Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
81 changes: 5 additions & 76 deletions .github/workflows/pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,81 +2,10 @@ name: PR Pipeline
on:
pull_request:
branches: [master]
permissions:
contents: read
jobs:
build-deploy:
runs-on: self-hosted
env:
SCROLL_REGISTRY_PR_NAMESPACE: druid-team-experimental
SCROLL_REGISTRY_ENDPOINT: ${{ secrets.SCROLL_REGISTRY_ENDPOINT }}
SCROLL_REGISTRY_API_KEY: ${{ secrets.SCROLL_REGISTRY_API_KEY }}
SCROLL_REGISTRY_API_SECRET: ${{ secrets.SCROLL_REGISTRY_API_SECRET }}
SCROLL_REGISTRY_BUCKET: ${{ secrets.SCROLL_REGISTRY_BUCKET_STAGING }}
DRUID_CLI_VERSION: v0.1.257
steps:
- uses: actions/checkout@v3
- uses: actions/setup-go@v3
with:
go-version: ">=1.19.3"
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Build and test Scroll UI
working-directory: ui
run: npm ci && npm test && npm run type-check && npm run build
- run: apt update && apt install -y make
- name: Build scroll tree
env:
SCROLL_REGISTRY_HOST: ${{ secrets.SCROLL_REGISTRY_HOST }}
run: |
if [ "${{ github.event.pull_request.head.repo.full_name }}" = "${{ github.repository }}" ]; then
registry_host="${SCROLL_REGISTRY_HOST#http://}"
registry_host="${registry_host#https://}"
registry_host="${registry_host%%/*}"
export DRUID_COLDSTARTER_IMAGE="${registry_host}/${SCROLL_REGISTRY_PR_NAMESPACE}/druid:stable-pr${{ github.event.pull_request.number }}"
fi
make build-tree
- name: Get registry binary
if: github.event.pull_request.head.repo.full_name == github.repository
uses: robinraju/release-downloader@v1.7
with:
repository: "highcard-dev/druid-cli"
tag: ${{ env.DRUID_CLI_VERSION }}
fileName: "druid"
token: ${{ secrets.GO_REPO_TOKEN }}
- name: Install druid
if: github.event.pull_request.head.repo.full_name == github.repository
run: |
chmod +x druid
mv druid /usr/local/bin/druid
- name: Validate all scrolls
run: ./scripts/validate_all_scrolls.sh && bash ./scripts/validate_ui_coverage.sh
- name: Test bounded push parallelism
run: bash ./scripts/tests/push-parallel.test.sh
- name: Login to registry
id: registry_login
continue-on-error: true
if: github.event.pull_request.head.repo.full_name == github.repository
run: druid login --host ${{ secrets.SCROLL_REGISTRY_HOST }} --user '${{ secrets.SCROLL_REGISTRY_USER }}' --password ${{ secrets.SCROLL_REGISTRY_PASSWORD }}
- name: Check scroll changes
id: scroll-changes
run: |
set -euo pipefail
git fetch origin "${{ github.base_ref }}" --depth=1
if git diff --quiet "origin/${{ github.base_ref }}"..HEAD -- scrolls; then
echo "changed=false" >> "$GITHUB_OUTPUT"
echo "No scroll source changes; skipping preview push."
else
echo "changed=true" >> "$GITHUB_OUTPUT"
echo "Scroll source changed; publishing preview tags."
fi
- name: Push experimental PR tags
if: github.event.pull_request.head.repo.full_name == github.repository && steps.scroll-changes.outputs.changed == 'true' && steps.registry_login.outcome == 'success'
env:
SCROLL_REGISTRY_HOST: ${{ secrets.SCROLL_REGISTRY_HOST }}
SCROLL_REGISTRY_NAMESPACE: druid-team-experimental
SCROLL_REGISTRY_RUNTIME_NAMESPACE: druid-team
SCROLL_TAG_SUFFIX: -pr${{ github.event.pull_request.number }}
SCROLL_PUSH_CATEGORIES: "0"
run: bash ./scripts/push.sh
uses: ./.github/workflows/scroll-lifecycle.yml
with:
public: false
49 changes: 7 additions & 42 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,47 +2,12 @@ name: Release Changed Pipeline
on:
workflow_dispatch:
push:
branches:
- master
tags:
- v*
branches: [master]
tags: [v*]
permissions:
contents: read
jobs:
build-deploy:
runs-on: self-hosted
env:
SCROLL_REGISTRY_ENDPOINT: ${{ secrets.SCROLL_REGISTRY_ENDPOINT }}
SCROLL_REGISTRY_API_KEY: ${{ secrets.SCROLL_REGISTRY_API_KEY }}
SCROLL_REGISTRY_API_SECRET: ${{ secrets.SCROLL_REGISTRY_API_SECRET }}
SCROLL_REGISTRY_BUCKET: ${{ secrets.SCROLL_REGISTRY_BUCKET_STAGING }}
SCROLL_REGISTRY_HOST: ${{ secrets.SCROLL_REGISTRY_HOST }}
SCROLL_REGISTRY_USER: ${{ secrets.SCROLL_REGISTRY_USER }}
SCROLL_REGISTRY_PASSWORD: ${{ secrets.SCROLL_REGISTRY_PASSWORD }}
DRUID_CLI_VERSION: v0.1.257
steps:
- uses: actions/checkout@v3
- uses: actions/setup-go@v3
with:
go-version: ">=1.19.3"
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Build and test Scroll UI
working-directory: ui
run: npm ci && npm test && npm run type-check && npm run build
- name: Get registry binary
uses: robinraju/release-downloader@v1.7
with:
repository: "highcard-dev/druid-cli"
tag: ${{ env.DRUID_CLI_VERSION }}
fileName: "druid"
token: ${{ secrets.GO_REPO_TOKEN }}
- run: chmod +x druid
- name: Install druid
run: mv druid /usr/local/bin/druid
- name: druid version
run: druid version
- run: ./scripts/validate_all_scrolls.sh && bash ./scripts/validate_ui_coverage.sh
- name: Push release scrolls
run: bash ./scripts/push.sh
uses: ./.github/workflows/scroll-lifecycle.yml
with:
public: true
130 changes: 130 additions & 0 deletions .github/workflows/scroll-lifecycle.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,130 @@
name: Shared Scroll lifecycle
on:
workflow_call:
inputs:
public:
description: Publish reviewed releases publicly; PR previews remain private.
