mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-06 04:12:04 +00:00
ci: emit ci-complete from self-CI for the CI complete ruleset (#162)
Some checks are pending
ci / isolation-tests (push) Waiting to run
ci / actionlint (push) Waiting to run
ci / ci-complete (push) Blocked by required conditions
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
Some checks are pending
ci / isolation-tests (push) Waiting to run
ci / actionlint (push) Waiting to run
ci / ci-complete (push) Blocked by required conditions
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
* ci: emit ci-complete from self-CI for the CI complete ruleset * fix(ci): keep a temporary ci / ci alias until the ruleset cutover * revert: drop the temporary ci / ci alias; the ruleset cutover landed
This commit is contained in:
parent
d154915a36
commit
b1aeebfca5
2 changed files with 40 additions and 15 deletions
51
.github/workflows/ci.yaml
vendored
51
.github/workflows/ci.yaml
vendored
|
|
@ -2,21 +2,22 @@ name: ci
|
|||
|
||||
# Self-CI for this org `.github` repo.
|
||||
#
|
||||
# The org ruleset "main branch protection" requires the `ci / ci` status check on
|
||||
# every repo. Consumer repos satisfy it via a short caller workflow that invokes
|
||||
# the reusable workflows here. This repo only HOUSES those reusable workflows
|
||||
# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat
|
||||
# permanently "Expected — Waiting for status to be reported" and could not merge.
|
||||
# This repo is on the org "CI complete" ruleset, which requires the
|
||||
# `ci-complete` status check on `main`. Consumer repos satisfy that ruleset
|
||||
# with a caller workflow that fans out to the reusable workflows housed here
|
||||
# and ends in a caller-owned `ci-complete` aggregator. This repo only HOUSES
|
||||
# those reusable workflows (all `workflow_call`-only), so it needs its own
|
||||
# portions and aggregator or every PR would sit permanently
|
||||
# "Expected — Waiting for status to be reported" and could not merge.
|
||||
#
|
||||
# This workflow produces that check by linting the workflow files with actionlint
|
||||
# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML.
|
||||
# The portions are genuinely useful CI for a repo whose whole product is
|
||||
# GitHub Actions YAML: the isolation-checker unit tests and actionlint over
|
||||
# every workflow file. They run in parallel; `ci-complete` requires both.
|
||||
#
|
||||
# Naming is load-bearing: the ruleset matches the required status check against
|
||||
# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job
|
||||
# the check-run name IS the job name, so the job must be named literally "ci / ci"
|
||||
# to emit that exact context. (A job named "ci" emits the context "ci" — which the
|
||||
# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.)
|
||||
# This mirrors the org's aggregator-job convention.
|
||||
# the check-run name IS the job name, so the aggregator is named literally
|
||||
# "ci-complete". Do not put the portion job names in a ruleset.
|
||||
#
|
||||
# actionlint is pinned to a tagged release and installed by downloading the
|
||||
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
|
||||
|
|
@ -47,9 +48,10 @@ permissions:
|
|||
contents: read
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
name: ci / ci
|
||||
isolation-tests:
|
||||
name: isolation-tests
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
|
|
@ -57,6 +59,13 @@ jobs:
|
|||
run: python3 scripts/test_check_app_terraform_isolation.py
|
||||
shell: bash
|
||||
|
||||
actionlint:
|
||||
name: actionlint
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Install actionlint
|
||||
env:
|
||||
ACTIONLINT_VERSION: 1.7.12
|
||||
|
|
@ -73,3 +82,19 @@ jobs:
|
|||
shellcheck --version
|
||||
./actionlint -color
|
||||
shell: bash
|
||||
|
||||
ci-complete:
|
||||
name: ci-complete
|
||||
needs: [isolation-tests, actionlint]
|
||||
if: always() && !cancelled()
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- name: Require portions
|
||||
env:
|
||||
ISOLATION_TESTS: ${{ needs.isolation-tests.result }}
|
||||
ACTIONLINT: ${{ needs.actionlint.result }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
test "${ISOLATION_TESTS}" = success
|
||||
test "${ACTIONLINT}" = success
|
||||
|
|
|
|||
|
|
@ -33,7 +33,7 @@ CI callers keep a `merge_group` trigger so native GitHub merge queues still run
|
|||
Two org rulesets. A repo is on exactly one of them:
|
||||
|
||||
- **main branch protection** requires `ci / ci` for unconverted remaining-lane repos.
|
||||
- **CI complete** requires `ci-complete` for converted HCP callers. It targets no repos until a cutover includes the repo and excludes it from the old ruleset in the same window.
|
||||
- **CI complete** requires `ci-complete` for converted HCP callers and for this repo. A repo joins it only when a cutover includes the repo and excludes it from the old ruleset in the same window.
|
||||
|
||||
The formatter GitHub App is not on the main-branch bypass list.
|
||||
|
||||
|
|
@ -93,7 +93,7 @@ The formatter GitHub App is not on the main-branch bypass list.
|
|||
|
||||
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
|
||||
|
||||
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
|
||||
**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
|
||||
|
||||
### Workflow templates (`workflow-templates/`)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue