Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
76cfd0e
test(python): synchronize interactive exec TTY readiness (#4076)
matthewgrossman Oct 1, 2026
c70a2fe
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
d20a711
chore(deps): refresh rpm lockfiles [SECURITY]
red-hat-konflux[bot] Oct 2, 2026
79f8537
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
8719fc9
fix(sandbox): restrict provider file mode (#4093)
drew Oct 2, 2026
f006d07
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
6a8389e
Merge remote-tracking branch 'upstream/main'
sutaakar Oct 2, 2026
6048bed
fix(ci): retry Nix shell and app dependency preparation (#4066)
matthewgrossman Oct 2, 2026
6e865df
feat(snap): ship the standalone prover binary in the snap (#3717)
olivercalder Oct 2, 2026
bc15ead
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
5d6b3b8
fix(kubernetes): serialize lifecycle cleanup with sandbox restart (#4…
matthewgrossman Oct 2, 2026
4ceb678
chore(deps): refresh rpm lockfiles (#71)
red-hat-konflux[bot] Oct 2, 2026
513e3d9
chore(deps): update registry.access.redhat.com/ubi9/nodejs-24-minimal…
red-hat-konflux[bot] Oct 2, 2026
769e15a
CARRY: fix(konflux): build gateway with vendored-z3 feature
EmilienM Oct 2, 2026
2ea0abc
Merge pull request #72 from opendatahub-io/fix-konflux-gateway-vendor…
EmilienM Oct 2, 2026
88afd36
fix(deps): upgrade russh to address Dependabot alert 40 (#4116)
alangou Oct 2, 2026
36819f4
fix(cli): stop uploads when Git filtering fails or selects no files (…
alangou Oct 2, 2026
f7273e4
fix(providers): restore supervisor-backed GCP metadata discovery (#3973)
feloy Oct 2, 2026
a48920a
feat(helm): add sandbox UID and GID values (#3947)
ericcurtin Oct 2, 2026
aa83209
fix(konflux): remove unused gateway Z3 prefetch
Oct 2, 2026
8e9136b
fix(vm): codesign macOS driver-vm with hypervisor entitlement in CI (…
benoitf Oct 2, 2026
9d6e4b3
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
6da17e8
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
046fd2a
ci: pin CI images by digest and add native architecture smoke checks …
alangou Oct 2, 2026
24220bd
Merge pull request #74 from opendatahub-io/autofix/rhai-4526
EmilienM Oct 2, 2026
ec49209
fix(providers): stabilize provider environment revisions (#4122)
drew Oct 2, 2026
7145daf
CARRY: fix(konflux): install Git in the CLI runtime
mprpic Oct 2, 2026
fec36a0
Merge pull request #68 from opendatahub-io/konflux/mintmaker/main/loc…
EmilienM Oct 2, 2026
7fceee0
Merge pull request #75 from opendatahub-io/fix/RHAI-4864-cli-runtime-git
EmilienM Oct 2, 2026
6420ac2
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
6205f37
Merge remote-tracking branch 'upstream/main'
moulalis Oct 2, 2026
57dc6be
Merge remote-tracking branch 'upstream/main'
moulalis Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .agents/skills/test-release-canary/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ The Release Canary (`.github/workflows/release-canary.yml`) smoke-tests the arti
| `macos` | `macos-latest-xlarge` | Installs the dev Homebrew artifacts, reaches the VM gateway, and creates, executes in, and deletes a sandbox. |
| `ubuntu-deb` | `ubuntu-latest` | Installs the dev Debian package, reaches the Docker gateway, and creates, executes in, and deletes a sandbox. |
| `fedora` | `fedora:latest` container | Installs the dev RPM packages, reaches the Podman gateway, and creates, executes in, and deletes a sandbox. |
| `ubuntu-snap-system-docker` | `ubuntu-latest` | Uses `install.sh` to install the snap from `latest/edge`, reuses system Docker, reaches the Docker gateway, and creates, executes in, and deletes a sandbox, and verifies that the Docker snap is not installed. |
| `ubuntu-snap-system-docker` | `ubuntu-latest` | Uses `install.sh` to install the snap from `latest/edge`, reuses system Docker, verifies the packaged prover version and a local policy boundary check, reaches the Docker gateway, creates, executes in, and deletes a sandbox, and verifies that the Docker snap is not installed. |
| `ubuntu-snap-docker-preflight` | `ubuntu-latest` | Verifies that `install.sh` rejects the OpenShell Snap path when Docker is absent or supplied by the Docker snap, without installing OpenShell. |
| `kubernetes` | `ubuntu-latest` + kind | Installs the dev Helm chart, reaches the in-cluster gateway, and creates, executes in, and deletes a sandbox using the published runtime images. |

Expand Down Expand Up @@ -144,6 +144,7 @@ Loopback registration auto-derives the gateway name to `openshell` if `--name` i
| Sandbox create or exec fails | Published sandbox and supervisor artifacts are missing, incompatible, or cannot establish the protected runtime channel. | Gateway logs plus Docker, Podman, VM, Snap, or Kubernetes runtime diagnostics for the job. |
| `macos`/`ubuntu-deb`/`fedora` job fails on `openshell status` | Local gateway service did not start (systemd/brew/podman). Often a driver issue. | Service logs in the job log; `OPENSHELL_COMPUTE_DRIVER` env in the "Ensure …" step. |
| `ubuntu-snap-system-docker` fails during `install.sh` | System Docker was unavailable, the edge revision or automatic interfaces were unavailable, or the gateway did not become reachable. | Failure diagnostics dump system Docker, snap service/connection/change state, gateway and snapd journals, snap logs, and port 17670 listeners. |
| `ubuntu-snap-system-docker` fails during the prover checks | The prover artifact is missing or packaged for the wrong architecture, `openshell.prover` is not exposed or confined to read the test policies, or its solver linkage is not runnable. | The `Verify Snap installation` and `Check a policy boundary with the Snap prover` steps, plus `snap info openshell` and `snap connections openshell`. |
| `ubuntu-snap-docker-preflight` unexpectedly succeeds | The installer no longer fails before installing the OpenShell snap when Docker is absent or supplied by the Docker snap. | Inspect `install.log`, `docker-snap.log`, `snap list`, and snapd changes. |
| `kubernetes` job fails on `helm install --wait` | Chart did not deploy in 5 min — usually image pull failure or readiness probe failing. | "Diagnostics on failure" step dumps `helm status`, manifest, pod describe, pod logs. |
| `kubernetes` job fails on `kubectl wait` | Gateway pod stuck `CrashLoopBackOff` or `ImagePullBackOff`. | Diagnostics dump; check `:dev` image existence at `ghcr.io/nvidia/openshell/gateway`. |
Expand Down
7 changes: 7 additions & 0 deletions .agents/skills/watch-github-actions/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,13 @@ gh run list --json databaseId,status,headBranch,url --jq '.[] | {id: .databaseId

## View Job Logs

`setup-nix` retries development-shell preparation once when `prepare-shell`
is enabled. Inspect both attempts in the job log; `setup-rust` assumes the
shell has already been prepared. Cargo, lint, and test commands are not retried.
Direct Nix builds and app dependency preparation also retry once; apps run
once after preparation succeeds. Skipped dependent E2E suites indicate blocked
coverage.

For `Trivy Changes`, inspect the `Resolve PR baseline` step for the base and head
SHAs. PR runs compare the tested merge commit with its
first parent; change detection and scans must use the same pair. On reruns, do
Expand Down
13 changes: 13 additions & 0 deletions .github/actions/build-rust-binary/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,10 @@ inputs:
description: Additional flags passed to cargo build
required: false
default: ""
entitlements-file:
description: Path to an entitlements plist for macOS ad-hoc codesigning (skipped when empty or not on macOS)
required: false
default: ""
runs:
using: composite
steps:
Expand Down Expand Up @@ -66,6 +70,15 @@ runs:
# Confirm Syft can decode the embedded cargo-auditable metadata.
SYFT_CHECK_FOR_APP_UPDATE=false syft "file:${binary}" -o cyclonedx-json | grep 'pkg:cargo/' > /dev/null

- name: Codesign with entitlements
if: inputs.entitlements-file != '' && runner.os == 'macOS'
shell: bash
env:
INPUTS_ENTITLEMENTS: ${{ inputs.entitlements-file }}
INPUTS_TRIPLE: ${{ inputs.triple }}
INPUTS_BINARY: ${{ inputs.binary }}
run: /usr/bin/codesign --entitlements "${INPUTS_ENTITLEMENTS}" --force -s - "target/${INPUTS_TRIPLE}/release/${INPUTS_BINARY}"

- name: Upload ${{ inputs.binary }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
Expand Down
3 changes: 3 additions & 0 deletions .github/actions/check-protobuf-compatibility/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,7 @@ runs:
env:
CHECK_REF: ${{ inputs.ref }}
run: |
# Retry dependency preparation, then run the compatibility check once.
nix build --no-link --no-write-lock-file .#check-protobuf-compatibility ||
nix build --no-link --no-write-lock-file .#check-protobuf-compatibility
nix run .#check-protobuf-compatibility --no-write-lock-file -- "$CHECK_REF"
24 changes: 23 additions & 1 deletion .github/actions/setup-nix/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,23 @@
# SPDX-License-Identifier: Apache-2.0

name: Setup Nix
description: Install Nix and configure the OpenShell Cachix cache
description: Install Nix, configure Cachix, and optionally prepare the development shell

inputs:
cachix-auth-token:
description: Token used to write build outputs to Cachix
required: false
default: ""

prepare-shell:
description: Prepare the development shell, retrying once on failure
required: false
default: "false"
shell-installable:
description: Development shell to prepare
required: false
default: "."

runs:
using: composite
steps:
Expand All @@ -22,3 +31,16 @@ runs:
name: openshell
authToken: ${{ inputs.cachix-auth-token }}
skipPush: ${{ inputs.cachix-auth-token == '' }}

- name: Prepare Nix development shell
if: inputs.prepare-shell == 'true'
shell: bash
env:
NIX_SHELL_INSTALLABLE: ${{ inputs.shell-installable }}
run: |
# HTTP 416 is not retried by Nix; a fresh invocation restarts downloads.
if nix develop "$NIX_SHELL_INSTALLABLE" -c true; then
exit 0
fi
echo "::warning::Nix shell preparation failed; retrying once."
nix develop "$NIX_SHELL_INSTALLABLE" -c true
6 changes: 1 addition & 5 deletions .github/actions/setup-rust/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# SPDX-License-Identifier: Apache-2.0

name: Setup Rust
description: Configure the Nix development shell and Rust caches
description: Configure Rust caches after setup-nix has prepared the development shell

inputs:
cache-key:
Expand All @@ -23,10 +23,6 @@ runs:
shell_drv=$(nix eval --raw --impure .#devShells --apply 'shells: shells.${builtins.currentSystem}.default.drvPath')
echo "hash=$(nix hash file --type sha256 --base16 "$shell_drv")" >> "$GITHUB_OUTPUT"

- name: Realize Nix development shell
shell: bash
run: nix develop -c true

- name: Cache Rust target and registry
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
Expand Down
31 changes: 18 additions & 13 deletions .github/workflows/branch-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@

jobs:
pr_metadata:
if: false # CARRY: disable upstream-only job (requires runners unavailable in downstream fork)

Check failure on line 26 in .github/workflows/branch-checks.yml

View workflow job for this annotation

GitHub Actions / Actionlint (informational)

constant expression "false" in condition. remove the if: section

Check failure on line 26 in .github/workflows/branch-checks.yml

View workflow job for this annotation

GitHub Actions / Actionlint (informational)

constant expression "false" in condition. remove the if: section
name: Resolve PR metadata
runs-on: ubuntu-latest
permissions:
Expand Down Expand Up @@ -65,7 +65,7 @@
runs-on: linux-amd64-cpu8
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -90,7 +90,7 @@
runs-on: linux-amd64-cpu8
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -115,14 +115,11 @@
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
github_access_token: ${{ secrets.GITHUB_TOKEN }}

- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
- uses: ./.github/actions/setup-nix
with:
name: openshell
authToken: ${{ secrets.CACHIX_AUTH_TOKEN }}
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
prepare-shell: "true"
shell-installable: .#devShells.x86_64-linux.default

- name: Check dependencies
run: cargo deny check licenses bans sources
Expand All @@ -138,6 +135,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- name: Format
Expand All @@ -159,6 +157,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- name: Verify Cargo lockfiles
Expand Down Expand Up @@ -186,6 +185,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand Down Expand Up @@ -222,6 +222,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand Down Expand Up @@ -258,6 +259,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand Down Expand Up @@ -307,6 +309,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand All @@ -331,6 +334,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand All @@ -357,6 +361,7 @@

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- uses: ./.github/actions/setup-rust
Expand All @@ -382,7 +387,7 @@
runs-on: ${{ matrix.runner }}
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down Expand Up @@ -418,7 +423,7 @@
runs-on: linux-amd64-cpu8
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -438,7 +443,7 @@
runs-on: linux-amd64-cpu8
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -458,7 +463,7 @@
runs-on: linux-amd64-cpu8
timeout-minutes: 30
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/branch-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -144,6 +144,7 @@ jobs:
ref: ${{ github.sha }}
- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
- uses: ./.github/actions/build-rust-binary
with:
Expand Down Expand Up @@ -184,6 +185,7 @@ jobs:
ref: ${{ github.sha }}
- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
- uses: ./.github/actions/build-rust-binary
with:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/build-binaries.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,7 @@ jobs:
ref: ${{ inputs.checkout-ref || github.sha }}
- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
- uses: ./.github/actions/build-rust-binary
with:
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/build-vm-driver.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ jobs:
- arch: aarch64
triple: aarch64-apple-darwin
runner: macos-15-xlarge
entitlements-file: crates/openshell-driver-vm/entitlements.plist
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
defaults:
Expand All @@ -52,6 +53,7 @@ jobs:

- uses: ./.github/actions/setup-nix
with:
prepare-shell: "true"
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}

- name: Download openshell-sandbox
Expand Down Expand Up @@ -81,7 +83,9 @@ jobs:
path: vm-init

- name: Build VM runtime
run: nix build .#vm-runtime
run: |
# HTTP 416 is not retried by Nix; restart the build once on failure.
nix build .#vm-runtime || nix build .#vm-runtime

- name: Assemble compressed VM runtime
run: |
Expand All @@ -106,3 +110,4 @@ jobs:
triple: ${{ matrix.triple }}
cargo-version: ${{ inputs['cargo-version'] }}
supervisor-image-tag: ${{ inputs['supervisor-image-tag'] }}
entitlements-file: ${{ matrix.entitlements-file }}
2 changes: 1 addition & 1 deletion .github/workflows/cargo-deny.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
name: Cargo Deny
runs-on: linux-amd64-cpu8
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/deb-package.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
runs-on: ${{ matrix.runner }}
timeout-minutes: 20
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/e2e-docker-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ jobs:
matrix:
include: ${{ fromJSON(inputs.suite-matrix) }}
container:
image: ghcr.io/nvidia/openshell/ci:37072ee81cd7b294c714bfa5ecc829b6927b3d70
image: ghcr.io/nvidia/openshell/ci:37072ee81cd7b294c714bfa5ecc829b6927b3d70@sha256:ffa96b8009de6e28bbf157060440c3abb312d3bcda444e9571c539c8c6115615
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/e2e-gpu-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ jobs:
runner: wsl-amd64-gpu-rtxpro6000-latest-1
experimental: true
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/helm-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@

jobs:
pr_metadata:
if: false # CARRY: disable upstream-only job (requires runners unavailable in downstream fork)

Check failure on line 27 in .github/workflows/helm-lint.yml

View workflow job for this annotation

GitHub Actions / Actionlint (informational)

constant expression "false" in condition. remove the if: section

Check failure on line 27 in .github/workflows/helm-lint.yml

View workflow job for this annotation

GitHub Actions / Actionlint (informational)

constant expression "false" in condition. remove the if: section
name: Resolve PR metadata
runs-on: ubuntu-latest
permissions:
Expand Down Expand Up @@ -82,7 +82,7 @@
if: needs.pr_metadata.outputs.should_run == 'true' && needs.helm_changes.outputs.should_run == 'true'
runs-on: linux-amd64-cpu8
container:
image: ghcr.io/nvidia/openshell/ci:latest
image: ghcr.io/nvidia/openshell/ci:9cb72baa2e61a1b5f12407e6e82da7fdba0aa722@sha256:67a9a0c32cb99825e6d3e9d9eec45d67149ea1ff7c11a1b1e1b3480d2d3df684
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/integration-runner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -85,4 +85,7 @@ jobs:
ENVIRONMENT: ${{ matrix.environment }}
INSTALLER: ${{ matrix.installer }}
TESTSUITE: ${{ matrix.testsuite }}
run: nix run .#tmachine -- test "${ENVIRONMENT}" "${INSTALLER}" "${TESTSUITE}"
run: |
# Retry dependency preparation, then execute the test suite once.
nix build --no-link .#tmachine || nix build --no-link .#tmachine
nix run .#tmachine -- test "${ENVIRONMENT}" "${INSTALLER}" "${TESTSUITE}"
Loading
Loading