required: true
type: boolean
permissions:
contents: read

jobs:
verify:
runs-on: self-hosted
outputs:
changed: ${{ steps.changes.outputs.changed }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
fetch-depth: 0
- uses: actions/setup-go@v5
with:
go-version: "1.24.7"
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Build and test Scroll UI
working-directory: ui
run: npm ci && npm test && npm run type-check && npm run build
- name: Build scroll tree
if: github.event_name == 'pull_request'
run: make build-tree
- name: Validate catalog and UI
run: go run ./scripts/validate-release-workflow && go run ./scripts/validate-scrolls.go && bash ./scripts/validate_ui_coverage.sh
- name: Test lifecycle publication
run: go test ./scripts/publish-lifecycle ./scripts/stage-scroll-ui ./scripts/validate-release-workflow -count=1
- name: Test bounded catalog publication
run: bash ./scripts/tests/push-parallel.test.sh
- name: Check release inputs
id: changes
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
set -euo pipefail
if [[ "$EVENT_NAME" == "pull_request" ]] && git diff --quiet "$BASE_SHA"...HEAD -- scrolls ui scripts .github/workflows go.mod go.sum Makefile; then
echo "changed=false" >> "$GITHUB_OUTPUT"
else
echo "changed=true" >> "$GITHUB_OUTPUT"
fi

publish:
needs: verify
if: >-
needs.verify.outputs.changed == 'true' &&
((inputs.public && github.event_name != 'pull_request') ||
(!inputs.public && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository))
# A fresh runner keeps Team credentials out of the untrusted validation job.
runs-on: ubuntu-latest
timeout-minutes: 360
environment: ${{ inputs.public && 'scroll-release' || 'scroll-preview' }}
concurrency:
group: scroll-lifecycle-${{ inputs.public && 'release' || format('pr-{0}', github.event.pull_request.number) }}
cancel-in-progress: false
steps:
- name: Require provisioned lifecycle environment
env:
LIFECYCLE_READY: ${{ vars.SCROLL_LIFECYCLE_READY }}
run: |
if [[ "$LIFECYCLE_READY" != "true" ]]; then
echo "Configure the protected Team lifecycle environment before publication." >&2
exit 1
fi
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- name: Checkout lifecycle-capable CLI
uses: actions/checkout@v4
with:
repository: highcard-dev/druid-cli
# Includes SOURCE_DATE_EPOCH and stable root-layer ordering.
ref: a9f5dd9ec361ee5b268dfa5b5c2a56ef60f350fd
path: .druid-cli
token: ${{ secrets.GO_REPO_TOKEN }}
persist-credentials: false
- uses: actions/setup-go@v5
with:
go-version-file: .druid-cli/go.mod
- name: Build pinned CLI
working-directory: .druid-cli
run: |
mkdir -p "$RUNNER_TEMP/scroll-cli"
go build -o "$RUNNER_TEMP/scroll-cli/druid" ./apps/druid
echo "$RUNNER_TEMP/scroll-cli" >> "$GITHUB_PATH"
- uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Build Scroll UI
working-directory: ui
run: npm ci && npm run build
- name: Build scroll tree
if: github.event_name == 'pull_request'
run: make build-tree
- name: Validate with pinned CLI
run: ./scripts/validate_all_scrolls.sh && bash ./scripts/validate_ui_coverage.sh
- name: Publish through shared lifecycle
env:
SCROLL_PUBLISH_MODE: lifecycle
SCROLL_LIFECYCLE_URL: ${{ vars.SCROLL_LIFECYCLE_URL }}
SCROLL_AUTH_URL: ${{ vars.SCROLL_AUTH_URL }}
SCROLL_LIFECYCLE_OWNER: ${{ vars.SCROLL_LIFECYCLE_OWNER }}
SCROLL_REGISTRY_HOST: ${{ vars.SCROLL_REGISTRY_HOST }}
SCROLL_REGISTRY_NAMESPACE: ${{ vars.SCROLL_LIFECYCLE_OWNER }}
SCROLL_REGISTRY_RUNTIME_NAMESPACE: druid-team
SCROLL_REGISTRY_USER: ${{ secrets.SCROLL_TEAM_REGISTRY_USER }}
SCROLL_REGISTRY_PASSWORD: ${{ secrets.SCROLL_TEAM_REGISTRY_PASSWORD }}
SCROLL_TEAM_EMAIL: ${{ secrets.SCROLL_TEAM_EMAIL }}
SCROLL_TEAM_PASSWORD: ${{ secrets.SCROLL_TEAM_PASSWORD }}
SCROLL_TAG_SUFFIX: -${{ github.event.pull_request.head.sha || github.sha }}
SCROLL_LIFECYCLE_REPOSITORY_SUFFIX: ${{ github.event_name == 'pull_request' && format('-pr{0}', github.event.pull_request.number) || '' }}
SCROLL_LIFECYCLE_PUBLISH: ${{ inputs.public && '1' || '0' }}
SCROLL_LIFECYCLE_REVIEWED: ${{ inputs.public && '1' || '0' }}
run: bash ./scripts/push.sh
Loading
Loading