forked from aztec-labs-eng/aztec-node
-
Notifications
You must be signed in to change notification settings - Fork 0
110 lines (102 loc) · 5.62 KB
/
Copy pathci3.yml
File metadata and controls
110 lines (102 loc) · 5.62 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
# CI for Aztec. At a high-level, runs ./bootstrap.sh ci in root. See root README.md for more details.
# Only for internal devs. For external devs, see ci3-external.yml.
#
# CAREFUL! We use "exec" a lot to ensure signal propagation to the child process, to allow proper ec2 cleanup.
name: CI3
on:
workflow_dispatch:
push:
branches:
- main
pull_request:
types: [opened, synchronize, reopened, ready_for_review, labeled]
concurrency:
group: ci3-${{ github.ref_name }}
# Never cancel main-branch runs: each push to main is a full run that produces the
# per-commit benchmark series, so a newer push must queue behind it, not kill it.
cancel-in-progress: ${{ github.ref_name != 'main' }}
jobs:
# The main CI job for Aztec. Fast runs gate pull requests; every push to main runs
# full CI, which also produces the per-commit benchmark series (bench/main).
#
# This orchestrates AWS EC2 spot instances then remotely runs ./bootstrap.sh
# The ci-full label enables heavier tests. For other labels, see ci3.sh.
#
# Standard PR Push to main
# | |
# | 1x AMD64 EC2 Spot | | 1x AMD64 EC2 Spot (full) |
# (fast) | + dedicated bench box |
#
# If you suspect a flaky test, look for people recently reporting similar things.
# Otherwise, spend time ensuring it is not your PR. Spend some time attempting to fix it.
# Try not to just increase timeouts. Post either about your fix or your efforts where
# engineers can broadly see it.
ci:
runs-on: ubuntu-latest
# exclusive with ci3-external.yml: never run on forks
# (github.event.pull_request.head.repo.fork resolves to nil if not a pull request)
if: github.event.pull_request.head.repo.fork != true && (github.event.pull_request.draft == false || contains(github.event.pull_request.labels.*.name, 'ci-draft'))
# No environment, and so no publish credentials: releases run in release.yml.
permissions:
id-token: write # required for OIDC assume-role with AWS
contents: read # checkout/fetch with the default github.token
statuses: write # post_github_status posts per-job commit statuses (ci/x-fast etc.) with github.token
steps:
# Do NOT bump actions/checkout to v6 here. v6 ("persist creds to a separate file", #2286)
# stores the persisted github.token in a temp credentials file pulled in via includeIf, which
# `git config --unset-all http....extraheader` cannot clear. Our runner-side pushes
# (ci3.sh release-pr tag) rely on swapping that header for a bot-PAT remote, so under v6
# they push as github-actions[bot] (contents: read) and 403. v5.0.1 is still node24 but
# keeps the credential as a removable local extraheader.
- name: Checkout
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
with:
# The commit to checkout. We want our actual commit, and not the result of merging the PR to the target.
ref: ${{ github.event.pull_request.head.sha || github.sha }}
# Fetch all of the PR's commits.
fetch-depth: ${{ github.event.pull_request.commits || 1 }}
# Persisted for authenticated reads; pushes swap in a bot-PAT remote at each push site.
persist-credentials: true
- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ vars.AWS_OIDC_ROLE_ARN }}
aws-region: us-east-2
role-session-name: ci3-${{ github.run_id }}
role-duration-seconds: 7200 # 2h – covers max AWS_SHUTDOWN_TIME (90 min ARM) + 30 min buffer
- name: Determine CI Mode
env:
PR_BASE_REF: ${{ github.event.pull_request.base.ref }}
GITHUB_REF_NAME: ${{ github.ref_name }}
GITHUB_TOKEN: ${{ github.token }}
PR_LABELS_JSON: ${{ toJson(github.event.pull_request.labels.*.name) }}
run: |
# Parse labels from JSON env var to avoid shell injection via label names
mapfile -t LABELS < <(echo "$PR_LABELS_JSON" | jq -r '.[]')
./.github/ci3_labels_to_env.sh "${LABELS[@]}"
- name: Run
env:
GITHUB_TOKEN: ${{ github.token }}
SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}
PR_BASE_REF: ${{ github.event.pull_request.base.ref }}
PR_HEAD_REF: ${{ github.event.pull_request.head.ref }}
PR_NUMBER: ${{ github.event.pull_request.number }}
GITHUB_REF_NAME: ${{ github.ref_name }}
GITHUB_ACTOR: ${{ github.actor }}
# Groups this workflow's CI dashboard entries under the GitHub run id (stable across re-runs).
RUN_ID: ${{ github.run_id }}
CI3_INSTANCE_PROFILE_NAME: ${{ vars.CI3_INSTANCE_PROFILE_NAME }}
CI3_SECURITY_GROUP_ID: ${{ vars.CI3_SECURITY_GROUP_ID }}
AWS_OIDC_ROLE_ARN: ${{ vars.AWS_OIDC_ROLE_ARN }}
# NOTE: $CI_MODE is set in the Determine CI Mode step.
run: ./.github/ci3.sh $CI_MODE
- name: Post-Actions
run: ./.github/ci3_success.sh
# Uses ci3/upload_benchmarks rather than github-action-benchmark: the action full-clones
# the multi-GB data repo per upload; the script does a shallow sparse clone instead.
- name: Upload benchmarks
# TODO(A-1764): Setup benchmarks.
if: false && env.BENCH_UPLOAD == '1'
env: &ci_benchmark_env
COMMIT_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: &ci_benchmark_run ./ci3/upload_benchmarks "Aztec Benchmarks" "bench/${BENCH_BRANCH:-}" ./bench-out/bench.json "$COMMIT_SHA"