ci: emit ci-complete from self-CI for the CI complete ruleset (#162)
Some checks are pending
ci / isolation-tests (push) Waiting to run
ci / actionlint (push) Waiting to run
ci / ci-complete (push) Blocked by required conditions
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions

* ci: emit ci-complete from self-CI for the CI complete ruleset

* fix(ci): keep a temporary ci / ci alias until the ruleset cutover

* revert: drop the temporary ci / ci alias; the ruleset cutover landed
This commit is contained in:
Adam Moussa 2026-10-05 21:49:03 +00:00 • committed by GitHub
parent d154915a36
commit b1aeebfca5
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 40 additions and 15 deletions

View file

@ -2,21 +2,22 @@ name: ci
# Self-CI for this org `.github` repo.
#
# The org ruleset "main branch protection" requires the `ci / ci` status check on
# every repo. Consumer repos satisfy it via a short caller workflow that invokes
# the reusable workflows here. This repo only HOUSES those reusable workflows
# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat
# permanently "Expected — Waiting for status to be reported" and could not merge.
# This repo is on the org "CI complete" ruleset, which requires the
# `ci-complete` status check on `main`. Consumer repos satisfy that ruleset
# with a caller workflow that fans out to the reusable workflows housed here
# and ends in a caller-owned `ci-complete` aggregator. This repo only HOUSES
# those reusable workflows (all `workflow_call`-only), so it needs its own
# portions and aggregator or every PR would sit permanently
# "Expected — Waiting for status to be reported" and could not merge.
#
# This workflow produces that check by linting the workflow files with actionlint
# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML.
# The portions are genuinely useful CI for a repo whose whole product is
# GitHub Actions YAML: the isolation-checker unit tests and actionlint over
# every workflow file. They run in parallel; `ci-complete` requires both.
#
# Naming is load-bearing: the ruleset matches the required status check against
# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job
# the check-run name IS the job name, so the job must be named literally "ci / ci"
# to emit that exact context. (A job named "ci" emits the context "ci" — which the
# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.)
# This mirrors the org's aggregator-job convention.
# the check-run name IS the job name, so the aggregator is named literally
# "ci-complete". Do not put the portion job names in a ruleset.
#
# actionlint is pinned to a tagged release and installed by downloading the
# release tarball and verifying its SHA256 — not `curl | bash` — to keep the
@ -47,9 +48,10 @@ permissions:
contents: read
jobs:
ci:
name: ci / ci
isolation-tests:
name: isolation-tests
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
@ -57,6 +59,13 @@ jobs:
run: python3 scripts/test_check_app_terraform_isolation.py
shell: bash
actionlint:
name: actionlint
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install actionlint
env:
ACTIONLINT_VERSION: 1.7.12
@ -73,3 +82,19 @@ jobs:
shellcheck --version
./actionlint -color
shell: bash
ci-complete:
name: ci-complete
needs: [isolation-tests, actionlint]
if: always() && !cancelled()
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Require portions
env:
ISOLATION_TESTS: ${{ needs.isolation-tests.result }}
ACTIONLINT: ${{ needs.actionlint.result }}
run: |
set -euo pipefail
test "${ISOLATION_TESTS}" = success
test "${ACTIONLINT}" = success

View file

@ -33,7 +33,7 @@ CI callers keep a `merge_group` trigger so native GitHub merge queues still run
Two org rulesets. A repo is on exactly one of them:
- **main branch protection** requires `ci / ci` for unconverted remaining-lane repos.
- **CI complete** requires `ci-complete` for converted HCP callers. It targets no repos until a cutover includes the repo and excludes it from the old ruleset in the same window.
- **CI complete** requires `ci-complete` for converted HCP callers and for this repo. A repo joins it only when a cutover includes the repo and excludes it from the old ruleset in the same window.
The formatter GitHub App is not on the main-branch bypass list.
@ -93,7 +93,7 @@ The formatter GitHub App is not on the main-branch bypass list.
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: actionlint (checksum-verified install) over all workflow files, emitting the required `ci / ci` status context. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
**`.github/workflows/ci.yaml`** — Self-CI for this repo: parallel `isolation-tests` (the isolation-checker unit tests) and `actionlint` (checksum-verified install) portions, plus a `ci-complete` aggregator that emits the status context the CI complete ruleset requires. Its shellcheck integration is enabled, so `run:` bodies are shell-linted too; the two deploy steps that rely on intentional word-splitting (`sam deploy … $PARAMS`, `cdk deploy $STACKS`) carry a per-line, commented `# shellcheck disable=SC2086` rather than being quoted or globally exempted.
### Workflow templates (`workflow-templates/`)