diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 0c7164e..60c1150 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -2,21 +2,22 @@ name: ci # Self-CI for this org `.github` repo. # -# The org ruleset "main branch protection" requires the `ci / ci` status check on -# every repo. Consumer repos satisfy it via a short caller workflow that invokes -# the reusable workflows here. This repo only HOUSES those reusable workflows -# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat -# permanently "Expected — Waiting for status to be reported" and could not merge. +# This repo is on the org "CI complete" ruleset, which requires the +# `ci-complete` status check on `main`. Consumer repos satisfy that ruleset +# with a caller workflow that fans out to the reusable workflows housed here +# and ends in a caller-owned `ci-complete` aggregator. This repo only HOUSES +# those reusable workflows (all `workflow_call`-only), so it needs its own +# portions and aggregator or every PR would sit permanently +# "Expected — Waiting for status to be reported" and could not merge. # -# This workflow produces that check by linting the workflow files with actionlint -# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML. +# The portions are genuinely useful CI for a repo whose whole product is +# GitHub Actions YAML: the isolation-checker unit tests and actionlint over +# every workflow file. They run in parallel; `ci-complete` requires both. # # Naming is load-bearing: the ruleset matches the required status check against # the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job -# the check-run name IS the job name, so the job must be named literally "ci / ci" -# to emit that exact context. (A job named "ci" emits the context "ci" — which the -# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.) -# This mirrors the org's aggregator-job convention. +# the check-run name IS the job name, so the aggregator is named literally +# "ci-complete". Do not put the portion job names in a ruleset. # # actionlint is pinned to a tagged release and installed by downloading the # release tarball and verifying its SHA256 — not `curl | bash` — to keep the @@ -47,9 +48,10 @@ permissions: contents: read jobs: - ci: - name: ci / ci + isolation-tests: + name: isolation-tests runs-on: ubuntu-latest + timeout-minutes: 10 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -57,6 +59,13 @@ jobs: run: python3 scripts/test_check_app_terraform_isolation.py shell: bash + actionlint: + name: actionlint + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install actionlint env: ACTIONLINT_VERSION: 1.7.12 @@ -73,3 +82,19 @@ jobs: shellcheck --version ./actionlint -color shell: bash + + ci-complete: + name: ci-complete + needs: [isolation-tests, actionlint] + if: always() && !cancelled() + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Require portions + env: + ISOLATION_TESTS: ${{ needs.isolation-tests.result }} + ACTIONLINT: ${{ needs.actionlint.result }} + run: | + set -euo pipefail + test "${ISOLATION_TESTS}" = success + test "${ACTIONLINT}" = success diff --git a/README.md b/README.md index 42dc097..55d2d35 100644 --- a/README.md +++ b/README.md @@ -33,7 +33,7 @@ CI callers keep a `merge_group` trigger so native GitHub merge queues still run Two org rulesets. A repo is on exactly one of them: - **main branch protection** requires `ci / ci` for unconverted remaining-lane repos. -- **CI complete** requires `ci-complete` for converted HCP callers. It targets no repos until a cutover includes the repo and excludes it from the old ruleset in the same window. +- **CI complete** requires `ci-complete` for converted HCP callers and for this repo. A repo joins it only when a cutover includes the repo and excludes it from the old ruleset in the same window. The formatter GitHub App is not on the main-branch bypass list. @@ -93,7 +93,7 @@ The formatter GitHub App is not on the main-branch bypass list. **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. -**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. +**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted. ### Workflow templates (`workflow-templates/`)