Summary
CI that builds CryptOS and installs it on the remote ESXi box, using the private self-hosted runners, on trusted events only (push to main, tags, owner dispatch; never pull_request or pull_request_target).
Every other CryptOS-PKI workflow stays on GitHub-hosted runners. The code repos are public, so hosted runners are free and fork pull requests never reach our own machines. The earlier plan to move all CI onto the private group is dropped (see CryptOS-PKI/cryptos-node#263 for the hosted-runner cleanup in this repo).
Scope
- Runner group:
runs-on: { group: self-hosted-private } (x86_64 only).
- Triggers:
push to main, v* tags, and workflow_dispatch by the repo owner only. The job guards with if: github.event_name != 'pull_request' && github.event_name != 'pull_request_target' and checks github.actor on dispatch. No pull_request_target anywhere.
- Secrets for the box sit behind a GitHub environment with a required reviewer.
- It will be set up from the owner's Linux-box session, which has the ESXi setup. It's undecided whether it lives in this repo or in its own repo.
Owner setup
- Grant the
self-hosted-private group to the repo that runs it, with "Allow public repositories" on if that repo is public.
- Create the environment with a required reviewer and the box secrets.
- The runners need passwordless sudo and apt for the image build.
Sub-issue: #13.
Summary
CI that builds CryptOS and installs it on the remote ESXi box, using the private self-hosted runners, on trusted events only (push to main, tags, owner dispatch; never pull_request or pull_request_target).
Every other CryptOS-PKI workflow stays on GitHub-hosted runners. The code repos are public, so hosted runners are free and fork pull requests never reach our own machines. The earlier plan to move all CI onto the private group is dropped (see CryptOS-PKI/cryptos-node#263 for the hosted-runner cleanup in this repo).
Scope
runs-on: { group: self-hosted-private }(x86_64 only).pushtomain,v*tags, andworkflow_dispatchby the repo owner only. The job guards withif: github.event_name != 'pull_request' && github.event_name != 'pull_request_target'and checksgithub.actoron dispatch. Nopull_request_targetanywhere.Owner setup
self-hosted-privategroup to the repo that runs it, with "Allow public repositories" on if that repo is public.Sub-issue: #13.