From 8e9c7a3dffa1b4f7932a2fb3a99f0fddd5eab12a Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Fri, 28 Aug 2026 14:10:50 +0200 Subject: [PATCH 1/2] fix(ci): make functional-tests.yml callable as a reusable workflow EduIDE-deployment's deploy-e2e.yml calls this workflow with an `environment` input and KEYCLOAK_USER / KEYCLOAK_PWD secrets, but the workflow declared only push and pull_request triggers. A call into a workflow with no workflow_call trigger fails while the run is being parsed, so every Deploy e2e run went red with no jobs listed at all. Add the workflow_call trigger with the input and secrets the caller actually sends, and derive LANDINGPAGE_URL from the input when called, falling back to vars.LANDINGPAGE_URL for this repository's own runs. In EduIDE-deployment the environment name under environments/ is the landing page hostname for every environment, so https:// is the URL the Playwright suite expects. Checkout has to name the repository as well: inside a called workflow the github context describes the caller, so a bare checkout would clone EduIDE-deployment and there would be no test suite on disk. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_019qeiQRFu8xAMRYWPdZewjG --- .github/workflows/functional-tests.yml | 39 +++++++++++++++++++++++++- README.md | 19 +++++++++++++ 2 files changed, 57 insertions(+), 1 deletion(-) diff --git a/.github/workflows/functional-tests.yml b/.github/workflows/functional-tests.yml index 6692a21..eab2a42 100644 --- a/.github/workflows/functional-tests.yml +++ b/.github/workflows/functional-tests.yml @@ -4,6 +4,31 @@ on: branches: [main, master] pull_request: branches: [main, master] + # EduIDE-deployment calls this after it has deployed an environment, so the + # suite runs against the rollout that just went green rather than against + # whatever the repository variable happens to point at. + workflow_call: + inputs: + environment: + type: string + required: true + description: >- + Landing page hostname to test, e.g. + e2e.eduide.student.k8s.aet.cit.tum.de. In EduIDE-deployment the + environment name and the landing page hostname are the same string, + so the caller passes its environment name straight through. + secrets: + KEYCLOAK_USER: + required: true + KEYCLOAK_PWD: + required: true + # A called workflow can only read secrets it declares. The functional + # project never touches Artemis, so these stay optional and simply stay + # empty for a caller that does not have them. + ARTEMIS_USER: + required: false + ARTEMIS_PWD: + required: false jobs: test: timeout-minutes: 60 @@ -11,14 +36,26 @@ jobs: env: KEYCLOAK_USER: ${{ secrets.KEYCLOAK_USER }} KEYCLOAK_PWD: ${{ secrets.KEYCLOAK_PWD }} - LANDINGPAGE_URL: ${{ vars.LANDINGPAGE_URL }} + # Called: test what the caller just deployed. Triggered directly: there is + # no input, so keep using the repository variable as before. + LANDINGPAGE_URL: ${{ inputs.environment && format('https://{0}', inputs.environment) || vars.LANDINGPAGE_URL }} ARTEMIS_URL: ${{ vars.ARTEMIS_URL }} ARTEMIS_USER: ${{ secrets.ARTEMIS_USER }} ARTEMIS_PWD: ${{ secrets.ARTEMIS_PWD }} NUM_INSTANCES: 10 steps: + # In a called workflow the github context belongs to the CALLER, so a bare + # checkout would clone the calling repository and leave no test suite to + # run. job.workflow_repository / job.workflow_sha point at the repo and + # commit this workflow file itself came from, which is what we want there. + # inputs.environment is only set when we are called, so direct push and + # pull_request runs keep checking out github.repository at github.sha + # exactly as before. - uses: actions/checkout@v4 + with: + repository: ${{ inputs.environment && job.workflow_repository || github.repository }} + ref: ${{ inputs.environment && job.workflow_sha || github.sha }} - uses: actions/setup-node@v4 with: node-version: lts/* diff --git a/README.md b/README.md index 1aa8cb1..9194ab1 100644 --- a/README.md +++ b/README.md @@ -140,6 +140,25 @@ This repository provides E2E integration tests for the [Theia Cloud IDE](https:/ | artemis | Runs the **integration** test with Artemis, either local or deployed depending on the URLs set in the env file. | [![Playwright Tests](https://github.com/ls1intum/theia-scale-tests/actions/workflows/artemis-integration-tests.yml/badge.svg)](https://github.com/ls1intum/theia-scale-tests/actions/workflows/artemis-integration-tests.yml) | | \*-setup | These are setup projects and not meant to be run on its own. Dependencies are already set. | +### Running the functional suite from another repository + +`.github/workflows/functional-tests.yml` is also a reusable workflow, so a deployment pipeline can run the suite against the environment it has just rolled out. `EduIDE/EduIDE-deployment` uses it that way: + +```yaml +e2e: + needs: deploy + uses: EduIDE/theia-scale-tests/.github/workflows/functional-tests.yml@main + with: + environment: e2e.eduide.student.k8s.aet.cit.tum.de + secrets: + KEYCLOAK_USER: ${{ secrets.E2E_KEYCLOAK_USER }} + KEYCLOAK_PWD: ${{ secrets.E2E_KEYCLOAK_PWD }} +``` + +`environment` is the landing page hostname; the job turns it into `LANDINGPAGE_URL=https://`. In EduIDE-deployment the environment name under `environments/` and the landing page hostname are the same string, so the caller passes its environment name through unchanged. Pushes and pull requests on this repository send no input and keep reading `LANDINGPAGE_URL` from the repository variable. + +`ARTEMIS_USER` and `ARTEMIS_PWD` are declared as optional secrets. The `functional` project