at people is not. + +## How a change gets in + +`main` is protected. Only the maintainers, @PhilippTheServer and @maltonoloco, can push +to it directly. Everyone else goes through a pull request: + +1. **Open an issue** describing the behaviour you expect once it is solved. Small fixes + too — it is where the discussion lives. +2. **Branch** from `main` (or fork, if you have no write access). +3. **Commit and push** your branch. +4. **Open a pull request** against `main` and link the issue with `Closes #N` in the + body. +5. **CI must pass.** These checks are required before the PR can be merged: + - `Run Tests with Services` + - `Code Quality Checks` + - `Security Scan` + - `Test Docker Build` +6. **A maintainer must approve.** Every file is owned by @PhilippTheServer and + @maltonoloco (see [.github/CODEOWNERS](.github/CODEOWNERS)); one of them has to + review and approve. New commits after an approval need a fresh approval. +7. **Squash merge.** The PR lands as a single commit on `main`; delete the branch + afterwards. + +## Before you open the PR + +Run the same checks locally so CI has no surprises (integration tests also need the API +running, and `.env` needs `GARAGE_RPC_SECRET` — see Dev Setup in the [README](README.md)): + +```sh +uv sync --extra test --extra dev +uv run ruff check src/ tests/ +uv run ruff format --check src/ tests/ +docker compose -f docker-compose.dev.yml up -d \ + opentaberna-db opentaberna-redis opentaberna-keycloak opentaberna-garage +uv run pytest tests/ -m "not integration and not slow" +``` + +Update the docs in the same PR as the change, not afterwards, and add a test that would +fail if your fix regressed. diff --git a/README.md b/README.md index ebee844..506d691 100644 --- a/README.md +++ b/README.md @@ -41,6 +41,10 @@ generate one with `openssl rand -hex 32`. On start it creates its access key fro `STORAGE_ACCESS_KEY`/`STORAGE_SECRET_KEY`; the API creates its buckets itself. The S3 API is on `http://localhost:9000`, its health check on `http://localhost:3903/health`. +# Contributing + +See [CONTRIBUTING.md](CONTRIBUTING.md) and the [Code of Conduct](CODE_OF_CONDUCT.md). + # Pipelines This FastAPI can be build and tested via GitHub workflows. There are two available workflows: