Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .github/workflows/deploy-kotlin-v2.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ on:
use-arc-runners:
required: false
type: boolean
default: false
description: "Run on the self-hosted ARC arm64 runners (takes precedence over use-blacksmith-runners). Applies to the test, image build and service profile jobs."
default: true
description: "Run on the self-hosted ARC arm64 runners (default; takes precedence over use-blacksmith-runners). Never used in public repositories: the ARC runner group rejects them, so they keep the Blacksmith/GitHub-hosted runners. Applies to the test, image build and service profile jobs."
# DEPRECATED (no-op): all builds and CI run on arm64. Retained for backwards
# compatibility with callers still passing it; the value is ignored and this
# input will be removed in a future release.
Expand Down Expand Up @@ -250,7 +250,7 @@ jobs:
with:
runner-size: ${{ inputs.runner-size }}
use-blacksmith-runners: ${{ inputs.use-blacksmith-runners }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
service-name: ${{ inputs.service-name }}
service-emoji: ${{ inputs.service-emoji }}
gradle-module: ${{ inputs.gradle-module }}
Expand All @@ -265,7 +265,7 @@ jobs:
with:
runner-size: ${{ inputs.runner-size }}
use-blacksmith-runners: ${{ inputs.use-blacksmith-runners }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
stage: ${{ inputs.stage }}
service-name: ${{ inputs.service-name }}
service-emoji: ${{ inputs.service-emoji }}
Expand Down Expand Up @@ -319,7 +319,7 @@ jobs:
gradle-module: ${{ inputs.gradle-module }}
java-version: ${{ inputs.java-version }}
openapi-max-workers: ${{ inputs.openapi-max-workers }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
secrets:
GHL_USERNAME: ${{ secrets.GHL_USERNAME }}
GHL_PASSWORD: ${{ secrets.GHL_PASSWORD }}
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/deploy-kotlin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ on:
use-arc-runners:
required: false
type: boolean
default: false
description: "Run on the self-hosted ARC arm64 runners (takes precedence over use-blacksmith-runners). Applies to the test, image build and service profile jobs."
default: true
description: "Run on the self-hosted ARC arm64 runners (default; takes precedence over use-blacksmith-runners). Never used in public repositories: the ARC runner group rejects them, so they keep the Blacksmith/GitHub-hosted runners. Applies to the test, image build and service profile jobs."
# DEPRECATED (no-op): all builds and CI run on arm64. Retained for backwards
# compatibility with callers still passing it; the value is ignored and this
# input will be removed in a future release.
Expand Down Expand Up @@ -238,7 +238,7 @@ jobs:
with:
runner-size: ${{ inputs.runner-size }}
use-blacksmith-runners: ${{ inputs.use-blacksmith-runners }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
service-name: ${{ inputs.service-name }}
service-emoji: ${{ inputs.service-emoji }}
gradle-module: ${{ inputs.gradle-module }}
Expand All @@ -253,7 +253,7 @@ jobs:
with:
runner-size: ${{ inputs.runner-size }}
use-blacksmith-runners: ${{ inputs.use-blacksmith-runners }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
stage: ${{ inputs.stage }}
service-name: ${{ inputs.service-name }}
service-emoji: ${{ inputs.service-emoji }}
Expand Down Expand Up @@ -304,7 +304,7 @@ jobs:
gradle-module: ${{ inputs.gradle-module }}
java-version: ${{ inputs.java-version }}
openapi-max-workers: ${{ inputs.openapi-max-workers }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
secrets:
GHL_USERNAME: ${{ secrets.GHL_USERNAME }}
GHL_PASSWORD: ${{ secrets.GHL_PASSWORD }}
Expand Down
44 changes: 23 additions & 21 deletions .github/workflows/pull-request-kotlin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,8 @@ on:
use-arc-runners:
required: false
type: boolean
default: false
description: "Run on the self-hosted ARC arm64 runners (takes precedence over use-blacksmith-runners). Caches go to S3 and SonarQube is reached in-cluster without Tailscale. Requires the GH_ACTION_ACCESS_KEY_ID and GH_ACTION_SECRET_ACCESS_KEY secrets."
default: true
description: "Run on the self-hosted ARC arm64 runners (default; takes precedence over use-blacksmith-runners). Never used in public repositories: the ARC runner group rejects them, so they keep the Blacksmith/GitHub-hosted runners. SonarQube is reached in-cluster without Tailscale, and caches go to S3 when the GH_ACTION_ACCESS_KEY_ID and GH_ACTION_SECRET_ACCESS_KEY secrets are passed (GitHub cache otherwise). Set to false to opt out."
