GRM-172: ci: docs fast-path, notify-failure scoping, post-merge queue
Post-merge / detect-and-configure (push) Successful in 1m1s
Post-merge / release-and-maintain (push) Successful in 54s

Co-authored-by: emil User <emil.simeonov@tutanota.com>
This commit was merged in pull request #281.
This commit is contained in:
2026-09-21 20:21:20 +00:00
committed by kireto
parent 96ff368c7c
commit 1b315e0aba
3 changed files with 58 additions and 38 deletions
+30 -25
View File
@@ -1,38 +1,43 @@
# GRM-172: Audit and document pre-pull image usage guidelines
# GRM-172: CI hygiene — docs fast-path, failure-notify scoping, post-merge cancel
## Problem
The grm repo contains a runner-level `pre_pull_images.yml` task file that
pre-pulls Docker images to avoid repeated pulls on every CI run. However,
there was no audit confirming that molecule `prepare.yml` files are not
also redundantly pre-pulling images that the runner setup already caches.
Wasteful pre-pulling wastes CI time and disk space.
GRM CI has the same inefficiencies fixed in infra (OBL-INFRA-613/615/616):
docs-only PRs run the full quality suite, CI failures auto-create issues
(noise — issues are for deploy failures only), and post-merge
`cancel-in-progress: true` can kill a release mid-publish.
## Approach
Audit all molecule `prepare.yml` files in the grm repo for pre-pull tasks.
The audit found NO molecule prepare.yml files contain pre-pull tasks, so no
code removal is needed. Document the audit findings in a spec and add a
comment to the runner-level `pre_pull_images.yml` task file clarifying that
it should not be used for images that molecule tests pull themselves (to
avoid redundant pulls).
REQ-1: Audit all molecule prepare.yml files for pre-pull tasks and confirm none exist
REQ-2: Add documentation comment to pre_pull_images.yml stating it should not be used for CI runner container images (already cached by runner setup) or images molecule tests pull themselves
REQ-3: Confirm gitea_runner_pre_pull_images default remains empty ([]) which is correct
REQ-1: Docs-only PRs skip heavy validate steps (lint-all, unit tests,
translation check, test-speed, security scan, workflow dry-run). Docs
gate, spec validation, PR size, and auto-merge preconditions still run.
Restricted to pull_request events.
REQ-2: Remove the failure-issue step from `ci.yml` validate job.
Post-merge keeps failure notification (release/publish failures are
deploy-pipeline events).
REQ-3: post-merge `cancel-in-progress: false` — queue instead of killing
an in-flight release/publish.
## Test Plan
- Grep all molecule prepare.yml files for pre-pull patterns confirms zero matches
- Verify pre_pull_images.yml comment is present and accurate
- Verify gitea_runner_pre_pull_images default is [] in defaults/main.yml
- Run make lint-ci to confirm no lint regressions
- `make workflow-lint` passes.
- Docs-only PR: quality steps skipped, gates still run.
- Non-docs PR: unchanged behavior.
## Deploy Plan
- Merge to master via auto-merge workflow
- No runtime changes; documentation-only
Workflow-only change; takes effect on merge. No release needed.
## Rollback Plan
- Revert the merge commit; comments are removed, no functional impact
Revert the commit.
## Acceptance Criteria
- [x] REQ-1: No molecule prepare.yml files in the grm repo contain pre-pull tasks (audit confirmed via grep)
- [x] REQ-2: pre_pull_images.yml contains a comment documenting it should not be used for CI runner container images or images molecule tests pull themselves
- [x] REQ-3: gitea_runner_pre_pull_images default remains empty ([]) in defaults/main.yml
- [x] REQ-1 implemented — early docs-only step + step-level `if` gates
- [x] REQ-2 implemented — notify step removed from ci.yml only
- [x] REQ-3 implemented — post-merge concurrency flipped
- [x] `make workflow-lint` passes