Skip to content

Add ok-to-test gate, use cluster HF token for e2e tests, fix istio issues, run wva against 2 different stacks simultaneously #43

Add ok-to-test gate, use cluster HF token for e2e tests, fix istio issues, run wva against 2 different stacks simultaneously

Add ok-to-test gate, use cluster HF token for e2e tests, fix istio issues, run wva against 2 different stacks simultaneously #43

name: CI - OpenShift E2E Gate
on:
pull_request:
branches:
- main
- dev
issue_comment:
types: [created]
# Permissions needed for nested e2e workflow to push images to GHCR
permissions:
contents: read
packages: write
pull-requests: write
issues: write
jobs:
# Post a comment on new PRs explaining the ok-to-test requirement
post-instructions:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- name: Check if author is admin/maintainer
id: check-permission
uses: actions/github-script@v7
with:
script: |
const { data: permission } = await github.rest.repos.getCollaboratorPermissionLevel({
owner: context.repo.owner,
repo: context.repo.repo,
username: context.payload.pull_request.user.login
});
const isPrivileged = ['admin', 'maintain', 'write'].includes(permission.permission);
console.log(`User ${context.payload.pull_request.user.login} has permission: ${permission.permission}, privileged: ${isPrivileged}`);
core.setOutput('is_privileged', isPrivileged);
return isPrivileged;
- name: Post ok-to-test instructions
if: steps.check-permission.outputs.is_privileged != 'true'
uses: actions/github-script@v7
with:
script: |
// Check if we already posted instructions
const comments = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number
});
const botComment = comments.data.find(c =>
c.user.type === 'Bot' &&
c.body.includes('OpenShift E2E tests require approval')
);
if (!botComment) {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.payload.pull_request.number,
body: `## OpenShift E2E Tests
OpenShift E2E tests require approval before running on external contributions.
**For maintainers/admins:** Comment \`/ok-to-test\` to approve and run the OpenShift E2E tests.
**For contributors:** Please wait for a maintainer to review and approve your PR for E2E testing.
_This check uses GPU resources on a shared OpenShift cluster._`
});
}
# Check for /ok-to-test comment and run tests
check-ok-to-test:
if: |
github.event_name == 'issue_comment' &&
github.event.issue.pull_request &&
contains(github.event.comment.body, '/ok-to-test')
runs-on: ubuntu-latest
outputs:
approved: ${{ steps.check.outputs.approved }}
pr_number: ${{ steps.get-pr.outputs.pr_number }}
pr_sha: ${{ steps.get-pr.outputs.pr_sha }}
steps:
- name: Check commenter permission
id: check
uses: actions/github-script@v7
with:
script: |
const { data: permission } = await github.rest.repos.getCollaboratorPermissionLevel({
owner: context.repo.owner,
repo: context.repo.repo,
username: context.payload.comment.user.login
});
const isPrivileged = ['admin', 'maintain', 'write'].includes(permission.permission);
console.log(`User ${context.payload.comment.user.login} has permission: ${permission.permission}, approved: ${isPrivileged}`);
if (isPrivileged) {
// Add reaction to indicate approval
await github.rest.reactions.createForIssueComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: context.payload.comment.id,
content: 'rocket'
});
} else {
await github.rest.reactions.createForIssueComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: context.payload.comment.id,
content: '-1'
});
}
core.setOutput('approved', isPrivileged);
- name: Get PR details
id: get-pr
if: steps.check.outputs.approved == 'true'
uses: actions/github-script@v7
with:
script: |
const { data: pr } = await github.rest.pulls.get({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.payload.issue.number
});
core.setOutput('pr_number', pr.number);
core.setOutput('pr_sha', pr.head.sha);
console.log(`PR #${pr.number} at SHA ${pr.head.sha}`);
# Run tests for privileged PR authors (automatic)
run-for-privileged:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
outputs:
should_run: ${{ steps.check.outputs.is_privileged }}
steps:
- name: Check if author is privileged
id: check
uses: actions/github-script@v7
with:
script: |
const { data: permission } = await github.rest.repos.getCollaboratorPermissionLevel({
owner: context.repo.owner,
repo: context.repo.repo,
username: context.payload.pull_request.user.login
});
const isPrivileged = ['admin', 'maintain', 'write'].includes(permission.permission);
console.log(`Author ${context.payload.pull_request.user.login} is privileged: ${isPrivileged}`);
core.setOutput('is_privileged', isPrivileged);
# Trigger the actual e2e tests
trigger-e2e:
needs: [run-for-privileged]
if: |
github.event_name == 'pull_request' &&
needs.run-for-privileged.outputs.should_run == 'true'
uses: ./.github/workflows/ci-e2e-openshift.yaml
with:
ref: ${{ github.event.pull_request.head.sha }}
secrets: inherit
trigger-e2e-approved:
needs: [check-ok-to-test]
if: |
github.event_name == 'issue_comment' &&
needs.check-ok-to-test.outputs.approved == 'true'
uses: ./.github/workflows/ci-e2e-openshift.yaml
with:
ref: ${{ needs.check-ok-to-test.outputs.pr_sha }}
secrets: inherit