# DEPRECATED (no-op): all builds and CI run on arm64. Retained for backwards
# compatibility with callers still passing it; the value is ignored and this
# input will be removed in a future release.
Expand Down Expand Up @@ -76,10 +76,10 @@ on:
secrets:
GH_ACTION_ACCESS_KEY_ID:
required: false
description: "AWS access key for the S3 cache bucket. Required with use-arc-runners."
description: "AWS access key for the S3 cache bucket, used on ARC. Without it ARC jobs use the GitHub cache."
GH_ACTION_SECRET_ACCESS_KEY:
required: false
description: "AWS secret key for the S3 cache bucket. Required with use-arc-runners."
description: "AWS secret key for the S3 cache bucket, used on ARC. Without it ARC jobs use the GitHub cache."
TAILSCALE_AUTHKEY:
required: false
description: "Tailscale auth key. When set, the runner joins the tailnet so it can reach the self-hosted SonarQube. Leave unset to keep scanning SonarCloud."
Expand All @@ -94,11 +94,13 @@ on:
description: "SonarQube token"
env:
# Test names with non-ASCII characters become report file names; the ARC runner image defaults to a POSIX locale.
LC_ALL: ${{ inputs.use-arc-runners && 'C.UTF-8' || '' }}
LC_ALL: ${{ (inputs.use-arc-runners && github.event.repository.private) && 'C.UTF-8' || '' }}
# On ARC the caches use S3 when the caller passes the bucket credentials, and the GitHub cache otherwise.
S3_CACHE: ${{ (inputs.use-arc-runners && github.event.repository.private) && secrets.GH_ACTION_ACCESS_KEY_ID != '' }}
jobs:
setup:
name: Setup
runs-on: ${{ inputs.use-arc-runners && 'arc-arm64-2cpu-4gb' || 'linux-arm64' }}
runs-on: ${{ (inputs.use-arc-runners && github.event.repository.private) && 'arc-arm64-2cpu-4gb' || 'linux-arm64' }}
timeout-minutes: 5
outputs:
runner-name: ${{ steps.runner.outputs.runner-name }}
Expand All @@ -113,10 +115,10 @@ jobs:
with:
runner-size: ${{ inputs.runner-size }}
use-blacksmith-runners: ${{ inputs.use-blacksmith-runners }}
use-arc-runners: ${{ inputs.use-arc-runners }}
use-arc-runners: ${{ (inputs.use-arc-runners && github.event.repository.private) }}
check-migration-order:
name: Check Migration Order
runs-on: ${{ inputs.use-arc-runners && 'arc-arm64-2cpu-4gb' || 'linux-arm64' }}
runs-on: ${{ (inputs.use-arc-runners && github.event.repository.private) && 'arc-arm64-2cpu-4gb' || 'linux-arm64' }}
timeout-minutes: 5
steps:
- name: Checkout
Expand Down Expand Up @@ -150,7 +152,7 @@ jobs:
distribution: corretto
java-version: ${{ inputs.java-version }}
- name: Restore Gradle cache
if: ${{ !inputs.use-arc-runners }}
if: ${{ env.S3_CACHE != 'true' }}
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with: &gradle-cache-restore
path: |
Expand All @@ -161,7 +163,7 @@ jobs:
${{ runner.os }}-gradle-${{ github.head_ref }}-
${{ runner.os }}-gradle-
- name: Restore Gradle cache (S3)
if: ${{ inputs.use-arc-runners }}
if: ${{ env.S3_CACHE == 'true' }}
uses: runs-on/cache/restore@88d90644011a3a9957fd141a106f5a94f9794203 # v5.0.7
env: &s3-cache-env
RUNS_ON_S3_BUCKET_CACHE: monta-github-ci-cache
Expand Down Expand Up @@ -208,26 +210,26 @@ jobs:
java-version: ${{ inputs.java-version }}
- name: Restore Gradle cache
id: gradle-cache
if: ${{ !inputs.use-arc-runners }}
if: ${{ env.S3_CACHE != 'true' }}
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with: *gradle-cache-restore
- name: Restore Gradle cache (S3)
id: gradle-cache-s3
if: ${{ inputs.use-arc-runners }}
if: ${{ env.S3_CACHE == 'true' }}
uses: runs-on/cache/restore@88d90644011a3a9957fd141a106f5a94f9794203 # v5.0.7
env: *s3-cache-env
with: *gradle-cache-restore
- name: Restore SonarCloud cache
id: sonar-cache
if: ${{ !inputs.skip-sonar && !inputs.use-arc-runners }}
if: ${{ !inputs.skip-sonar && env.S3_CACHE != 'true' }}
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with: &sonar-cache-restore
path: ~/.sonar/cache
key: ${{ runner.os }}-sonar
restore-keys: ${{ runner.os }}-sonar
- name: Restore SonarCloud cache (S3)
id: sonar-cache-s3
if: ${{ !inputs.skip-sonar && inputs.use-arc-runners }}
if: ${{ !inputs.skip-sonar && env.S3_CACHE == 'true' }}
uses: runs-on/cache/restore@88d90644011a3a9957fd141a106f5a94f9794203 # v5.0.7
env: *s3-cache-env
with: *sonar-cache-restore
Expand Down Expand Up @@ -257,7 +259,7 @@ jobs:
