# Invoked by sdk.yml to run full subprocess Java SDK coverage followed by focused # in-process smoke on standard platforms and x64 musl, plus JDK 17 and docs checks. name: "SDK Java" env: HUSKY: 0 POWERSHELL_UPDATECHECK: Off SDK_HOME: ${{ inputs.sdk-home }} SETUP_NODE_TIMEOUT_MINUTES: 10 on: workflow_call: inputs: platform: required: false type: string default: all sdk-home: required: true type: string permissions: contents: read jobs: java: name: "Java (${{ matrix.os }}, JDK ${{ matrix.test-jdk }})" if: contains(fromJSON('["all","linux-x64","darwin-arm64","win32-x64"]'), inputs.platform) strategy: fail-fast: false matrix: os: ${{ fromJSON(inputs.platform == 'linux-x64' && '["ubuntu-latest"]' || inputs.platform == 'darwin-arm64' && '["macos-26"]' || inputs.platform == 'win32-x64' && '["windows-latest"]' || '["ubuntu-latest","macos-26","windows-latest"]') }} test-jdk: ["25", "17"] exclude: - os: macos-26 test-jdk: "17" - os: windows-latest test-jdk: "17" runs-on: ${{ matrix.os }} defaults: run: shell: bash working-directory: ${{ inputs.sdk-home }}/java steps: - uses: actions/checkout@v7 timeout-minutes: 4 with: persist-credentials: false - uses: ./.github/actions/download-sdk-runtime with: artifact-name: ${{ runner.os == 'Linux' && format('executable-sdk-{0}-{1}-gnu', runner.os, runner.arch) || format('executable-sdk-{0}-{1}', runner.os, runner.arch) }} path: ${{ github.workspace }} - run: node "$SDK_HOME/scripts/ci/runtime-artifact.mjs" restore && node "$SDK_HOME/scripts/ci/runtime-artifact.mjs" prepare working-directory: . - uses: actions/setup-java@v5 with: java-version: "25" distribution: microsoft cache: maven - uses: actions/setup-node@v6 with: node-version: 22 # TEMPORARY MERGE QUEUE REDUCTION: pull requests and main pushes retain # static checks; merge groups rerun only SDK compatibility coverage. - if: github.event_name != 'merge_group' && runner.os == 'Linux' && matrix.test-jdk == '25' run: ./scripts/test-update-documentation-versions.sh - run: ./mvnw test-compile jar:jar - if: github.event_name != 'merge_group' && runner.os == 'Linux' && matrix.test-jdk == '25' run: ./mvnw javadoc:javadoc - if: github.event_name != 'merge_group' && runner.os == 'Linux' && matrix.test-jdk == '25' run: ./mvnw spotless:check - if: runner.os == 'Windows' run: pwsh.exe -Command "Write-Host 'PowerShell ready'" - if: matrix.test-jdk == '25' id: subprocess env: CI: "true" run: ./mvnw -pl sdk verify -Dskip.test.harness=true -Dcopilot.cli.path="$COPILOT_CLI_PATH" - if: matrix.test-jdk == '17' uses: actions/setup-java@v5 with: java-version: "17" distribution: microsoft - if: matrix.test-jdk == '17' env: CI: "true" run: ./mvnw -pl sdk jacoco:prepare-agent@wire-up-coverage-instrumentation antrun:run@print-test-jdk-banner surefire:test failsafe:integration-test failsafe:verify jacoco:report@build-coverage-report-from-tests -Denforcer.skip=true -Dcopilot.cli.path="$COPILOT_CLI_PATH" - name: Test in-process smoke if: ${{ !cancelled() && matrix.test-jdk == '25' && (steps.subprocess.outcome == 'success' || steps.subprocess.outcome == 'failure') }} env: CI: "true" run: | mkdir -p sdk/target/subprocess-reports for reports in surefire-reports surefire-reports-isolated failsafe-reports; do if [ -d "sdk/target/$reports" ]; then mv "sdk/target/$reports" sdk/target/subprocess-reports/ fi done ./mvnw verify -Pinprocess \ -Dskip.test.harness=true \ -Dtest=NoTestsForInProcessSmoke \ -Dsurefire.failIfNoSpecifiedTests=false \ -Dit.test=InProcessTransportIT,AuthHostE2ETest \ -Dcopilot.inprocess.cli.path="$COPILOT_CLI_PATH" - if: github.event_name != 'merge_group' && runner.os == 'Linux' && matrix.test-jdk == '25' run: ./mvnw install -Dmaven.test.skip=true -Dskip.test.harness=true -Dcopilot.native.skip.download=true - name: Validate documentation examples if: github.event_name != 'merge_group' && runner.os == 'Linux' && matrix.test-jdk == '25' working-directory: ${{ inputs.sdk-home }}/scripts/docs-validation run: | npm ci npm run extract npm run validate:java - if: failure() uses: actions/upload-artifact@v7 with: name: java-test-results-${{ matrix.os }}-jdk-${{ matrix.test-jdk }} path: | ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports/ ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports-isolated/ ${{ inputs.sdk-home }}/java/sdk/target/failsafe-reports/ ${{ inputs.sdk-home }}/java/sdk/target/subprocess-reports/ retention-days: 7 java-musl-x64: name: "Java (JDK 25, linuxmusl-x64)" if: inputs.platform == 'all' || inputs.platform == 'linuxmusl-x64' runs-on: ubuntu-latest timeout-minutes: 