Skip to content

ci: build on GitHub runners, dual-arch, via EduIDE/.github@v1 - #502

Closed
Mtze wants to merge 89 commits into
eclipse-theia:mainfrom
EduIDE:feature/git-setup-simplifications
Closed

Mtze wants to merge 89 commits into
eclipse-theia:mainfrom
EduIDE:feature/git-setup-simplifications

Conversation

@Mtze

@Mtze Mtze commented Aug 25, 2026

Copy link
Copy Markdown

Repoints the three image builds at the org-owned reusable workflow added in EduIDE/.github#1, and collapses three near-identical 18-line jobs into one matrix (107 → 62 lines).

Why

  • Drops the cross-org dependency. All three jobs currently point at ls1intum/.github@feature/split-build-workflow-modes — an unmerged PR branch in another organisation. If it is deleted, every build here breaks at once.
  • Both architectures on every event, including PRs. build-arm64: ${{ github.event_name != 'pull_request' }} meant PR images were amd64-only, so a PR build could not be scheduled onto an arm64 node.
  • fail-fast: false, so one component failing no longer cancels the other two.

Removed

verify-cache.yml (228 lines) and certs/squid-proxy-ca.crt. That workflow only probed cluster-internal services:

apt-cacher-ng.apt-cacher-ng.svc.cluster.local
registry-mirror.registry-mirror.svc.cluster.local
registry-mirror-ghcr.registry-mirror.svc.cluster.local
squid.squid.svc.cluster.local
verdaccio.verdaccio.svc.cluster.local

All .svc.cluster.local, therefore unreachable from GitHub-hosted runners. The CA certificate existed solely to talk to the Squid proxy.

What to watch on this PR

This is the first real test of the runner migration. The thing to check in the CI run:

  1. All three components publish a manifest with both linux/amd64 and linux/arm64 (the workflow asserts this and fails if not).
  2. Build duration versus the previous ARC runs.
  3. No disk exhaustion. These are small Java images so free-disk-space is off; the large Theia images in EduIDE are the real test and come next.

Note on @v1

v1 currently points at the head of EduIDE/.github#1, not a merged commit, so that this PR can be validated before that one merges. I will re-point v1 at the merge commit once EduIDE/.github#1 lands. Nothing else consumes v1 yet.

🤖 Generated with Claude Code

https://claude.ai/code/session_019qeiQRFu8xAMRYWPdZewjG

CodeByNikolas and others added 28 commits February 6, 2026 12:31
* feat: add support for versioned releases

Adds automatic Docker image tagging for GitHub releases using a
consistent approach across all three images.

Changes:
- Added 'release' event trigger to workflow
- Added determine-tag job to extract release tag for all images
- All jobs now depend on determine-tag and use release_tag consistently
- operator & service: use type=raw with release_tag from determine-tag
- landing-page: pass release_tag via tags input to reusable workflow

This unified approach prepares for future migration of all jobs to
the reusable workflow, ensuring consistent tag handling.

When a release is published (e.g., v1.0.0), Docker images will be tagged:
- ghcr.io/ls1intum/theia/landing-page:v1.0.0
- ghcr.io/ls1intum/theia/operator:v1.0.0
- ghcr.io/ls1intum/theia/service:v1.0.0

Existing behavior (PR and push builds) remains unchanged.

* Add PR and branch tagging support to determine-tag job

* Remove duplicate tags, use release_tag consistently across all jobs

* Simplify tagging: use docker metadata-action type=ref patterns, remove custom determine-tag job

* Restore original whitespace formatting

* Apply suggestion from @Mtze

---------

Co-authored-by: Matthias Linhuber <github@linhuber.org>
#67)

* Refactor sentry tracing helpers, make sure spans are ordered in the correct hierarchy and add tracing across microservices

* Update remaining usages of Sentry without going through the centralised helper

* Add more in-depth tracing for session url updating

* Remove debug flags

* add sentry.properties symlink in operator to make it pick up the properties file

* Decrease session polling timeout massively

* Fix trace continuation attributes

* Remove unnecessary overloads as Transactions extend Spans

* Remove redundant error tracking as it's handled centrally

* Pass correct span to lazy session handler

* Properly instrument data bridge injection

* Fix span propagation out of thread-local scops

* Fix async trace continuation

* Final cleanups and noise reductions

* Fix typo

* Address coderabbit feedback

* Integrate code rabbit suggestions

* Implement suggestions

* Fix tracing

* Finalize sentry config flow

* Remove fallback to mode for sentry env

* add console log for sentry init

* Add sentry trace propagation

* hardcode sentry dsn
#69)

* Refactor sentry tracing helpers, make sure spans are ordered in the correct hierarchy and add tracing across microservices

* Update remaining usages of Sentry without going through the centralised helper

* Add more in-depth tracing for session url updating

* Remove debug flags

* add sentry.properties symlink in operator to make it pick up the properties file

* Decrease session polling timeout massively

* Fix trace continuation attributes

* Remove unnecessary overloads as Transactions extend Spans

* Remove redundant error tracking as it's handled centrally

* Pass correct span to lazy session handler

* Properly instrument data bridge injection

* Fix span propagation out of thread-local scops

* Fix async trace continuation

* Final cleanups and noise reductions

* Fix typo

* Address coderabbit feedback

* Integrate code rabbit suggestions

* Implement suggestions

* Fix tracing

* Finalize sentry config flow

* Remove fallback to mode for sentry env

* add console log for sentry init

* Add sentry trace propagation

* hardcode sentry dsn

* Implement concurrent handling of session events to increase throughpu

* Synchronize ingress manager rule modifications

* Centralize session status checks and early return if not eligible for handling in all session handlers

* Improve and simplify concurrency handling

* Shutdown executor properly to address code rabbit suggestions

* Implement coderabbit suggestions

* empty

* Simplification

* Continue async trace properly

* address invalid interruption handling concerns

* add comment

* Treat absence of workspace as an ephemeral session

* Capture exceptions for session launch failures

* small tracing fix

* empty

* Address coderabbit issues

* Address all feedback

* Use lambda based switch expressions for code quality
* First draft

* Syntax fix

* Fix import issues

* Temporary hardcode cache

* Fix permissions issue

* Make gradle folder accessable to theia user

* Change the way how caching is configured

* switch default cache url to use tls

* Update default params for operator

* Make the caching more general, not specific to gradle

* Remove imports

* cleanup

* remove default values

* Switch to template environment variables

* remove .idea

* fix conflict

* fix infalid mount path, without tls

* Cache renames to support build cache and dependency cache

* add additional argument validation
* Make sentry configurable

* Some more documentation

* add proper argument forwarding

* Document expectations more clearly
* docs: Add AGENTS.md with build commands and code style guidelines

* apply feedback
* Migrate to gateway api

* Add redirect rule and request header modification in IngressManager

- Introduced a new method to create redirect rules for specified paths.
- Added functionality to set the X-Forwarded-Uri header in request filters.
- Updated existing rule creation logic to incorporate these new features.

* Fixes

* Address coderabbit comment

* Make sentry configurable

* Some more documentation

* Refactor ingres manager to gateway api control flows

* Add jitter for route edit conflicts

* Update documentation related to envoy specific behaviours and ingress setup

* add proper argument forwarding

* Migrate to typed gateway api resources
Automatically assigns the PR author as assignee when a PR is opened,
reopened, or marked ready for review.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
* Add permissions block to build workflow

* Migrate to dynamic registry configuration

* change runner type

* Update readme
* Fix arm runner set

* proper arm runner

---------

Co-authored-by: Nikolas Hack <33756465+CodeByNikolas@users.noreply.github.com>
* Implement Scaling API

* Add comment

* empty

* change runner type

* Refactor appdefinition admin resources to token auth

* change runner type

* Migrate to dynamic registry configuration

* Add permissions block to build workflow

* Revert "Add permissions block to build workflow"

This reverts commit 297393a.

* Revert "Migrate to dynamic registry configuration"

This reverts commit e64b6bc.

* Revert "change runner type"

This reverts commit 8e454a9.

* Revert "change runner type"

This reverts commit 304933b.

* Add permissions block to build workflow

* Migrate to dynamic registry configuration

* change runner type

* Update readme

* Use ubuntu for arm builds as well

* Switch to custom auth token header to avoid conflict with quarkus bearer auth interception

* Remove licenses

* Change validation of app defintion scaling to respect undefined max values
* Fixes config.js caching and SPA routing

* remove unnecessary expires header
* feat: remove landing-page node workspace and sources

* feat: remove landing-page dockerfile and build artifacts

* feat: remove landing-page build and deploy workflow

* feat: remove landing-page terraform configurations

* docs: update documentation to reflect landing-page removal
* migrate shared http route to route per session

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Bumps the npm_and_yarn group with 2 updates in the /node directory: [axios](https://github.com/axios/axios) and [ajv](https://github.com/ajv-validator/ajv).
Bumps the npm_and_yarn group with 6 updates in the /node/monitor directory:

| Package | From | To |
| --- | --- | --- |
| [ajv](https://github.com/ajv-validator/ajv) | `6.12.6` | `6.14.0` |
| [qs](https://github.com/ljharb/qs) | `6.13.0` | `6.14.2` |
| [serialize-javascript](https://github.com/yahoo/serialize-javascript) | `6.0.2` | `removed` |
| [underscore](https://github.com/jashkenas/underscore) | `1.13.7` | `1.13.8` |
| [webpack](https://github.com/webpack/webpack) | `5.102.1` | `5.105.4` |
| [jws](https://github.com/brianloveswords/node-jws) | `3.2.2` | `3.2.3` |
| [qs](https://github.com/ljharb/qs) | `6.13.0` | `6.14.2` |

Bumps the npm_and_yarn group with 10 updates in the /theia directory:

| Package | From | To |
| --- | --- | --- |
| [axios](https://github.com/axios/axios) | `1.12.2` | `1.13.6` |
| [ajv](https://github.com/ajv-validator/ajv) | `6.12.6` | `6.14.0` |
| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.17.23` |
| [webpack](https://github.com/webpack/webpack) | `5.102.1` | `5.105.4` |
| @isaacs/brace-expansion | `5.0.0` | `5.0.1` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.22.0` | `1.27.1` |
| [basic-ftp](https://github.com/patrickjuchli/basic-ftp) | `5.0.5` | `5.2.0` |
| [diff](https://github.com/kpdecker/jsdiff) | `5.2.0` | `5.2.2` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.3.0` | `3.3.3` |
| [multer](https://github.com/expressjs/multer) | `2.0.2` | `2.1.1` |



Updates `axios` from 1.12.2 to 1.13.5
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.12.2...v1.13.5)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `axios` from 1.12.2 to 1.13.5
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.12.2...v1.13.5)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `qs` from 6.13.0 to 6.14.2
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.2)

Removes `serialize-javascript`

Updates `underscore` from 1.13.7 to 1.13.8
- [Commits](jashkenas/underscore@1.13.7...1.13.8)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `jws` from 3.2.2 to 3.2.3
- [Release notes](https://github.com/brianloveswords/node-jws/releases)
- [Changelog](https://github.com/auth0/node-jws/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jws@v3.2.2...v3.2.3)

Updates `qs` from 6.13.0 to 6.14.2
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.2)

Updates `underscore` from 1.13.7 to 1.13.8
- [Commits](jashkenas/underscore@1.13.7...1.13.8)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `qs` from 6.13.0 to 6.14.2
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.2)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

Updates `axios` from 1.12.2 to 1.13.6
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.12.2...v1.13.5)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `lodash` from 4.17.21 to 4.17.23
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.17.23)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `@isaacs/brace-expansion` from 5.0.0 to 5.0.1

Updates `@modelcontextprotocol/sdk` from 1.22.0 to 1.27.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.22.0...v1.27.1)

Updates `ajv` from 6.12.6 to 6.14.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

Updates `axios` from 1.12.2 to 1.13.6
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.12.2...v1.13.5)

Updates `basic-ftp` from 5.0.5 to 5.2.0
- [Release notes](https://github.com/patrickjuchli/basic-ftp/releases)
- [Changelog](https://github.com/patrickjuchli/basic-ftp/blob/master/CHANGELOG.md)
- [Commits](patrickjuchli/basic-ftp@v5.0.5...v5.2.0)

Updates `diff` from 5.2.0 to 5.2.2
- [Changelog](https://github.com/kpdecker/jsdiff/blob/master/release-notes.md)
- [Commits](kpdecker/jsdiff@v5.2.0...v5.2.2)

Updates `dompurify` from 3.3.0 to 3.3.3
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.3.0...3.3.3)

Updates `lodash` from 4.17.21 to 4.17.23
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.21...4.17.23)

Updates `multer` from 2.0.2 to 2.1.1
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v2.0.2...v2.1.1)

Updates `webpack` from 5.102.1 to 5.105.4
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack@v5.102.1...v5.105.4)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.13.5
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: axios
  dependency-version: 1.13.5
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.14.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: serialize-javascript
  dependency-version: 
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: underscore
  dependency-version: 1.13.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: jws
  dependency-version: 3.2.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.14.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: underscore
  dependency-version: 1.13.8
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: qs
  dependency-version: 6.14.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: direct:development
  dependency-group: npm_and_yarn
- dependency-name: axios
  dependency-version: 1.13.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.17.23
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@isaacs/brace-expansion"
  dependency-version: 5.0.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.27.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: axios
  dependency-version: 1.13.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: basic-ftp
  dependency-version: 5.2.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: diff
  dependency-version: 5.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: dompurify
  dependency-version: 3.3.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: lodash
  dependency-version: 4.17.23
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: multer
  dependency-version: 2.1.1
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: webpack
  dependency-version: 5.105.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the npm_and_yarn group with 1 update in the /node directory: [flatted](https://github.com/WebReflection/flatted).
Bumps the npm_and_yarn group with 2 updates in the /node/monitor directory: [flatted](https://github.com/WebReflection/flatted) and [undici](https://github.com/nodejs/undici).
Bumps the npm_and_yarn group with 2 updates in the /theia directory: [flatted](https://github.com/WebReflection/flatted) and [socket.io-parser](https://github.com/socketio/socket.io).


Updates `flatted` from 3.3.3 to 3.4.2
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

Updates `flatted` from 3.3.3 to 3.4.2
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

Updates `undici` from 7.16.0 to 7.24.4
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.16.0...v7.24.4)

Updates `flatted` from 3.3.3 to 3.4.2
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

Updates `socket.io-parser` from 4.2.4 to 4.2.6
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.4...socket.io-parser@4.2.6)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.24.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: socket.io-parser
  dependency-version: 4.2.6
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ion-mode (#91)

* ci: add execution-mode dropdown and reusable workflow routing

* Run determine-tag on merge-path runner selection

* Remove determine-tag job and rely on reusable workflow tags

* Use reusable workflow default mirror resolution

* Expose github registry cache toggle in cloud build workflow

* Always enable github-runners registry cache in cloud workflow

* Scope cloud build concurrency by execution mode

* Use explicit registry cache-from/to in cloud workflow calls

* Align CI style, add conversion-webhook build target, improve Docker layer caching

* Add nightly schedule at 02:00 UTC, disable_layer_cache input, and no-cache-on-schedule wiring

* Fix GHCR image and cache refs to lowercase in cloud build workflow

* fix: fix malformed Maven command chain in conversion-webhook Dockerfile

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* ci: guard image_tag input for non-dispatch events in build workflow

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* refactor: use reusable workflow for all images

- Switch all 3 images to use reusable workflow from ls1intum/.github
- Add docker-secrets input for operator and service (SENTRY_AUTH_TOKEN)
- Add concurrency control to cancel in-progress runs
- Keep GitHub-hosted runners and multi-arch builds (defaults)

* fix: pass docker-secrets via secrets block instead of inputs

GitHub Actions doesn't allow secrets in reusable workflow inputs.
Pass SENTRY_AUTH_TOKEN via the secrets block instead.

* chore: remove accidentally committed Eclipse IDE files

These files are IDE-specific and should not be tracked in git.

* feat: add commit SHA suffix to image tags

- Add determine-tag job to compute base_tag and sha_tag
- Images now receive two tags: pr-<nr> and pr-<nr>-<sha7>
- Enables precise version identification and deployment rollback

* feat: add registry-based caching for faster builds

- Add cache_tag output to determine-tag job (PR-specific or shared)
- Add cache-from/cache-to for all three images (landing-page, operator, service)
- PR builds use PR-specific cache with fallback to shared cache
- Main builds use shared 'build-cache' tag

* feat: switch to self-hosted ARC runners

- Use arc-runner-set-stateless for amd64 builds
- Disable ARM builds temporarily (pending ARM cluster availability)
- Reduces build times and costs using on-premise infrastructure

* ci: remove concurrency to allow parallel builds

* ci: trigger workflow

* chore: enable ARM64 builds in CI

* fix: specify arm64 runner set in CI workflow

* trigger: retry arm build

* trigger: retry with fixed job container requirement

* chore: trigger ci to verify spegel caching

* feat: configure buildx to use internal harbor cache

* feat: Add registry services to build workflow

* feat: Add registry caching with cache-from and cache-to

* feat: Add conditional apt proxy config to Dockerfiles

* Trigger CI to test apt proxy fix

* Test apt proxy with HTTPS CONNECT fix

* chore: Remove trigger.txt

* feat: Use APT_HTTP_PROXY build-arg for hybrid caching

Updated all Dockerfiles to accept APT_HTTP_PROXY build-arg instead of
copying .docker-build-config/01proxy file from context.

Benefits:
- Hybrid compatible: Works on both ARC runners and GitHub-hosted runners
- No COPY layer needed in build
- Cleaner approach with ARG/conditional logic

Modified Dockerfiles:
- dockerfiles/conversion-webhook/Dockerfile
- dockerfiles/operator/Dockerfile
- dockerfiles/service/Dockerfile
- dockerfiles/wondershaper/Dockerfile

Each now:
- Accepts APT_HTTP_PROXY as ARG
- Conditionally configures proxy if provided
- Falls back to direct connection if not provided (GitHub runners)

* chore: Trigger CI to test APT_HTTP_PROXY build-arg

* fix: Use host network for ARC runner builds to access Kubernetes DNS

Docker buildx using default bridge network cannot resolve Kubernetes service DNS,
causing APT proxy timeouts on arm64 builds. Using host network allows builds
to resolve apt-cacher-ng.apt-cacher-ng.svc.cluster.local and other internal services.

Note: This is safe for our internal ARC runners but would not be appropriate for
public GitHub-hosted runners.

* fix: Force HTTP repos when using apt-cacher-ng to enable caching

- Convert HTTPS repos to HTTP when APT_HTTP_PROXY is set
- Fixes 500 errors from apt-cacher-ng on Ubuntu Noble/Debian Bookworm
- Ubuntu Noble defaults to HTTPS which apt-cacher-ng cannot cache
- Add cache verification workflow to monitor infrastructure health
- Workflow runs on PR changes to Dockerfiles and manual trigger

* ci: enhance verify-cache workflow with extensive tests

* fix(ci): use docker container for npm cache verification

* fix: Only tag as 'latest' on main/master branch

- Previously, workflow_dispatch on any branch would tag as 'latest'
- Now properly checks both event type AND branch ref
- Feature branch workflow_dispatch/push now tags with branch name
- Prevents accidental 'latest' tag pollution from feature branches

* feat: Add Squid HTTPS proxy verification to cache tests

- Add verify-squid-cache job to test Squid proxy connectivity
- Test both HTTP (port 3128) and HTTPS (port 3129) endpoints
- Functional test downloads VSIX extension twice to verify caching
- Update report-status to include Squid proxy status
- Ensures VS Code extension caching layer is working properly

* fix: Correctly test Squid HTTPS proxy port 3129

- Port 3129 is an SSL-bump proxy, not a direct endpoint
- Use curl with -x flag to test HTTPS requests through the proxy
- Previous test was incorrectly fetching the proxy endpoint directly

* fix: Install Squid CA certificate for HTTPS proxy verification

- Checkout squid-proxy-ca.crt from artemis-theia-blueprints repo
- Install CA cert into system trust store with update-ca-certificates
- Removes need for -k (insecure) flag in curl commands
- Properly validates SSL-bump proxy certificates

* debug: Check where cert file is located after sparse checkout

* fix: Download Squid CA cert directly with curl

- Simpler approach than sparse checkout
- Fetches cert directly from GitHub raw URL
- Avoids git checkout complexity

* feat: Add Squid CA certificate to theia-cloud repo

- Copy squid-proxy-ca.crt from artemis-theia-blueprints
- Workflow now uses local cert file via checkout
- Self-contained solution, no external dependencies

* feat: implement external language server support

* fix: Change PVC access mode to ReadWriteMany for shared volume access

- Language server pods need to mount the same PVC as Theia pods
- ReadWriteOnce prevents multiple pods from mounting the volume
- Switch to Longhorn storage class which supports RWX
- Enables simultaneous access for Theia IDE and external language servers

* feat: Inject WORKSPACE_PATH environment variable into language server pods

- Add WORKSPACE_PATH env var to LS deployments when PVC is mounted
- Set WORKSPACE_PATH to the same value as the mount path from AppDefinitionSpec
- Ensures Java and Rust language servers use the correct workspace directory

This fixes the workspace path inconsistency issue where:
- Kubernetes operator mounts PVC to /home/project (or custom path)
- Language server images were hardcoded to use different paths
- Now LS containers receive WORKSPACE_PATH env var with the correct path

Works in conjunction with PR #80 in artemis-theia-blueprints which
updates LS images to respect the WORKSPACE_PATH environment variable.

Also adds comprehensive Kubernetes testing documentation.

* docs: Remove temporary markdown files from feature branch

- Remove EXTERNAL_LS_IMPLEMENTATION_PLAN.md (implementation complete)
- Remove EXTERNAL_LS_TESTING.md (content moved to PR description)

* fix: Update ARM runner name from arc-runner-set-stateless-arm to arc-runner-set-arm64

* fix: Correct ARM runner name to arc-runner-set-stateless-arm

* Revert "fix: Correct ARM runner name to arc-runner-set-stateless-arm"

This reverts commit a3b40bd.

* chore: trigger CI

* feat: Add concurrency control to skip intermediate queued runs per branch

* push mods

* empty

* Remaining fixes as a result of merging main

* Make sentry configurable

* Some more documentation

* add proper argument forwarding

* Fix coderabbit issues

* Fix additional comments

* docs: Add AGENTS.md with build commands and code style guidelines

* Add prewarmed language server resource factory and manager methods

Add createPrewarmedDeployment/Service, patchPvcIntoLsDeployment, and
deletePrewarmedResources to LanguageServerResourceFactory with AppDef-owned
naming (instance-{id}-ls-{appDef}-{uid}).