# automatically for repos still on SonarCloud (no TAILSCALE_AUTHKEY passed).
- name: Tailscale
id: tailscale
if: ${{ !inputs.skip-sonar && !inputs.use-arc-runners && env.TAILSCALE_AUTHKEY != '' }}
if: ${{ !inputs.skip-sonar && !(inputs.use-arc-runners && github.event.repository.private) && env.TAILSCALE_AUTHKEY != '' }}
continue-on-error: ${{ inputs.sonar-non-blocking }}
uses: tailscale/github-action@780049a30b6ff5c378a9e7b389d15ece7a204888 # v4.1.3
with:
Expand All @@ -275,7 +277,7 @@ jobs:
# Same reason as the upload step below: an expression here does not survive the step failing. An unreachable
# tailnet then fails the scan itself, which the blocking check below re-raises.
- name: Wait for SonarQube to be reachable over the tailnet
if: ${{ !inputs.skip-sonar && !inputs.use-arc-runners && steps.tailscale.outcome != 'failure' }}
if: ${{ !inputs.skip-sonar && !(inputs.use-arc-runners && github.event.repository.private) && steps.tailscale.outcome != 'failure' }}
continue-on-error: true
shell: bash
env:
Expand Down Expand Up @@ -329,7 +331,7 @@ jobs:
gradle-module: ${{ inputs.gradle-module }}
gradle-tasks: 'sonar'
# ARC runs in the same cluster as SonarQube, whose vpn.internal hostname is only reachable over Tailscale.
gradle-args: ${{ inputs.gradle-args }}${{ inputs.use-arc-runners && ' -Dsonar.host.url=http://sonarqube.sonarqube.svc.cluster.local:9000' || '' }}
gradle-args: ${{ inputs.gradle-args }}${{ (inputs.use-arc-runners && github.event.repository.private) && ' -Dsonar.host.url=http://sonarqube.sonarqube.svc.cluster.local:9000' || '' }}
# Restores what continue-on-error was meant to express, in an `if` where `inputs` does evaluate.
- name: Fail when a blocking Sonar scan failed
if: ${{ steps.sonar.outcome == 'failure' && !inputs.sonar-non-blocking }}
Expand All @@ -356,26 +358,26 @@ jobs:
**/build/test-results/**/*.trx
**/build/test-results/**/*.json
- name: Save Gradle cache
if: ${{ always() && !inputs.use-arc-runners && steps.gradle-cache.outputs.cache-hit != 'true' }}
if: ${{ always() && env.S3_CACHE != 'true' && steps.gradle-cache.outputs.cache-hit != 'true' }}
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with: &gradle-cache-save
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ github.head_ref }}-${{ github.sha }}
- name: Save Gradle cache (S3)
if: ${{ always() && inputs.use-arc-runners && steps.gradle-cache-s3.outputs.cache-hit != 'true' }}
if: ${{ always() && env.S3_CACHE == 'true' && steps.gradle-cache-s3.outputs.cache-hit != 'true' }}
uses: runs-on/cache/save@88d90644011a3a9957fd141a106f5a94f9794203 # v5.0.7
env: *s3-cache-env
with: *gradle-cache-save
- name: Save SonarQube cache
if: ${{ always() && !inputs.skip-sonar && !inputs.use-arc-runners && steps.sonar-cache.outputs.cache-hit != 'true' }}
if: ${{ always() && !inputs.skip-sonar && env.S3_CACHE != 'true' && steps.sonar-cache.outputs.cache-hit != 'true' }}
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with: &sonar-cache-save
path: ~/.sonar/cache
key: ${{ runner.os }}-sonar
- name: Save SonarQube cache (S3)
if: ${{ always() && !inputs.skip-sonar && inputs.use-arc-runners && steps.sonar-cache-s3.outputs.cache-hit != 'true' }}
if: ${{ always() && !inputs.skip-sonar && env.S3_CACHE == 'true' && steps.sonar-cache-s3.outputs.cache-hit != 'true' }}
uses: runs-on/cache/save@88d90644011a3a9957fd141a106f5a94f9794203 # v5.0.7
env: *s3-cache-env
with: *sonar-cache-save
Loading
Loading