Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 2 additions & 13 deletions .github/workflows/branch-e2e.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
name: Branch E2E Checks

on:
merge_group:
types: [checks_requested]
push:
branches:
- "pull-request/[0-9]+"
Expand Down Expand Up @@ -50,15 +48,6 @@ jobs:
run_kubernetes_ha_e2e="$(jq -r 'index("test:e2e-kubernetes") != null' <<< "$LABELS_JSON")"
run_kubernetes_credential_drivers_e2e="$(jq -r 'index("test:e2e-kubernetes") != null' <<< "$LABELS_JSON")"
;;
merge_group)
# Merge groups have no PR labels. When GPU E2E is required as documented
# in CI.md, skipping it leaves the gate pending until the queue times out
# and ejects the PR. HA stays off until stable.
run_core_e2e=true
run_gpu_e2e=true
run_kubernetes_ha_e2e=false
run_kubernetes_credential_drivers_e2e=false
;;
*)
run_core_e2e=true
run_gpu_e2e=true
Expand All @@ -82,7 +71,7 @@ jobs:

version:
needs: [pr_metadata]
if: needs.pr_metadata.outputs.should_run == 'true'
if: needs.pr_metadata.outputs.should_run == 'true' && needs.pr_metadata.outputs.run_any_e2e == 'true'
permissions:
contents: read
runs-on: ubuntu-latest
Expand Down Expand Up @@ -228,7 +217,7 @@ jobs:
build-rpm:
name: Build RPM packages
needs: [pr_metadata, version, build-binaries]
if: needs.pr_metadata.outputs.should_run == 'true'
if: needs.pr_metadata.outputs.run_integration == 'true'
permissions:
actions: read
contents: read
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/required-ci-gates.yml
Original file line number Diff line number Diff line change
Expand Up @@ -276,6 +276,9 @@ jobs:
resolve_context

evaluate_workflow "OpenShell / Branch Checks" "branch-checks.yml" "Branch Checks"
evaluate_workflow "OpenShell / E2E" "branch-e2e.yml" "Branch E2E Checks" "test:e2e" "Core E2E result"
evaluate_workflow "OpenShell / GPU E2E" "branch-e2e.yml" "Branch E2E Checks" "test:e2e-gpu" "GPU E2E result"
# E2E is opt-in on PRs and does not run for merge groups.
if [ "$CONTEXT_KIND" != "merge_group" ]; then
evaluate_workflow "OpenShell / E2E" "branch-e2e.yml" "Branch E2E Checks" "test:e2e" "Core E2E result"
evaluate_workflow "OpenShell / GPU E2E" "branch-e2e.yml" "Branch E2E Checks" "test:e2e-gpu" "GPU E2E result"
fi
evaluate_workflow "OpenShell / Helm Lint" "helm-lint.yml" "Helm Lint"
17 changes: 9 additions & 8 deletions CI.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,8 +72,8 @@ Windows checks are not required for merging and do not run in merge queues.
Main and manual runs also build release binaries, with `continue-on-error: true`
so Windows failures do not fail the workflow.

Every approved `Branch E2E Checks` run builds the RPM packages, including
runs without optional E2E labels. Core integration qualification builds and installs
`Branch E2E Checks` builds binaries and images only when an E2E suite is
selected. DEB and RPM packages build only when integration qualification is selected. Core integration qualification builds and installs
the DEB on Ubuntu with Docker and installs the CLI and gateway RPMs on Fedora with
rootful and rootless Podman. These lanes run conformance using the matching runtime
images. Release Dev and Release Tag use the same package installers.
Expand Down Expand Up @@ -433,8 +433,6 @@ Important: if a PR requires manual admission, every new commit needs another `/o
GitHub merge queue is required for `main`. Repository administrators must enable **Require merge queue** in the branch ruleset for `main` and keep these required status contexts aligned with the PR gates:

- `OpenShell / Branch Checks`
- `OpenShell / E2E`
- `OpenShell / GPU E2E`
- `OpenShell / Helm Lint`
- `OpenShell / Trivy Changes`

Expand All @@ -445,7 +443,7 @@ its own stable result status.
Merge-group runs use the `merge_group` event. The event is distinct from `pull_request` and `push`, and GitHub will not report required checks for queued PRs unless the workflows include it. In this repository:

- `Branch Checks` runs the standard non-E2E gates on the merge-group SHA.
- `Branch E2E Checks` runs core E2E and GPU E2E for merge groups. Kubernetes HA E2E remains optional and label-driven on PRs.
- `Branch E2E Checks` does not run for merge groups. E2E suites remain opt-in on PRs.
- `Helm Lint` runs for merge groups without the PR diff optimization, because the merge-group branch is the final integration state.
- `Trivy Changes` compares the merge-group configuration with its base and rejects new High or Critical findings.
- `Required CI Gates` posts the same `OpenShell / ...` statuses to the merge-group SHA and does not require a `pull-request/<N>` mirror for merge-group events.
Expand All @@ -471,7 +469,7 @@ The bot's full administrator documentation is internal to NVIDIA. The only comma
| File | Role |
|---|---|
| `.github/workflows/branch-checks.yml` | Required non-E2E checks. Triggers on `push: pull-request/[0-9]+` for PR mirrors and `merge_group` for queued merges. |
| `.github/workflows/branch-e2e.yml` | Standard, GPU, Kubernetes HA, and Kubernetes credential-driver E2E. PR mirror pushes use `test:e2e`, `test:e2e-gpu`, and `test:e2e-kubernetes` labels; merge groups run core and GPU E2E. |
| `.github/workflows/branch-e2e.yml` | Standard, GPU, Kubernetes HA, and Kubernetes credential-driver E2E. PR mirror pushes use `test:e2e`, `test:e2e-gpu`, and `test:e2e-kubernetes` labels; merge groups do not run E2E. |
| `.github/workflows/build-binaries.yml`, `build-vm-driver.yml` | Shared binary matrices used by branch and release workflows. The VM driver remains separate because its build consumes the runtime binaries. |
| `.github/workflows/build-images.yml` | Builds and pushes multi-platform images, then uploads the same OCI images as workflow artifacts. |
| `.github/workflows/package-release-binaries.yml` | Packages raw build artifacts into release tarballs without rebuilding them. |
Expand Down Expand Up @@ -507,11 +505,14 @@ These workflows run after merge to publish dev/tagged artifacts and verify them.
Require these statuses in the branch ruleset for PR and merge-queue CI:

- `OpenShell / Branch Checks`
- `OpenShell / E2E`
- `OpenShell / GPU E2E`
- `OpenShell / Helm Lint`
- `OpenShell / Trivy Changes`

The following statuses are opt-in and controlled by labels:

- `OpenShell / E2E`: `test:e2e`
- `OpenShell / GPU E2E`: `test:e2e-gpu`

For mirror-based workflows, require the statuses published by
`Required CI Gates`, not their underlying jobs. `OpenShell / Trivy Changes` is
the stable result job of the direct pull-request workflow. Together these
Expand Down
Loading