Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# SPDX-FileCopyrightText: © 2026 OpenCHAMI a Series of LF Projects, LLC
# SPDX-License-Identifier: MIT

# actionlint doesn't recognize GitHub's self-repository `uses: $/...` syntax
# yet. Remove this once it does.
paths:
.github/workflows/0-local-ci.yml:
ignore:
- 'reusable workflow call "\$/'
22 changes: 22 additions & 0 deletions .github/workflows/0-local-ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# SPDX-FileCopyrightText: © 2025 OpenCHAMI a Series of LF Projects, LLC
# SPDX-License-Identifier: MIT

name: 0-local-ci

# Local to this repo: CI for github-actions itself. Not a reusable workflow;
# do not call it from other repos. See "Workflow naming" in the README.

on:
pull_request:
push:
branches: [ main ]

permissions:
contents: read # baseline for checkout

jobs:
lint:
uses: $/.github/workflows/lint-ci.yml
permissions:
contents: read # baseline for checkout
security-events: write # zizmor SARIF upload to GHAS
54 changes: 27 additions & 27 deletions .github/workflows/build-publish-container-goreleaser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,40 +5,40 @@
# with multi-arch builds, build provenance attestation, and PR snapshot
# support.

name: Build and publish container using goreleaser
name: build-publish-container-goreleaser
on:
workflow_call:
inputs:
build_deps:
build-deps:
type: string
required: false
description: 'Space-separated list of apt packages to install before building (e.g. "gcc-aarch64-linux-gnu libc6-dev-arm64-cross").'
cgo_enabled:
cgo-enabled:
type: number
required: false
default: 0
go_version:
go-version:
type: string
required: false
description: 'Go version to use (e.g. "1.26.7", "stable"). Mutually exclusive with go_version_file.'
go_version_file:
description: 'Go version to use (e.g. "1.26.7", "stable"). Mutually exclusive with go-version-file.'
go-version-file:
type: string
required: false
description: 'Path to a go.mod or .go-version file containing the Go version. Mutually exclusive with go_version.'
release_draft:
description: 'Path to a go.mod or .go-version file containing the Go version. Mutually exclusive with go-version.'
release-draft:
type: boolean
required: false
default: false
description: 'Create the release as a draft, overriding release.draft in .goreleaser.yml'
is_pr_build:
is-pr-build:
type: boolean
required: false
default: false
pr_number:
pr-number:
type: number
required: false
default: ${{ github.event.number || 0 }}
registry_subject_name:
registry-subject-name:
type: string
required: true

Expand All @@ -49,7 +49,7 @@ permissions:
attestations: write # write build provenance attestations

jobs:
container_build_publish:
container-build-publish:
runs-on: ubuntu-latest
steps:
- name: Checkout
Expand All @@ -58,18 +58,18 @@ jobs:
fetch-tags: true
fetch-depth: 0
- name: Install build dependencies
if: ${{ inputs.build_deps != '' }}
if: ${{ inputs.build-deps != '' }}
env:
BUILD_DEPS: ${{ inputs.build_deps }}
BUILD_DEPS: ${{ inputs.build-deps }}
run: |
sudo apt update
# shellcheck disable=SC2086 # intentional word splitting
sudo apt install -y --no-install-recommends ${BUILD_DEPS}
- name: Set up Go
uses: actions/setup-go@v6.4.0
with:
go-version: ${{ inputs.go_version || (inputs.go_version_file == '' && 'stable' || '') }}
go-version-file: ${{ inputs.go_version_file || '' }}
go-version: ${{ inputs.go-version || (inputs.go-version-file == '' && 'stable' || '') }}
go-version-file: ${{ inputs.go-version-file || '' }}
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
Expand Down Expand Up @@ -107,17 +107,17 @@ jobs:
echo "BUILD_HOST=$(hostname)"
echo "GO_VERSION=$(go version | awk '{print $3}')"
echo "BUILD_USER=$(whoami)"
echo "CGO_ENABLED=${{ inputs.cgo_enabled }}"
echo "IS_PR_BUILD=${{ inputs.is_pr_build }}"
echo "CGO_ENABLED=${{ inputs.cgo-enabled }}"
echo "IS_PR_BUILD=${{ inputs.is-pr-build }}"
} >> "${GITHUB_ENV}"
- name: Create Tag for PR
if: ${{ inputs.is_pr_build }}
if: ${{ inputs.is-pr-build }}
run: |
git config --global user.name "github-actions[bot]"
git config --global user.email "github-actions[bot]@users.noreply.github.com"
git tag -f -a pr-${{ inputs.pr_number }} -m "PR Release"
git tag -f -a pr-${{ inputs.pr-number }} -m "PR Release"
- name: Generate release notes
if: ${{ !inputs.is_pr_build }}
if: ${{ !inputs.is-pr-build }}
env:
GITHUB_TOKEN: ${{ github.token }}
run: gh api "repos/${GITHUB_REPOSITORY}/releases/generate-notes" -F tag_name="${{ github.ref_name }}" --jq .body > ../notes.md
Expand All @@ -127,11 +127,11 @@ jobs:
GITHUB_TOKEN: ${{ github.token }}
with:
version: '~> 2'
args: release --clean ${{ inputs.is_pr_build && '--skip=announce,validate,archive' || '' }}${{ env.SKIP_CONTAINER_PUBLISH == 'true' && (inputs.is_pr_build && ',publish' || '--skip=publish') || '' }} ${{ inputs.release_draft && '--draft' || '' }} ${{ !inputs.is_pr_build && '--release-notes ../notes.md' || '' }}
args: release --clean ${{ inputs.is-pr-build && '--skip=announce,validate,archive' || '' }}${{ env.SKIP_CONTAINER_PUBLISH == 'true' && (inputs.is-pr-build && ',publish' || '--skip=publish') || '' }} ${{ inputs.release-draft && '--draft' || '' }} ${{ !inputs.is-pr-build && '--release-notes ../notes.md' || '' }}
id: goreleaser
- name: Process goreleaser output
if: env.SKIP_CONTAINER_PUBLISH == 'false'
id: process_goreleaser_output
id: process-goreleaser-output
run: |
node - <<'EOF'
const fs = require('fs');
Expand All @@ -149,14 +149,14 @@ jobs:
echo "digest=$(cat digest.txt)" >> "${GITHUB_OUTPUT}"
fi
- name: Attest Binaries
if: ${{ (env.SKIP_CONTAINER_PUBLISH == 'false') && (inputs.is_pr_build == false) }}
if: ${{ (env.SKIP_CONTAINER_PUBLISH == 'false') && (inputs.is-pr-build == false) }}
uses: actions/attest-build-provenance@v4.1.0
with:
subject-path: dist/**
- name: generate build provenance
if: ${{ (env.SKIP_CONTAINER_PUBLISH == 'false') && (inputs.is_pr_build == false) }}
if: ${{ (env.SKIP_CONTAINER_PUBLISH == 'false') && (inputs.is-pr-build == false) }}
uses: actions/attest-build-provenance@v4.1.0
with:
subject-name: ${{ inputs.registry_subject_name }}
subject-digest: ${{ steps.process_goreleaser_output.outputs.digest }}
subject-name: ${{ inputs.registry-subject-name }}
subject-digest: ${{ steps.process-goreleaser-output.outputs.digest }}
push-to-registry: true
13 changes: 6 additions & 7 deletions .github/workflows/build-rpm-quadlet.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,10 @@
# Copyright © 2026 OpenCHAMI a Series of LF Projects, LLC
# SPDX-FileCopyrightText: © 2026 OpenCHAMI a Series of LF Projects, LLC
# SPDX-License-Identifier: MIT
#
# Reusable workflow: builds the caller repo's podman quadlet RPM and
# uploads it as an unsigned artifact for downstream signing.

