Skip to content

feat(nuxt-cloudflare): E2E off the pull request, mode: e2e, audit warns on PRs - #175

Merged
loganrenz merged 4 commits into
mainfrom
fast-ci-e2e-callable
Sep 29, 2026
Merged

loganrenz merged 4 commits into
mainfrom
fast-ci-e2e-callable

Conversation

@loganrenz

@loganrenz loganrenz commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

What

Fast CI + ship program, lane E2E-CALLABLE. Logan (2026-09-29): E2E skips on PRs, runs after each merge (newest wins) plus nightly, one org switch; pnpm audit warns on PRs and blocks on main + nightly.

  1. vars.CI_E2E_IN_CI == 'false' skips E2E plan, E2E and E2E quarantine on every event; Required reads the skip as success (a lane that runs anyway still fails it). Unset or any other value changes nothing, so this merge alone changes no behaviour. Build also stops packing the prebuilt app for E2E, and the folded-gate condition follows the switch.
  2. mode: e2e (default ci), for a caller workflow named E2E: Build -> E2E plan -> E2E (+ quarantine) and Required as the verdict; every other lane, the Caller lint and the audit are skipped, the var is ignored, and the plan never path-skips (a newer push cancels the run, so no diff can prove a skip). Required is red for an unknown mode, run-e2e not true, journey-smoke-url set, or any E2E lane failing/cancelled/skipped without the plan's say-so. README section "E2E off the pull request" carries the caller YAML (push main, nightly cron, workflow_dispatch, concurrency: {group: e2e-<repo>, cancel-in-progress: true}) and the listener YAML.
  3. Audit: pull_request / pull_request_target turn the failure into ::warning:: (advisory list kept, step passes); push, schedule, workflow_dispatch still fail.
  4. red-main: red-main-self.yml and the listener template also act on schedule runs on the default branch (and list workflows: ["CI", "E2E"]).

Verify (Opus)

One blocker, fixed in d05c9c9: with CI_E2E_IN_CI=false a PR minted a Required proof although E2E never ran (the proof key omits the variable, so a rollback or repo override would let the push reuse it and go green without E2E). The mint condition reads the raw run-e2e again; test_e2e_mode.py has a test (mutation-checked). Also: README notes case-insensitivity, proof-key comment corrected.

Judgement call to review

The brief says the var skips E2E "on any event". I did not let it override e2e-full-paths (acre-oracle style protected-path escalation) or expected-candidate-sha (release validation): both are explicit promises to run browsers, and the gates behind them fail closed if the lane is silently skipped. Unset/other behaviour is unchanged. If Logan wants the var to win over them too, it is one term in the E2E_ON expression.

Checks run (nice, targeted; no ci-local)

Check Result Time
actionlint -no-color -oneline .github/workflows/*.yml pass <2s
python3 scripts/lint_callables.py 11 files, 0 findings 0.2s
every scripts/test_*.py (30 modules, incl. new test_e2e_mode.py, extended test_dependency_audit.py 44 cases, test_red_main_listener.py) all rc=0 (one fix: test_package_auth_cleanup.py expectation, rerun green) 2m01s sweep
ruff check scripts/test_e2e_mode.py pass (pre-existing unused imports in two older test files untouched) <1s
mutation checks of test_e2e_mode.py (var honoured in e2e mode, path-skip in e2e mode, mode in proof key, gate accepting run-e2e false, dropped escalation exception) all 5 caught -

test_e2e_mode.py is wired into ci.yml after the fast-path contract tests.

Canary (cloudflarestat-us, PR #32 pinned to this branch's SHA, unmerged, closed after)

cloudflarestat-us, PR https://github.com/narduk-enterprises/cloudflarestat-us/pull/32 (unmerged, closed after), ci.yml and a canary-only e2e.yml pinned to head d05c9c9. Repo-level variable CI_E2E_IN_CI=false (no org variable).

Rollout

Exact per-app e2e.yml and listener change are in the README section above. After merge, v2 is advanced by hand per the README. No org variable is set by this PR; the orchestrator flips CI_E2E_IN_CI when the per-app E2E callers are in.

🤖 Generated with Claude Code

loganrenz and others added 4 commits September 29, 2026 18:01
…s on PRs

- vars.CI_E2E_IN_CI == 'false' skips e2e-plan, e2e and e2e-quarantine on any
  event; Required treats the skip as success. Unset or other values change nothing.
- mode: e2e input for a caller workflow named E2E (push to main, nightly,
  workflow_dispatch): build -> e2e-plan -> e2e plus a Required verdict, ignores the var.
- pnpm audit warns on pull_request/pull_request_target, fails elsewhere.
- red-main-self and the listener template also act on schedule runs.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… Required proof

The proof key does not include the variable, so a proof minted while it was
false could be reused by a push after the variable was removed, turning main
green without E2E. The mint condition reads the raw run-e2e input again.
Also: README case-insensitivity note, accurate proof-key comment.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@loganrenz
loganrenz merged commit e29724f into main Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant