Skip to content

ci: keep every job on GitHub-hosted runners - #263

Merged
Bugs5382 merged 2 commits into
mainfrom
ci/262-shared-runners
Sep 29, 2026
Merged

Bugs5382 merged 2 commits into
mainfrom
ci/262-shared-runners

Conversation

@Bugs5382

@Bugs5382 Bugs5382 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

What and why

Keeps every job in this repo on GitHub-hosted runners and brings the workflows in line with the minute-saving pattern. The repo is public, so hosted runners are free, and fork pull requests never run code on our own machines.

  • Runners: every job stays on ubuntu-latest. The two image-build jobs (build-image, release-assets) still pick ubuntu-24.04-arm for arm64 dispatches.
  • Timeouts: every job gets timeout-minutes: 10 for the small checks, 15 for the license checks and the release upload, 20 for Go validation, 60 for the image build and 90 for the release assets. Recent image builds take 4 to 9 minutes.
  • Drafts: jobs that run on pull requests skip drafts (github.event.pull_request.draft != true, which stays true on push events). ready_for_review is added to their pull_request types, so marking a PR ready starts CI.
  • Docs: the README's CI section notes that draft pull requests are skipped.

Private-runner work for building CryptOS and installing it on the remote ESXi box is tracked in CryptOS-PKI/cryptos#261. Nothing in this PR uses the private runners.

Refs CryptOS-PKI/cryptos-appliance#14
Refs CryptOS-PKI/cryptos-appliance#13

Verification

  • Lint clean
  • Tests pass
  • Build succeeds
  • Documentation updated (if behavior or API changed)

How this was verified

  • actionlint -shellcheck= (as the Actionlint workflow runs it) passes on every workflow.
  • The pre-push hook (go vet, go test ./...) passes locally.
  • No workflow references self-hosted-private or pull_request_target.

Every job moves from ubuntu-latest to the self-hosted-private runner
group. The image-build jobs keep the hosted ubuntu-24.04-arm runner for
arm64 dispatches, because the group only has x86_64 runners.

Every touched job gets a timeout-minutes. Jobs that run on pull requests
skip drafts, and ready_for_review is added to their triggers so marking
a PR ready starts CI. The README CI section now names the runners.

Refs: #262
@Bugs5382 Bugs5382 added the skip-changelog Excluded from release notes (chore/ci/test/style). label Sep 29, 2026
@Bugs5382 Bugs5382 self-assigned this Sep 29, 2026
The repo is public, so hosted runners are free and fork pull requests never
reach the private runner group. The timeouts, draft skip and ready_for_review
triggers stay.
@Bugs5382 Bugs5382 changed the title ci: run workflows on the shared self-hosted runner group ci: keep every job on GitHub-hosted runners Sep 29, 2026
@Bugs5382
Bugs5382 marked this pull request as ready for review September 29, 2026 02:59
@Bugs5382

Copy link
Copy Markdown
Contributor Author

Closing summary

Every job in this repo stays on GitHub-hosted runners, which are free for public repos and keep fork PRs off our own machines; arm64 image builds stay on ubuntu-24.04-arm. The jobs that lacked them gain timeout-minutes and the draft skip, and ready_for_review now starts CI. The private-runner work to build and install on the remote ESXi box is tracked in CryptOS-PKI/cryptos-appliance#14.

@Bugs5382
Bugs5382 merged commit 3ae738b into main Sep 29, 2026
@Bugs5382
Bugs5382 deleted the ci/262-shared-runners branch September 29, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Excluded from release notes (chore/ci/test/style).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant