From 1b315e0abae4a5d3b57ba79f0c63a884594a567a Mon Sep 17 00:00:00 2001 From: emil User Date: Mon, 21 Sep 2026 20:21:20 +0000 Subject: [PATCH] GRM-172: ci: docs fast-path, notify-failure scoping, post-merge queue Co-authored-by: emil User --- .gitea/workflows/ci.yml | 37 +++++++++++++++------- .gitea/workflows/post-merge.yml | 4 ++- docs/specs/GRM-172.md | 55 ++++++++++++++++++--------------- 3 files changed, 58 insertions(+), 38 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 398f73a..ac405b7 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -32,6 +32,22 @@ jobs: - uses: actions/checkout@v4 with: fetch-depth: 0 + # Implements: REQ-1 (GRM-172) — docs-only changes skip the heavy + # quality steps. Detection needs only git, so it runs before setup. + - name: Detect docs-only change + id: docs-only + if: github.event_name == 'pull_request' + run: | + HEAD="${{ github.event.pull_request.head.sha || github.sha }}" + DOCS_ONLY=true + while IFS= read -r f; do + case "$f" in + docs/*|*.md|.devin/*) ;; + *) DOCS_ONLY=false; break;; + esac + done < <(git diff --name-only "origin/master...$HEAD") + echo "docs-only=$DOCS_ONLY" >> "$GITHUB_OUTPUT" + echo "docs-only=$DOCS_ONLY" - name: Set up environment env: CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }} @@ -39,11 +55,13 @@ jobs: run: make setup-image EXTRAS=ci,lint # --- quality steps --- - name: Lint all + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true export PATH="$HOME/.local/bin:$PATH" make lint-all - name: Unit tests with 100% coverage + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true make pytest-cov @@ -57,14 +75,17 @@ jobs: export PATH="$HOME/.local/bin:$PATH" make devx-docs-check - name: Translation completeness check + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true python3 -m devx.ci.check_translations --translations src/grm/translations.json - name: Check unit test speed + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true python3 -m devx.tools.check_test_speed --max-seconds 4 --max-single-seconds 0.5 - name: Dependency security scan + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true # Install pip in venv if missing (needed by pip-audit) @@ -72,6 +93,7 @@ jobs: PIPAPI_PYTHON_LOCATION=$PWD/.venv/bin/python \ pip-audit --desc --skip-editable 2>&1 || true - name: Workflow dry-run validation + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true export PATH="$HOME/.local/bin:$PATH" @@ -156,18 +178,9 @@ jobs: --owner "${{ github.repository_owner }}" \ --repo "${{ github.event.repository.name }}" \ --github-output - - name: Notify on failure - if: failure() - env: - CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }} - run: | - . .venv/bin/activate 2>/dev/null || true - export PATH="$HOME/.local/bin:$PATH" - python3 -m devx.ci.notify_failure --auto-login \ - --repo "${{ github.repository }}" \ - --run-id "${{ github.run_id }}" \ - --workflow "ci/validate" \ - --commit "${{ github.sha }}" + # Implements: REQ-2 (GRM-172) — no failure-issue step in PR CI; + # auto-created issues are for deploy-pipeline failures only + # (post-merge keeps its notification). molecule-tests: needs: [validate] diff --git a/.gitea/workflows/post-merge.yml b/.gitea/workflows/post-merge.yml index bfe2741..2e93e14 100644 --- a/.gitea/workflows/post-merge.yml +++ b/.gitea/workflows/post-merge.yml @@ -25,7 +25,9 @@ on: concurrency: group: post-merge-${{ github.ref }} - cancel-in-progress: true + # Implements: REQ-3 (GRM-172) — queue instead of killing an in-flight + # release/publish; a cancelled release can leave tag-without-publish. + cancel-in-progress: false env: PIP_BREAK_SYSTEM_PACKAGES: "1" diff --git a/docs/specs/GRM-172.md b/docs/specs/GRM-172.md index a0e788a..f739cdb 100644 --- a/docs/specs/GRM-172.md +++ b/docs/specs/GRM-172.md @@ -1,38 +1,43 @@ -# GRM-172: Audit and document pre-pull image usage guidelines +# GRM-172: CI hygiene — docs fast-path, failure-notify scoping, post-merge cancel ## Problem -The grm repo contains a runner-level `pre_pull_images.yml` task file that -pre-pulls Docker images to avoid repeated pulls on every CI run. However, -there was no audit confirming that molecule `prepare.yml` files are not -also redundantly pre-pulling images that the runner setup already caches. -Wasteful pre-pulling wastes CI time and disk space. + +GRM CI has the same inefficiencies fixed in infra (OBL-INFRA-613/615/616): +docs-only PRs run the full quality suite, CI failures auto-create issues +(noise — issues are for deploy failures only), and post-merge +`cancel-in-progress: true` can kill a release mid-publish. ## Approach -Audit all molecule `prepare.yml` files in the grm repo for pre-pull tasks. -The audit found NO molecule prepare.yml files contain pre-pull tasks, so no -code removal is needed. Document the audit findings in a spec and add a -comment to the runner-level `pre_pull_images.yml` task file clarifying that -it should not be used for images that molecule tests pull themselves (to -avoid redundant pulls). -REQ-1: Audit all molecule prepare.yml files for pre-pull tasks and confirm none exist -REQ-2: Add documentation comment to pre_pull_images.yml stating it should not be used for CI runner container images (already cached by runner setup) or images molecule tests pull themselves -REQ-3: Confirm gitea_runner_pre_pull_images default remains empty ([]) which is correct +REQ-1: Docs-only PRs skip heavy validate steps (lint-all, unit tests, +translation check, test-speed, security scan, workflow dry-run). Docs +gate, spec validation, PR size, and auto-merge preconditions still run. +Restricted to pull_request events. + +REQ-2: Remove the failure-issue step from `ci.yml` validate job. +Post-merge keeps failure notification (release/publish failures are +deploy-pipeline events). + +REQ-3: post-merge `cancel-in-progress: false` — queue instead of killing +an in-flight release/publish. ## Test Plan -- Grep all molecule prepare.yml files for pre-pull patterns confirms zero matches -- Verify pre_pull_images.yml comment is present and accurate -- Verify gitea_runner_pre_pull_images default is [] in defaults/main.yml -- Run make lint-ci to confirm no lint regressions + +- `make workflow-lint` passes. +- Docs-only PR: quality steps skipped, gates still run. +- Non-docs PR: unchanged behavior. ## Deploy Plan -- Merge to master via auto-merge workflow -- No runtime changes; documentation-only + +Workflow-only change; takes effect on merge. No release needed. ## Rollback Plan -- Revert the merge commit; comments are removed, no functional impact + +Revert the commit. ## Acceptance Criteria -- [x] REQ-1: No molecule prepare.yml files in the grm repo contain pre-pull tasks (audit confirmed via grep) -- [x] REQ-2: pre_pull_images.yml contains a comment documenting it should not be used for CI runner container images or images molecule tests pull themselves -- [x] REQ-3: gitea_runner_pre_pull_images default remains empty ([]) in defaults/main.yml + +- [x] REQ-1 implemented — early docs-only step + step-level `if` gates +- [x] REQ-2 implemented — notify step removed from ci.yml only +- [x] REQ-3 implemented — post-merge concurrency flipped +- [x] `make workflow-lint` passes