30 steps: - uses: actions/checkout@v7 timeout-minutes: 4 with: persist-credentials: false - uses: ./.github/actions/download-sdk-runtime with: artifact-name: executable-sdk-Linux-X64-musl path: ${{ github.workspace }} - run: node "$SDK_HOME/scripts/ci/runtime-artifact.mjs" restore working-directory: . - uses: ./.github/actions/run-alpine-tests env: COPILOT_HMAC_KEY: ${{ secrets.COPILOT_DEVELOPER_CLI_INTEGRATION_HMAC_KEY }} with: image: eclipse-temurin:25-jdk-alpine sdk-root: /workspace/${{ inputs.sdk-home }} workdir: /workspace/${{ inputs.sdk-home }}/java command: | apk add --no-cache java-cacerts maven nodejs npm export JAVA_TOOL_OPTIONS=-Djavax.net.ssl.trustStore=/etc/ssl/certs/java/cacerts export GITHUB_ENV=/tmp/copilot-sdk-runtime.env export COPILOT_RUNTIME_TARGET=linuxmusl-x64 export COPILOT_RUNTIME_OUTPUT_DIRECTORY=/workspace/.sdk-runtime/linuxmusl-x64 node "$COPILOT_SDK_ROOT/scripts/ci/runtime-artifact.mjs" prepare set -a . "$GITHUB_ENV" set +a node copilot-native/scripts/validate-native-host.mjs linuxmusl-x64 ./mvnw test-compile jar:jar -Dcopilot.native.libc=musl status=0 ./mvnw -pl sdk verify -Dskip.test.harness=true -Dcopilot.cli.path="$COPILOT_CLI_PATH" || status=$? mkdir -p sdk/target/subprocess-reports for reports in surefire-reports surefire-reports-isolated failsafe-reports; do if [ -d "sdk/target/$reports" ]; then mv "sdk/target/$reports" sdk/target/subprocess-reports/ fi done ./mvnw verify -Pinprocess \ -Dskip.test.harness=true \ -Dtest=NoTestsForInProcessSmoke \ -Dsurefire.failIfNoSpecifiedTests=false \ -Dit.test=InProcessTransportIT,AuthHostE2ETest \ -Dcopilot.native.libc=musl \ -Dcopilot.inprocess.cli.path="$COPILOT_CLI_PATH" || status=$? exit "$status" - if: failure() uses: actions/upload-artifact@v7 with: name: java-test-results-linuxmusl-x64 path: | ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports/ ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports-isolated/ ${{ inputs.sdk-home }}/java/sdk/target/failsafe-reports/ ${{ inputs.sdk-home }}/java/sdk/target/subprocess-reports/ retention-days: 7 java-musl-arm64: name: "Java (JDK 25, linuxmusl-arm64)" if: inputs.platform == 'all' || inputs.platform == 'linuxmusl-arm64' runs-on: ubuntu-24.04-arm timeout-minutes: 30 steps: - uses: actions/checkout@v7 timeout-minutes: 4 with: persist-credentials: false - uses: ./.github/actions/download-sdk-runtime with: artifact-name: executable-sdk-Linux-ARM64-musl path: ${{ github.workspace }} - run: node "$SDK_HOME/scripts/ci/runtime-artifact.mjs" restore working-directory: . - name: Run Java SDK tests (linuxmusl-arm64) env: COPILOT_HMAC_KEY: ${{ secrets.COPILOT_DEVELOPER_CLI_INTEGRATION_HMAC_KEY }} run: | docker run --rm \ --volume "$GITHUB_WORKSPACE:/workspace" \ --workdir "/workspace/$SDK_HOME/java" \ --env CI=true \ --env COPILOT_HMAC_KEY \ --env GITHUB_ACTIONS=true \ --env GITHUB_WORKSPACE=/workspace \ --env COPILOT_SDK_ROOT="/workspace/$SDK_HOME" \ eclipse-temurin:25-jdk-alpine \ sh -c 'set -eux apk add --no-cache bash git java-cacerts maven nodejs npm git config --global --add safe.directory /workspace export JAVA_TOOL_OPTIONS=-Djavax.net.ssl.trustStore=/etc/ssl/certs/java/cacerts export GITHUB_ENV=/tmp/copilot-sdk-runtime.env export COPILOT_RUNTIME_TARGET=linuxmusl-arm64 export COPILOT_RUNTIME_OUTPUT_DIRECTORY=/workspace/.sdk-runtime/linuxmusl-arm64 node "$COPILOT_SDK_ROOT/scripts/ci/runtime-artifact.mjs" prepare set -a . "$GITHUB_ENV" set +a node copilot-native/scripts/validate-native-host.mjs linuxmusl-arm64 ./mvnw test-compile jar:jar -Dcopilot.native.libc=musl status=0 ./mvnw -pl sdk verify -Dskip.test.harness=true -Dcopilot.cli.path="$COPILOT_CLI_PATH" || status=$? mkdir -p sdk/target/subprocess-reports for reports in surefire-reports surefire-reports-isolated failsafe-reports; do if [ -d "sdk/target/$reports" ]; then mv "sdk/target/$reports" sdk/target/subprocess-reports/ fi done ./mvnw verify -Pinprocess \ -Dskip.test.harness=true \ -Dtest=NoTestsForInProcessSmoke \ -Dsurefire.failIfNoSpecifiedTests=false \ -Dit.test=InProcessTransportIT,AuthHostE2ETest \ -Dcopilot.native.libc=musl \ -Dcopilot.inprocess.cli.path="$COPILOT_CLI_PATH" || status=$? exit "$status"' - if: failure() uses: actions/upload-artifact@v7 with: name: java-test-results-linuxmusl-arm64 path: | ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports/ ${{ inputs.sdk-home }}/java/sdk/target/surefire-reports-isolated/ ${{ inputs.sdk-home }}/java/sdk/target/failsafe-reports/ ${{ inputs.sdk-home }}/java/sdk/target/subprocess-reports/ retention-days: 7