Repository navigation
ci: keep every job on GitHub-hosted runners - #263
Merged
Merged
Conversation
Every job moves from ubuntu-latest to the self-hosted-private runner group. The image-build jobs keep the hosted ubuntu-24.04-arm runner for arm64 dispatches, because the group only has x86_64 runners. Every touched job gets a timeout-minutes. Jobs that run on pull requests skip drafts, and ready_for_review is added to their triggers so marking a PR ready starts CI. The README CI section now names the runners. Refs: #262
The repo is public, so hosted runners are free and fork pull requests never reach the private runner group. The timeouts, draft skip and ready_for_review triggers stay.
Bugs5382
marked this pull request as ready for review
September 29, 2026 02:59
Contributor
Author
|
Closing summary Every job in this repo stays on GitHub-hosted runners, which are free for public repos and keep fork PRs off our own machines; arm64 image builds stay on ubuntu-24.04-arm. The jobs that lacked them gain timeout-minutes and the draft skip, and ready_for_review now starts CI. The private-runner work to build and install on the remote ESXi box is tracked in CryptOS-PKI/cryptos-appliance#14. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Keeps every job in this repo on GitHub-hosted runners and brings the workflows in line with the minute-saving pattern. The repo is public, so hosted runners are free, and fork pull requests never run code on our own machines.
ubuntu-latest. The two image-build jobs (build-image,release-assets) still pickubuntu-24.04-armfor arm64 dispatches.timeout-minutes: 10 for the small checks, 15 for the license checks and the release upload, 20 for Go validation, 60 for the image build and 90 for the release assets. Recent image builds take 4 to 9 minutes.github.event.pull_request.draft != true, which stays true on push events).ready_for_reviewis added to theirpull_requesttypes, so marking a PR ready starts CI.Private-runner work for building CryptOS and installing it on the remote ESXi box is tracked in CryptOS-PKI/cryptos#261. Nothing in this PR uses the private runners.
Refs CryptOS-PKI/cryptos-appliance#14
Refs CryptOS-PKI/cryptos-appliance#13
Verification
How this was verified
actionlint -shellcheck=(as the Actionlint workflow runs it) passes on every workflow.go vet,go test ./...) passes locally.self-hosted-privateorpull_request_target.