name: Build RPM for Podman Quadlet Files
run-name: Create Podman Quadlet RPM for ${{ github.ref }}
name: build-rpm-quadlet
on:
workflow_call:
inputs:
Expand All @@ -18,19 +17,19 @@ permissions:
contents: read # baseline for checkout

jobs:
rpmbuild:
rpm-build:
runs-on: ubuntu-latest
container:
image: rockylinux:9
steps:
- name: Install build dependencies
run: dnf install -y -q git make rpm-build rpmlint tar gzip
run: dnf install -y -q git make rpm-build rpmlint

- name: Mark workspace as a safe git directory
run: git config --global --add safe.directory "$GITHUB_WORKSPACE"

- name: Checkout
uses: actions/checkout@v6.0.2
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-tags: true
fetch-depth: 0
Expand All @@ -39,7 +38,7 @@ jobs:
run: make rpm-build

- name: Upload RPM
uses: actions/upload-artifact@v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ inputs.artifact-name-unsigned-rpms }}
path: '**/*.rpm'
20 changes: 0 additions & 20 deletions .github/workflows/ci.yml

This file was deleted.

68 changes: 0 additions & 68 deletions .github/workflows/coverage-go.yml

This file was deleted.

7 changes: 3 additions & 4 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# SPDX-FileCopyrightText: 2025 OpenCHAMI a Series of LF Projects, LLC
# SPDX-FileCopyrightText: © 2025 OpenCHAMI a Series of LF Projects, LLC
# SPDX-License-Identifier: MIT

name: dependency-review
Expand Down Expand Up @@ -41,10 +41,9 @@ permissions:

jobs:
dependency-review:
name: dependency-review
runs-on: ubuntu-latest
runs-on: ubuntu-slim
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
Expand Down
11 changes: 5 additions & 6 deletions .github/workflows/docker-build-release.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
# SPDX-FileCopyrightText: 2025 OpenCHAMI a Series of LF Projects, LLC
# SPDX-License-Identifier: MIT

name: Build image
run-name: Dockeer image build for ${{ github.event.push.ref }}
name: docker-build-release

on:
workflow_call:
Expand Down Expand Up @@ -128,7 +127,7 @@ jobs:
registry: ghcr.io

- name: Build and push image
id: docker_build
id: docker-build
uses: docker/build-push-action@v7.2.0
with:
push: true
Expand All @@ -153,14 +152,14 @@ jobs:
${{ env.CC != '' && format('"CC={0}"', env.CC) || '' }}

publish-release:
runs-on: ubuntu-latest
runs-on: ubuntu-slim
needs: build-push-images
if: github.event_name == 'push' && contains(github.ref, 'refs/tags/')
permissions:
contents: write # create GitHub release
steps:
- name: Parse semver string
id: semver_parser
id: semver-parser
uses: booxmedialtd/ws-action-parse-semver@v1.4.7
with:
input_string: ${{ github.event.ref }}
Expand All @@ -170,5 +169,5 @@ jobs:
# by default this will use the tag push tag as the tag and name
# if we want to trigger tagging from the workflow, "tag" and "commit"
# need to be set to create a new one
prerelease: ${{ steps.semver_parser.outputs.prerelease != '' }}
prerelease: ${{ steps.semver-parser.outputs.prerelease != '' }}
skipIfReleaseExists: true
Loading
Loading