From 2ae678bcb39b44462d4e34536e47aec4eca742bf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stefan=20W=C3=A4rting?= Date: Tue, 29 Sep 2026 10:16:47 +0200 Subject: [PATCH] Run CI and releases exclusively on self-hosted pools --- .github/actionlint.yaml | 3 ++ .github/workflows/ci.yml | 39 ++++++++++++++-------- .github/workflows/dependabot-automerge.yml | 2 +- .github/workflows/release.yml | 2 +- README.md | 7 ++++ 5 files changed, 37 insertions(+), 16 deletions(-) create mode 100644 .github/actionlint.yaml diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml new file mode 100644 index 0000000..3453c7e --- /dev/null +++ b/.github/actionlint.yaml @@ -0,0 +1,3 @@ +self-hosted-runner: + labels: + - tart diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ca3f6f1..2bd3091 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,8 +11,9 @@ concurrency: jobs: validate: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository name: validate action - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 - uses: actions/setup-python@v6 @@ -24,16 +25,22 @@ jobs: python -m unittest discover -s tests -v - name: actionlint run: | - curl -fsSL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash | bash -s -- latest /usr/local/bin - actionlint + mkdir -p "$RUNNER_TEMP/actionlint" + curl -fsSL https://raw.githubusercontent.com/rhysd/actionlint/main/scripts/download-actionlint.bash | bash -s -- latest "$RUNNER_TEMP/actionlint" + "$RUNNER_TEMP/actionlint/actionlint" selftest: - name: test-${{ matrix.os }} - runs-on: ${{ matrix.os }} + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository + name: test-${{ matrix.platform }} + runs-on: ${{ matrix.runner }} strategy: fail-fast: false matrix: - os: [ubuntu-latest, ubuntu-22.04, macos-latest, macos-14] + include: + - platform: macos-arm64 + runner: [self-hosted, macOS, ARM64, tart] + - platform: linux-x64 + runner: [self-hosted, linux, x64] steps: - uses: actions/checkout@v7 @@ -70,8 +77,9 @@ jobs: adb --version selftest-multipackage: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository name: test-multipackage - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 - uses: actions/setup-java@v6 @@ -90,8 +98,9 @@ jobs: [ -x "$ANDROID_HOME/platform-tools/adb" ] selftest-nopackages: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository name: test-cli-only - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 - id: cli @@ -105,8 +114,9 @@ jobs: [ -n "$CLI_VERSION" ] selftest-nocache: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository name: test-nocache - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 - uses: ./ @@ -116,8 +126,9 @@ jobs: - run: adb --version selftest-custom-sdk-path: + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository name: test-custom-sdk-path - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 - id: cli @@ -130,9 +141,9 @@ jobs: SDK_PATH: ${{ steps.cli.outputs.sdk-path }} run: | set -euo pipefail - [ "$ANDROID_HOME" = "/tmp/my-android-sdk" ] + [ "$ANDROID_HOME" = "$(cd /tmp/my-android-sdk && pwd -P)" ] [ -x "/tmp/my-android-sdk/platform-tools/adb" ] - [ "$SDK_PATH" = "/tmp/my-android-sdk" ] + [ "$SDK_PATH" = "$ANDROID_HOME" ] selftest-windows: name: test-windows-x64 @@ -187,7 +198,7 @@ jobs: # Gate job. Name MUST be "CI" to match the org-level required_status_checks # ruleset that protects the default branch. CI: - if: always() + if: always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) needs: - validate - selftest @@ -196,7 +207,7 @@ jobs: - selftest-nocache - selftest-custom-sdk-path - selftest-windows - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - name: Check results env: diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 54ed928..895e42e 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -7,7 +7,7 @@ permissions: jobs: dependabot: - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] if: github.actor == 'dependabot[bot]' || github.actor == 'premex-pot[bot]' steps: - name: Generate token diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aedc2d5..639dcd4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,7 +9,7 @@ permissions: jobs: release: - runs-on: ubuntu-latest + runs-on: [self-hosted, macOS, ARM64, tart] steps: - uses: actions/checkout@v7 diff --git a/README.md b/README.md index aaf4049..9d7f65f 100644 --- a/README.md +++ b/README.md @@ -183,3 +183,10 @@ These surface build issues as inline annotations in the GitHub UI. ## License [MIT](LICENSE) + +## Repository CI runners + +This repository uses our self-hosted pools exclusively: Tart (macOS ARM64) for +validation, SDK scenarios, releases and maintenance; Linux x64 for the Linux +installation smoke test; and Windows x64 for Windows installation tests. +External fork pull requests do not execute repository code on these pools.