Upstream drift #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: Upstream drift | |
| # Three things in this repo mirror decdn/decdn and go stale when upstream moves: | |
| # - roles/decdn_node/vars/main/networks.yml (contract addresses; upstream | |
| # redeploys change every one of them at once) | |
| # - charts/decdn-node/files/monitoring/ (dashboards + alert rules) | |
| # - ansible/molecule/schema/files/schema-keys.txt (the node.toml key inventory) | |
| # This job regenerates each from upstream main and fails when a committed copy | |
| # differs. It is a scheduled early warning, not a PR gate: an upstream change must | |
| # not turn unrelated PRs red. Fix drift by re-running the generator it names. | |
| on: | |
| schedule: | |
| - cron: '17 6 * * 1' # Mondays 06:17 UTC | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: upstream-drift | |
| cancel-in-progress: true | |
| jobs: | |
| drift: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| # Public repo, default branch. The sync scripts read origin/main through git, | |
| # which this checkout provides as a remote-tracking ref. | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: decdn/decdn | |
| ref: main | |
| path: upstream | |
| persist-credentials: false | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.12' | |
| # Each check exits 0 (current), 1 (stale) or anything else (could not run), and | |
| # the two failure kinds are reported differently: a broken generator is not an | |
| # upstream change. Full output goes to the job summary; annotations stay one line. | |
| - name: Compare the mirrors with upstream main | |
| run: | | |
| rc=0 | |
| check() { | |
| local name="$1" out status; shift | |
| out="$("$@" 2>&1)" && status=0 || status=$? | |
| case "$status" in | |
| 0) echo "- ✅ **$name**: current" >> "$GITHUB_STEP_SUMMARY" ;; | |
| 1) rc=1 | |
| echo "::error title=$name is stale::re-run its generator (see the job summary)" | |
| { echo "- ❌ **$name**: stale"; echo '```'; echo "$out"; echo '```'; } >> "$GITHUB_STEP_SUMMARY" ;; | |
| *) rc=1 | |
| echo "::error title=$name check could not run::exit $status (see the job summary)" | |
| { echo "- ⚠️ **$name**: check failed to run (exit $status)"; echo '```'; echo "$out"; echo '```'; } >> "$GITHUB_STEP_SUMMARY" ;; | |
| esac | |
| } | |
| # The schema inventory has no --check of its own: generate, then diff, so a | |
| # crashing generator (exit 2) is not mistaken for "every key removed" (exit 1). | |
| # shellcheck disable=SC2329 # invoked indirectly, through check() | |
| schema_check() { | |
| local fresh | |
| fresh="$(mktemp)" | |
| python3 ansible/molecule/schema/files/gen-schema-keys.py upstream > "$fresh" || return 2 | |
| diff -u ansible/molecule/schema/files/schema-keys.txt "$fresh" | |
| } | |
| echo "### Upstream drift (decdn/decdn@$(git -C upstream rev-parse --short HEAD))" >> "$GITHUB_STEP_SUMMARY" | |
| check "network profiles" python3 scripts/sync-network-profiles.py upstream --check | |
| check "monitoring assets" scripts/sync-monitoring.sh upstream --check | |
| check "config schema keys" schema_check | |
| exit "$rc" |