GitHub runs a workflow_run workflow from the default branch only, so a feature branch no longer waits for a merge of master before its reds are posted. record() reads the FAILED run from RED_WATCH_* (id, attempt, workflow, branch, sha, event, url, actor, title, author: the workflow_run payload) and asks the jobs API for that run, not the watcher's own; the inline GITHUB_* shape stays for a branch with the old `red` job (one line per run id either way). The inline job leaves ci.yml. Self-test covers the workflow_run shape and the full line. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
42 lines
2.6 KiB
YAML
42 lines
2.6 KiB
YAML
# The red watcher as its own workflow, on workflow_run, so the copy on master watches EVERY branch's ci run whatever
|
|
# ci.yml that branch carries: GitHub runs a workflow_run workflow from the default branch only, and the branch's own
|
|
# ci.yml never enters it (7 October 2026: the inline `red` job of ci.yml was conditioned on master and release-*, and
|
|
# a feature branch would have waited for a merge of master before its reds were posted at all).
|
|
#
|
|
# One line per failed run (tools/ci/red-watch.mjs record, idempotent per run attempt) to /srv/ci-red/red.jsonl on the
|
|
# box; the box's igneum-ci-red.timer posts each new line once to the hidden updates channel, naming the branch, the
|
|
# commit, the red check and the pushing author. Runs on the box's own runner (not a GitHub-hosted machine: the billing
|
|
# block of 6 October 2026, 18:37Z to 20:10Z, failed every hosted job at start and nobody was told). Never blocks a
|
|
# release: it reads the run, writes one line, and ends.
|
|
name: ci-red
|
|
on:
|
|
workflow_run:
|
|
workflows: [ci]
|
|
types: [completed]
|
|
jobs:
|
|
red:
|
|
name: red watcher (every branch; one line per failed run, with the branch, commit, red check and pushing author, to the updates channel and the box file)
|
|
if: ${{ github.event.workflow_run.conclusion == 'failure' }}
|
|
runs-on: [self-hosted, linux, x64, igneum-build-1]
|
|
timeout-minutes: 5
|
|
permissions:
|
|
actions: read # the failed run's jobs API (the first real red run, 21:19Z on 6 October: the default token answered 403 and the line carried no step)
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
sparse-checkout: tools/ci
|
|
- name: record the failed run (one line, the branch, the commit, the failed jobs and their first failed step from the run's own API, the pushing author)
|
|
env:
|
|
GITHUB_TOKEN: ${{ github.token }}
|
|
RED_WATCH_RUN_ID: ${{ github.event.workflow_run.id }}
|
|
RED_WATCH_ATTEMPT: ${{ github.event.workflow_run.run_attempt }}
|
|
RED_WATCH_WORKFLOW: ${{ github.event.workflow_run.name }}
|
|
RED_WATCH_BRANCH: ${{ github.event.workflow_run.head_branch }}
|
|
RED_WATCH_SHA: ${{ github.event.workflow_run.head_sha }}
|
|
RED_WATCH_EVENT: ${{ github.event.workflow_run.event }}
|
|
RED_WATCH_URL: ${{ github.event.workflow_run.html_url }}
|
|
RED_WATCH_ACTOR: ${{ github.event.workflow_run.actor.login }}
|
|
RED_WATCH_TITLE: ${{ github.event.workflow_run.head_commit.message }}
|
|
RED_WATCH_AUTHOR: ${{ github.event.workflow_run.head_commit.author.name }}
|
|
run: node tools/ci/red-watch.mjs record --file /srv/ci-red/red.jsonl
|