ci: validate main after merge and run the runner-controller tests #245
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!245
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "ci/validate-main-and-python-test"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Two CI gaps, both from the code-quality tooling review.
1. Nothing validated
main(#55)CI was
pull_request-only. A squash or rebase merge produces a commit that nopull_requestrunever saw, so breakage existing only on the merged result went uncaught — and a base branch quietly
failing its own CI blocks every later PR once branch protection requires the check. That is exactly
what happened in
bitborg-reconcile-trigger: itsmainsat with aREADME.mdthat failedformat:check, and the symptom surfaced as an unrelated Renovate PR failing.All five repos share this gap; this is the bitborg-infra half.
Scoped to
main, so it does not double-run CI: pushes to PR branches still only firepull_request.Safe with the change-detection step as written. On a
push,pull_request.base.shais empty, so"Detect changed areas" takes its existing documented fail-safe path —
could not resolve the PR base diff — running ALL checks (fail-safe)→__ALL__→ every check runs. That is precisely the desiredbehaviour for a
mainvalidation run, so no rework of that step is needed.2. The runner-controller tests were never run
ansible/roles/runner-controller/files/test_controller_logic.pyhas existed since #195 and nothingever executed it. This is the orphan-detection logic that decides which ephemeral VMs get
deleted, and the file's own comments record two production incidents.
Verified green before wiring it in —
9/9 checks passed. It is dependency-free by design (plainpython3, no pytest, no ansible import), so it needs nothing added to the baked runner image, and itis path-gated on
ansible/like the neighbouring steps.Not included, and why
The review's headline Phase 0 item was "add
--offlineto the ansible-lint step". It is alreadydone —
ansible/.ansible-lint:17setsoffline: true, and CI runscd ansible && ansible-lint,which loads that config. There is no Galaxy egress to remove. The review had read only the command
line, not the resolved config. Likewise its fourth item: the
yamlrule is inskip_listdeliberately ("Prettier owns YAML formatting; ansible-lint stays semantic-only"), not a severity
that might fail to gate. Both corrections are recorded in the research doc.
Refs #55, #57