feat(actions): support owner-level and global scoped workflows#38154
Open
Zettat123 wants to merge 1 commit into
Open
feat(actions): support owner-level and global scoped workflows#38154Zettat123 wants to merge 1 commit into
Zettat123 wants to merge 1 commit into
Conversation
44b2d78 to
f0788dd
Compare
f0788dd to
d86c6cb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds scoped workflows to Gitea Actions. Workflows defined centrally in a "source" repository that automatically run on every repository in scope: an organization's repositories, or (for instance admins) every repository on the instance. Each scoped run executes in the consuming repository's own context (its runners, secrets, and branch) while its content is read from the source repository, so an org or instance can mandate shared CI across many repositories without copying workflow files into each one.
An owner or instance admin registers source repositories on a settings page and can mark individual workflows as required. A required scoped workflow cannot be opted out by a consuming repository and gates its pull-request merges; an optional one can be disabled per repository. Scoped workflows live under a dedicated
SCOPED_WORKFLOW_DIRS(default.gitea/scoped_workflows), kept separate from regularWORKFLOW_DIRS.Main changes
Configuration
New
SCOPED_WORKFLOW_DIRSsetting, validated to not overlap withWORKFLOW_DIRS. An empty value disables the feature.Data model & migration
action_scoped_workflow_sourcetable mapping a registering owner (owner_id, where0= instance-level) to a source repository, with a per-workflowWorkflowConfigsmap.ActionRungainsWorkflowRepoID/WorkflowCommitSHA(the pinned content source) and anIsScopedRunflag.Detection & run creation
On consumer events, scoped workflows from the effective sources (the owner's own sources plus instance-level ones) are matched and turned into runs that execute in the consumer's context, with content pinned to the source repo's default-branch commit.
on: workflow_runandon: scheduleare currently not supported.Opt-out
A consuming repository can disable an optional scoped workflow (tracked separately from regular
DisabledWorkflows); required scoped workflows can never be disabled, opted out, or bypassed.Commit status
A scoped run's status context format is
"<source repo full name>: <workflow display name> / <job> (<event>)"(for example:
my-org/scoped-workflows: db-tests / test-sqlite (pull_request)),keeping it distinct from a same-named repo-level workflow and from other sources.
Required status checks
Admins mark workflows required and supply status-check patterns.
EffectiveRequiredContextsappends those patterns to the branch protection's required contexts and they are matched must-present-and-pass. If the status checks from scoped workflows fail, the PR cannot be merged.Screenshots
Reusable workflows (
uses:)A scoped workflow's local
uses: ./…resolves against the source repository.uses:directory validation honors the instance-configurableWORKFLOW_DIRSandSCOPED_WORKFLOW_DIRS(previously hardcoded to.gitea/.github/workflows).Manual dispatch
workflow_dispatchis supported for scoped workflows (web and API), resolving inputs/content from the source repo.Performance
A process-local LRU cache keyed by source repo ID for the per-source workflow parse, so instance-level and owner-level sources don't open the source repo and parse workflow files on every event.
UI
Org / user / admin pages to register and remove sources, search repositories, and mark workflows required with their status-check patterns. The repository Actions sidebar groups scoped workflows by source with owner/instance labels and required/disabled badges.
Screenshots
Scoped workflows setting page:
Consumer repo's Actions runs list:
Owner: this is a owner-level scoped workflows source repoGlobal: this is a global scoped workflows source repoRequired: this scoped workflow is required, repo admin cannot disable it