never touches Artemis, so a caller that does not have them can leave them out. + ## Development - Single User Playwright Tests are run using a Test Account for Keycloak, to change the Test User, change the environment variables in GitHub Secrets \ From 1bef94c2b5dcac45cac5d4abf8e6377624c8fc85 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Fri, 28 Aug 2026 15:13:48 +0200 Subject: [PATCH 2/2] fix(ci): run on a runner that exists, and make the Artemis URL an input `runs-on: [self-hosted, e2e-test]` matched no registered runner, so every run since 2026-08-27 15:13 sat queued - nine of them, including plain pushes to main on workflows nobody had touched. The repository has no self-hosted runners of its own, and the only ones in the organisation are two ARC scale sets on the student cluster (`arc-buildkit-*-stud-amd64`). An ARC scale-set runner is addressed by its scale set name and never carries the `self-hosted` label, so that label combination cannot ever match. `ubuntu-latest` is enough: the environments under test are reachable from the public internet, which Let's Encrypt proves every time it validates their certificates over HTTP-01, so the suite needs no cluster access. `ARTEMIS_URL` is now an optional `artemis_url` input, because different environments front different Artemis instances and the caller is the only thing that knows which. It falls back to the repository variable when the workflow is triggered directly, so existing behaviour is unchanged. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_019qeiQRFu8xAMRYWPdZewjG --- .github/workflows/functional-tests.yml | 24 ++++++++++++++++++++++-- README.md | 14 ++++++++++++++ 2 files changed, 36 insertions(+), 2 deletions(-) diff --git a/.github/workflows/functional-tests.yml b/.github/workflows/functional-tests.yml index eab2a42..6c50833 100644 --- a/.github/workflows/functional-tests.yml +++ b/.github/workflows/functional-tests.yml @@ -17,6 +17,15 @@ on: e2e.eduide.student.k8s.aet.cit.tum.de. In EduIDE-deployment the environment name and the landing page hostname are the same string, so the caller passes its environment name straight through. + artemis_url: + type: string + required: false + default: '' + description: >- + Artemis instance to integrate against, as a full URL, for example + https://artemis.tum.de. Environments front different Artemis + instances, so it belongs to the caller. Empty falls back to the + ARTEMIS_URL repository variable. secrets: KEYCLOAK_USER: required: true @@ -32,14 +41,25 @@ on: jobs: test: timeout-minutes: 60 - runs-on: [self-hosted, e2e-test] + # Was `[self-hosted, e2e-test]`, which no registered runner answers to. The + # only self-hosted runners in this org are two ARC scale sets on the student + # cluster (`arc-buildkit-*-stud-amd64`), and an ARC scale-set runner is + # addressed by its scale set name, never by `self-hosted`. Every run since + # 2026-08-27 15:13 sat queued for that reason. + # + # The environments under test are reachable from the public internet - Let's + # Encrypt validates their certificates over HTTP-01 - so a hosted runner + # reaches them and needs no cluster access. + runs-on: ubuntu-latest env: KEYCLOAK_USER: ${{ secrets.KEYCLOAK_USER }} KEYCLOAK_PWD: ${{ secrets.KEYCLOAK_PWD }} # Called: test what the caller just deployed. Triggered directly: there is # no input, so keep using the repository variable as before. LANDINGPAGE_URL: ${{ inputs.environment && format('https://{0}', inputs.environment) || vars.LANDINGPAGE_URL }} - ARTEMIS_URL: ${{ vars.ARTEMIS_URL }} + # Configurable, so a caller can point the suite at its own Artemis. + # Falls back to the repository variable when triggered directly. + ARTEMIS_URL: ${{ inputs.artemis_url || vars.ARTEMIS_URL }} ARTEMIS_USER: ${{ secrets.ARTEMIS_USER }} ARTEMIS_PWD: ${{ secrets.ARTEMIS_PWD }} NUM_INSTANCES: 10 diff --git a/README.md b/README.md index 9194ab1..538b903 100644 --- a/README.md +++ b/README.md @@ -150,11 +150,25 @@ e2e: uses: EduIDE/theia-scale-tests/.github/workflows/functional-tests.yml@main with: environment: e2e.eduide.student.k8s.aet.cit.tum.de + artemis_url: https://artemis.tum.de secrets: KEYCLOAK_USER: ${{ secrets.E2E_KEYCLOAK_USER }} KEYCLOAK_PWD: ${{ secrets.E2E_KEYCLOAK_PWD }} ``` +| Input | Required | | +|---|---|---| +| `environment` | yes | Landing page hostname. Becomes `LANDINGPAGE_URL` as `https://` | +| `artemis_url` | no | Artemis instance to integrate against, as a full URL. Environments front different Artemis instances, so it belongs to the caller. Empty falls back to the `ARTEMIS_URL` repository variable | + +`KEYCLOAK_USER` and `KEYCLOAK_PWD` are required; `ARTEMIS_USER` and `ARTEMIS_PWD` +are optional and only needed by suites that reach Artemis. + +The job runs on `ubuntu-latest`. It used to ask for `[self-hosted, e2e-test]`, +which no registered runner answers to, so every run queued indefinitely. The +environments under test are reachable from the public internet, so a hosted +runner is enough. + `environment` is the landing page hostname; the job turns it into `LANDINGPAGE_URL=https://`. In EduIDE-deployment the environment name under `environments/` and the landing page hostname are the same string, so the caller passes its environment name through unchanged. Pushes and pull requests on this repository send no input and keep reading `LANDINGPAGE_URL` from the repository variable. `ARTEMIS_USER` and `ARTEMIS_PWD` are declared as optional secrets. The `functional` project never touches Artemis, so a caller that does not have them can leave them out.