Add patchPvcIntoPrewarmedLsDeployment and deletePrewarmedLanguageServer
to LanguageServerManager as orchestration layer.

* Integrate prewarmed LS into EagerSessionHandler and PrewarmedResourcePool

EagerSessionHandler: add getStorageName(), replace createLanguageServer()
with patchPvcIntoPrewarmedLsDeployment() at session assignment, and clean
up prewarmed LS resources on session deletion.

PrewarmedResourcePool: create, reconcile, and delete LS resources alongside
Theia pods via ensureLanguageServerCapacity/reconcileLanguageServers helpers.

* Decouple patchEnvVarsIntoExistingDeployment from Session object

* feat: disable QEMU setup for image builds

* fix: remove duplicate ghcr.io prefix from image names

* fix: use registry-mirror with zot NodePort instead of deprecated Harbor mirrors

* fix PVC eager start

* Add SidecarSpec to AppDefinition CRD, bump to v1beta11 with conversion mapper

* Add sidecar package: SidecarConfig, SidecarManager, SidecarResourceFactory

Introduce the new org.eclipse.theia.cloud.operator.sidecar package that
replaces the hardcoded languageserver package with an agnostic N-sidecar
system driven entirely by CRD configuration.

- SidecarConfig: immutable record with fromSpec()/fromLegacyOptions()
  for v1beta11 sidecars list and backward-compatible options map
- SidecarManager: @singleton facade for create/delete/inject lifecycle
  across both lazy and eager (prewarmed) session paths
- SidecarResourceFactory: Fabric8 DeploymentBuilder/ServiceBuilder
  replacing YAML template placeholder substitution

* Replace LanguageServer references with Sidecar in operator consumers

Update DI module, session handlers, and pool to use the new sidecar
package instead of the languageserver package:

- AbstractTheiaCloudOperatorModule: bind SidecarManager + SidecarResourceFactory
- LazySessionHandler: injectSidecarEnvVars, createSidecars, deleteSidecars
- EagerSessionHandler: deletePrewarmedSidecars, remove patchEnvVars block
- PrewarmedResourcePool: delegate all LS capacity/reconcile/create/delete
  calls to SidecarManager, remove 3 private LS helper methods

* Delete languageserver package and YAML templates

Remove the now-unused hardcoded language server system:
- LanguageServerConfig, LanguageServerManager, LanguageServerRegistry,
  LanguageServerResourceFactory (4 Java files)
- templateLanguageServerDeployment.yaml, templateLanguageServerService.yaml

* Fix eager path: create sidecars before Theia, inject env vars, restart pods on release

* Add SidecarConfig unit tests (22 tests), update AGENTS.md sidecar docs, add test deps to operator pom

* Harden sidecar config: validate unique names and serialize SIDECAR_CONFIG via Jackson

* ci: build and push conversion-webhook image in PR/branch builds

Adds a build-and-push-conversion-webhook job mirroring the operator job.
This ensures the conversion webhook image (with v1beta11 mapper support)
is published as ghcr.io/eduide/eduide-cloud/conversion-webhook:pr-70
for deployment testing via EduIDE-deployment.

* fix(conversion): register AppDefinitionV1beta10 in Fabric8 SPI

AppDefinitionV1beta10 was missing from the KubernetesResource SPI file.
Fabric8 uses ServiceLoader to discover typed CustomResource classes for
JSON deserialization. Without registration, incoming v1beta10 objects
are deserialized as GenericKubernetesResource, causing a ClassCastException
in the conversion webhook when v1beta11 becomes the storage version and
Kubernetes asks the webhook to convert existing v1beta10 resources.

* fix(conversion): null-safe timeout in AppDefinitionHub v1beta9/v1beta10 constructors

timeout is an optional Integer field in v1beta9/v1beta10 specs — not set
on all existing resources. OptionalInt.of() on a null Integer throws NPE
during conversion. Fix by guarding with a null check, matching the
existing pattern already used in the v1beta8 constructor.

