Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/workflows/action-lint.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
push:
branches: [main]
paths: ['.github/workflows/**']
Expand All @@ -24,8 +24,9 @@ permissions:
jobs:
actionlint:
name: 🧹 Actionlint${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: 📥 Checkout
uses: actions/checkout@v4
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/ci-go.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
paths-ignore:
- "**.md"
- "docs/**"
Expand All @@ -38,8 +38,9 @@ concurrency:
jobs:
go-validation:
name: Go validation (format, lint, vet, test, build)${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/ci-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,7 @@ jobs:
if: ${{ !startsWith(github.ref, 'refs/tags/v') && !inputs.release_assets }}
# amd64 -> ubuntu-latest (x86_64); arm64 -> the hosted arm64 runner.
runs-on: ${{ (github.event.inputs.arch == 'arm64') && 'ubuntu-24.04-arm' || 'ubuntu-latest' }}
timeout-minutes: 60
env:
ARCH: ${{ github.event.inputs.arch || 'amd64' }}
steps:
Expand Down Expand Up @@ -139,6 +140,7 @@ jobs:
name: Build the unsigned release assets
if: ${{ startsWith(github.ref, 'refs/tags/v') || inputs.release_assets }}
runs-on: ${{ (github.event.inputs.arch == 'arm64') && 'ubuntu-24.04-arm' || 'ubuntu-latest' }}
timeout-minutes: 90
env:
ARCH: ${{ github.event.inputs.arch || 'amd64' }}
# The platform/statekey variants published for each release.
Expand Down Expand Up @@ -252,6 +254,7 @@ jobs:
needs: release-assets
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: write # create/update the release and upload the assets
env:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/cron-cleanup-runs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ jobs:
cleanup:
name: Prune old and failed runs
runs-on: ubuntu-latest
timeout-minutes: 10
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/job-gitleaks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
permissions:
contents: read
# One run per PR per workflow: a new push cancels the older PR run. Pushes to
Expand All @@ -26,8 +26,9 @@ concurrency:
jobs:
gitleaks:
name: 🔒 Gitleaks (secret scan)${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v6
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/job-golic.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
push:
branches: [main]
paths-ignore: ['**.md']
Expand All @@ -23,8 +23,9 @@ permissions:
jobs:
golic:
name: 🔏 License headers${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v6
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/job-label-checker.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ name: Label Checker
on:
pull_request:
branches: [main]
types: [opened, reopened, edited, synchronize]
types: [opened, reopened, edited, synchronize, ready_for_review]
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true
Expand All @@ -26,7 +26,9 @@ permissions:
jobs:
autolabel:
name: Autolabel
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
# Map the conventional-commit prefix in the PR title to a categorizing
# label and apply it. Best-effort (continue-on-error): the
Expand Down Expand Up @@ -62,8 +64,9 @@ jobs:
needs: [autolabel]
# Run even if autolabel was skipped/failed; the label may already be present
# from the PR title.
if: always()
if: always() && github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
pull-requests: read
steps:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/job-label-sync.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ jobs:
labeler:
name: Sync labels
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: crazy-max/ghaction-github-labeler@v5
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/job-license-check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
push:
branches: [main]
permissions:
Expand All @@ -22,8 +22,9 @@ concurrency:
jobs:
npm:
name: npm dependency licenses${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down Expand Up @@ -52,8 +53,9 @@ jobs:

go:
name: Go dependency licenses${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/job-pr-checks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ on:
# edited is here so retargeting a stacked PR onto main starts CI, and so
# a title or body edit re-runs the title and body checks. The diff-based
# job skips edited events that did not change the base.
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
# One run per PR per workflow: a new push cancels the older PR run. A title
# or body edit gets its own group, so its run never cancels real CI.
concurrency:
Expand All @@ -20,16 +20,19 @@ permissions:
jobs:
pr-title:
name: PR Title
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: amannn/action-semantic-pull-request@v5
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

pr-hygiene:
name: PR Hygiene${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
if: github.event.action != 'edited' || github.event.changes.base != null
if: github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null)
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
with:
Expand Down Expand Up @@ -63,7 +66,9 @@ jobs:

pr-body:
name: PR Body
if: github.event.pull_request.draft != true
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check body
env:
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/release-drafter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ on:
branches: [main]
# edited is here so retargeting a stacked PR onto main starts CI. Jobs
# skip edited events that did not change the base (title/body edits).
types: [opened, synchronize, reopened, edited]
types: [opened, synchronize, reopened, ready_for_review, edited]
workflow_dispatch:

permissions:
Expand All @@ -35,8 +35,9 @@ jobs:
draft:
name: Draft release and update changelog${{ github.event.action == 'edited' && github.event.changes.base == null && ' (edit, not run)' || '' }}
# Inert until the GitHub App is configured (see header).
if: ${{ vars.APP_CLIENT_ID != '' && (github.event.action != 'edited' || github.event.changes.base != null) }}
if: ${{ vars.APP_CLIENT_ID != '' && github.event.pull_request.draft != true && (github.event.action != 'edited' || github.event.changes.base != null) }}
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write # update releases + push the changelog commit
pull-requests: write # autolabeler
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@ They are for evaluation with Secure Boot off. A node installed from one cannot b

GitHub Actions:

- **`ci-go`** ([`ci-go.yml`](.github/workflows/ci-go.yml)) — `task ci` (format, lint, vet, test, build) on every pull request + push to `main`, on a GitHub-hosted Linux runner.
- **`ci-go`** ([`ci-go.yml`](.github/workflows/ci-go.yml)) — `task ci` (format, lint, vet, test, build) on every pull request + push to `main`, on a GitHub-hosted Linux runner. Draft pull requests are skipped; CI runs when the PR is marked ready.
- **`ci-image`** ([`ci-image.yml`](.github/workflows/ci-image.yml)) — builds the UKI on a **GitHub-hosted runner** (amd64 on `ubuntu-latest`, arm64 on `ubuntu-24.04-arm`), installing the kernel / `ukify` / `sbsign` toolchain per run. Runs on push to `main`, tags, and manual dispatch; use `workflow_dispatch` on a branch to validate image changes before merging. On `main` it signs with a per-run ephemeral key as a smoke test and uploads nothing. On a `v*` tag it builds the unsigned [release assets](#release-assets) and attaches them to the tag's release (a draft, marked pre-release for `-alpha`/`-beta`/`-rc` tags, if none exists yet); dispatch with `release_assets` builds them without publishing.

The QEMU + `swtpm` integration boot is run on a real host by the operator, not in CI.
Expand Down
Loading