Files
hermes-agent/.github/workflows/archive-inputs.yml
ethernet 3dc75f5ab7 ci: skip R2-dependent jobs when release-signing secrets are absent
archive-inputs (push to main on pm/lock.json), the nightly canary R2
prune and termux-verify's bionic runtime job all called
r2.credentials(), which exits 2 on a missing CLOUDFLARE_R2_* env. On a
repo without the release-signing environment provisioned, merging this
branch would turn main red on the first push and the nightly red daily.

A job-level `if` cannot read `secrets`, so the gates use the documented
shapes: single-step consumers expose the secret through the job env and
test `env.CLOUDFLARE_R2_ACCOUNT_ID` in the step `if`; the multi-step
termux job is gated by a job that outputs a provisioned flag. A stable
release candidate (inputs.release) still runs and fails loudly.

termux-verify also triggered on a personal branch (ethie/cli-bundles)
and a test glob that no longer exists; it now runs on main pushes and
PRs touching the Termux paths.
2026-09-21 18:37:10 -04:00

50 lines
1.8 KiB
YAML

name: Archive pinned PM inputs
on:
push:
branches: [main]
paths:
- 'pm/lock.json'
- 'pm/artifact-mirror.json'
- 'scripts/termux/runtime_libs.json'
- 'scripts/ci/archive_inputs.py'
- '.github/workflows/archive-inputs.yml'
workflow_call:
inputs:
sha:
description: 'The admitted commit whose pins are archived.'
required: true
type: string
workflow_dispatch:
permissions:
contents: read
jobs:
archive-inputs:
name: Preserve every pinned HTTP input
if: github.event_name != 'pull_request' && github.event_name != 'pull_request_target'
runs-on: ubuntu-24.04
environment: release-signing
timeout-minutes: 60
env:
CLOUDFLARE_R2_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_R2_ACCOUNT_ID }}
CLOUDFLARE_R2_ACCESS_KEY_ID: ${{ secrets.CLOUDFLARE_R2_ACCESS_KEY_ID }}
CLOUDFLARE_R2_SECRET_ACCESS_KEY: ${{ secrets.CLOUDFLARE_R2_SECRET_ACCESS_KEY }}
CLOUDFLARE_R2_BUCKET: ${{ vars.CLOUDFLARE_R2_BUCKET }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
ref: ${{ inputs.sha || github.sha }}
persist-credentials: false
# Runner Python is intentional: the toolchain's upstream may be gone.
# A job-level `if` cannot read `secrets`; the job env can. Forks and a
# repo whose release-signing environment is not provisioned yet must
# skip the archive, not turn main red.
- name: Verify and archive every pinned input
if: env.CLOUDFLARE_R2_ACCOUNT_ID != ''
run: python3 -m scripts.ci.archive_inputs
- name: Report the unprovisioned archive
if: env.CLOUDFLARE_R2_ACCOUNT_ID == ''
run: echo "::notice::CLOUDFLARE_R2_* secrets are not configured; pinned inputs were not archived."