From 4b553b4204cfb78820102074aa4aac39a0146158 Mon Sep 17 00:00:00 2001 From: Pawel Kosiec Date: Wed, 7 Oct 2026 15:06:20 +0200 Subject: [PATCH] ci: move workflows to IaC-managed runner groups IT turns off the legacy runner groups on Oct 15. - PR workflows (ci, bundle-size, pr-metadata) run on the untrusted group. - Main-only workflows (prepare-release*, docs-deploy, close-inactive-prs) run on the public-repos group. - devhub-build takes the runner group and label as inputs. The nightly run uses the public-repos default. The PR run passes the untrusted group. Co-authored-by: Isaac Signed-off-by: Pawel Kosiec --- .github/workflows/bundle-size.yml | 4 +-- .github/workflows/ci.yml | 35 ++++++++++--------- .github/workflows/close-inactive-prs.yml | 4 +-- .github/workflows/devhub-build.yml | 12 +++++-- .github/workflows/docs-deploy.yml | 8 ++--- .github/workflows/pr-metadata.yml | 8 ++--- .../workflows/prepare-release-lakebase.yml | 4 +-- .github/workflows/prepare-release.yml | 8 ++--- 8 files changed, 47 insertions(+), 36 deletions(-) diff --git a/.github/workflows/bundle-size.yml b/.github/workflows/bundle-size.yml index e785aa6b4..c960348a8 100644 --- a/.github/workflows/bundle-size.yml +++ b/.github/workflows/bundle-size.yml @@ -34,8 +34,8 @@ jobs: pull-requests: write id-token: write # setup-jfrog-npm exchanges an OIDC token for registry auth runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - name: Setup JFrog npm diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2eb25ba49..2b5fc786f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,8 +16,8 @@ permissions: jobs: detect-changes: runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb name: Detect Changes outputs: @@ -38,8 +38,8 @@ jobs: lint_and_typecheck: name: Lint & Type Check runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -116,8 +116,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.appkit == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -138,8 +138,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.appkit == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -169,8 +169,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.appkit == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb permissions: contents: read id-token: write @@ -194,8 +194,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.appkit == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb permissions: contents: read id-token: write @@ -219,8 +219,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.appkit == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb # Job-level permissions REPLACE (not merge with) the top-level set, so all # three must be listed: pull-requests: write for the sticky comment step, # and id-token: write which setup-jfrog-npm needs for its OIDC token. @@ -364,8 +364,8 @@ jobs: needs: detect-changes if: needs.detect-changes.outputs.docs == 'true' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -409,3 +409,6 @@ jobs: with: appkit-remote: ${{ github.event.pull_request.head.repo.clone_url || format('https://github.com/{0}.git', github.repository) }} appkit-ref: ${{ github.head_ref || github.ref_name }} + # PR refs can't match the public-repos allow-list (main only). + runner-group: databricks-ghec-untrusted-runner-group + runner-label: linux-ubuntu-latest-untrusted-2core-8gb diff --git a/.github/workflows/close-inactive-prs.yml b/.github/workflows/close-inactive-prs.yml index 03b226107..ae9faf0d6 100644 --- a/.github/workflows/close-inactive-prs.yml +++ b/.github/workflows/close-inactive-prs.yml @@ -19,8 +19,8 @@ jobs: stale: name: Mark and Close Inactive PRs runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb steps: - uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0 with: diff --git a/.github/workflows/devhub-build.yml b/.github/workflows/devhub-build.yml index 256317ddb..8aee9fb5e 100644 --- a/.github/workflows/devhub-build.yml +++ b/.github/workflows/devhub-build.yml @@ -14,6 +14,14 @@ on: description: "AppKit branch/ref to sync docs from" type: string default: "main" + runner-group: + description: "Runner group for the build job" + type: string + default: "databricks-ghec-public-repos-runner-group-small" + runner-label: + description: "Runner label for the build job" + type: string + default: "linux-ubuntu-latest-public-2core-8gb" permissions: contents: read @@ -23,8 +31,8 @@ jobs: build: name: Build DevHub runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: ${{ inputs.runner-group }} + labels: ${{ inputs.runner-label }} steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 diff --git a/.github/workflows/docs-deploy.yml b/.github/workflows/docs-deploy.yml index ffb012705..3773c6436 100644 --- a/.github/workflows/docs-deploy.yml +++ b/.github/workflows/docs-deploy.yml @@ -19,8 +19,8 @@ concurrency: jobs: build: runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb name: Build Docs steps: @@ -43,8 +43,8 @@ jobs: deploy: runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb name: Deploy to GitHub Pages needs: build diff --git a/.github/workflows/pr-metadata.yml b/.github/workflows/pr-metadata.yml index 1a4b8e2d1..eb5330a0b 100644 --- a/.github/workflows/pr-metadata.yml +++ b/.github/workflows/pr-metadata.yml @@ -17,8 +17,8 @@ concurrency: jobs: check-title: runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb name: Conventional Commit Title steps: @@ -43,8 +43,8 @@ jobs: detect-breaking: name: Detect Breaking Commits runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-untrusted-runner-group + labels: linux-ubuntu-latest-untrusted-2core-8gb steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: diff --git a/.github/workflows/prepare-release-lakebase.yml b/.github/workflows/prepare-release-lakebase.yml index acba746af..345437139 100644 --- a/.github/workflows/prepare-release-lakebase.yml +++ b/.github/workflows/prepare-release-lakebase.yml @@ -18,8 +18,8 @@ permissions: jobs: prepare: runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb steps: - name: Checkout diff --git a/.github/workflows/prepare-release.yml b/.github/workflows/prepare-release.yml index 6b533fc84..200b4626b 100644 --- a/.github/workflows/prepare-release.yml +++ b/.github/workflows/prepare-release.yml @@ -18,8 +18,8 @@ jobs: outputs: version: ${{ steps.version.outputs.version }} runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb steps: - name: Checkout @@ -128,8 +128,8 @@ jobs: needs: [prepare] if: needs.prepare.outputs.version != '' runs-on: - group: databricks-protected-runner-group - labels: linux-ubuntu-latest + group: databricks-ghec-public-repos-runner-group-small + labels: linux-ubuntu-latest-public-2core-8gb steps: - name: Checkout