Repository navigation
feat(workflows): default every shared workflow to ARC; public repos use GitHub's runner - #367
Merged
Merged
Conversation
…se GitHub's runner deploy-generic(-v2), deploy-python, pull-request-bun, pull-request-react and component-test-python gain use-arc-runners (default true), and component-build's default flips to true. ARC is only used in private repositories. runner-size-converter returns ubuntu-24.04-arm for public repositories, so they no longer fall back to Blacksmith, and component-build skips the Blacksmith builder there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
JesperTerkelsen
marked this pull request as ready for review
October 1, 2026 07:28
JesperTerkelsen
requested review from
tobias0106
and removed request for
a team
October 1, 2026 07:28
gh05tdog
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What?
Makes the self-hosted ARC runners the default for every shared workflow, not just the Kotlin ones, and moves public repos to GitHub's standard runner.
deploy-generic,deploy-generic-v2,deploy-pythonuse-arc-runnersinput (defaulttrue), passed down tocomponent-build/component-test-pythonpull-request-bun,pull-request-react,component-test-pythonuse-arc-runnersinput (defaulttrue). Setup runs onarc-arm64-2cpu-4gbon ARC; the main job's runner comes from the convertercomponent-buildfalsetotrue, so its direct callers move too. The Blacksmith builder job is never selected in a public reporunner-size-converterubuntu-24.04-armwhenevergithub.event.repository.privateisfalse, whatever the inputs. ARC is only returned for private reposEvery read is
(inputs.use-arc-runners && github.event.repository.private), as in the Kotlin workflows (#360). The ARC runner group also disallows public repositories (https://github.com/monta-app/kube-manifests/pull/7727).Who moves
From an org-wide scan of all 307 non-archived repos:
deploy-generic(-v2), 11 callingcomponent-builddirectly, plus service-grid'spull-request-reactjob.ubuntu-24.04-arm. Their PR workflows used to fall back to Blacksmith because ARC is private-only.Not affected:
@f0866ab), and internal-ocpi-tooling's PR workflow (@b65d4f5).runs-on: blacksmith-*written directly in the repo: service-agentic, data-slm-pipeline, service-ocpp, server, service-control, service-identity-ui. These get per-repo PRs.Test plan
After merge, each affected repo's next deploy runs on ARC. Rather than an opt-in PR and a revert per repo, the follow-up per-repo PRs pass the
GH_ACTION_*S3 secrets, which the ARC image build uses for its cache-mount storage. Merging each one triggers that repo's first ARC deploy. They go out one team at a time, and each team's results are checked before the next.Risks
docker build. Most of these images runnpm/pnpm/pipinside the Dockerfile. The runner's CodeArtifact proxy (npm via the job-started hook) doesn't reach inside the build, so cold builds hit the public registries from the shared NAT IP, and npm/PyPI could rate-limit. The Dockerfile cache mounts (feat(build): keep Dockerfile cache mounts between ARC image builds #359) keep warm builds off the registries.use-arc-runners: falsein a repo.🤖 Generated with Claude Code