* fix(operator): harden appdefinition conversion/init edge cases

- guard null timeout in v1beta10 AppDefinitionHub conversion path
- retry appdefinition watch init on transient 429 "storage is (re)initializing"

* fix(sidecar): address reviewer findings in prewarmed reconcile and conversion

- fix v1beta10 status mapping guard for operatorStatus
- make prewarmed sidecar reconciliation recover missing service/deployment independently
- make sidecar PVC mount injection idempotent and propagate pullSecret to sidecar pods
- ensure prewarmed PVCs exist before sidecar reconcile/create and remove dead helper
- default mountWorkspace to true when omitted
- finish lazy cleanup span on successful session deletion

* docs: untrack sidecar redesign planning notes

- remove docs/sidecar-redesign from repository tracking
- keep files local-only for personal/reference use

* fix(conversion): guard nullable maxInstances and align PVC Javadoc

- handle nullable v1beta10 maxInstances in AppDefinitionHub conversion
- align createInstancePvc Javadoc with actual behavior

* fix(common): preserve sidecar equality semantics and nullable v1beta10 maxInstances

- compare SidecarSpec.mountWorkspace via Objects.equals to avoid boxed Boolean identity bugs
- keep v1beta10 maxInstances nullable in hub->v1beta10 mapping instead of coercing absent values to 0

---------

Co-authored-by: lukaskratzel <lukaskratzel2004@gmail.com>
…essions (#100)

* fix(operator): inject sidecar env vars for lazy sessions without PVC

* chore: trigger CI

* chore: trigger CI

* fix(ci): remove duplicate conversion-webhook job key

* fix(operator): use session-based sidecar host names in lazy env injection

* fix(service): reject ephemeral launch for sidecar-enabled app definitions

* refactor(sidecar): remove legacy langserver-image options path

* docs(agents): document CRD-only sidecars and workspace-backed launch rules

* fix(operator): enforce k8s-safe lazy sidecar service names

* fix(operator): recreate terminating eager PVCs before deployment
)

* fix(storage): require shared workspace before RWX

* test(service): clarify ephemeral session error test
* add bazel url, and remove tls setup

* revert gradle flag to standart buildCache flag, to not introduce breaking changes
Add documentation/ExternalIntegration.md describing the POST /service
launch contract, the LaunchRequest and EnvironmentVars payload, the
end-to-end env-var flow (lazy vs eager/prewarmed injection), the auth
model, and integrator behaviors. Link it from Architecture.md. Generated
api/ files and openapi.json are left untouched.


Claude-Session: https://claude.ai/code/session_012iEasFrsCzFTCkRh5SP1KY

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Repoints the three image builds at the org-owned reusable workflow and
collapses three near-identical 18-line jobs into one matrix (107 -> 62
lines).

Why this matters beyond tidiness:

- Drops the dependency on ls1intum/.github@feature/split-build-workflow-modes,
  an unmerged PR branch in another organisation. If that branch is
  deleted, every image build here breaks.

- operator, service and conversion-webhook are now built for both
  linux/amd64 and linux/arm64 on every event, including pull requests.
  Previously arm64 was skipped for PRs, so a PR image could not be
  scheduled onto an arm64 node.

- fail-fast: false, so one component failing no longer cancels the other
  two.

Removes verify-cache.yml and certs/squid-proxy-ca.crt. That workflow only
probed cluster-internal services (apt-cacher-ng, verdaccio, squid and the
two registry mirrors, all .svc.cluster.local) which are unreachable from
GitHub-hosted runners, and the CA certificate existed solely for it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019qeiQRFu8xAMRYWPdZewjG
@Mtze

Mtze commented Aug 25, 2026

Copy link
Copy Markdown
Author

Opened against the wrong repository by mistake - this targets the EduIDE/EduIDE-Cloud fork, not upstream Theia Cloud. Apologies for the noise.

@Mtze Mtze closed this Aug 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants