Skip to content

fix(ci): take the two hosted-runner builds off the PR rail (#11946, option 3) - #11962

Merged
diegosouzapw merged 1 commit into
release/v3.8.51from
fix/ci-11946-hosted-build-rail
Aug 29, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.51from
fix/ci-11946-hosted-build-rail

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Opção 3 do #11946, adaptada ao que os dados mostraram

  • O runner hospedado (7 GB) não builda a release/v3.8.51 em nenhum perfil: Build App morreu em 19/30 runs (a própria branch incluída) ~8 min dentro do next build, com swapfile de 10 GB; o Build (advisory) do quality.yml (mesma receita) falhou em 8/8 PRs de fork recentes; e o DAST smoke (PR) morre no passo "Build CLI bundle" (que é um next build backend-only) ~7 min depois, antes de o servidor subir — escondido como check advisory permanentemente vermelho.
  • A ideia original de "dast consumir o artefato do ci.yml" não se aplica a PRs de release: o ci.yml só roda em main. Não há artefato para consumir lá.

O que muda

workflow antes depois
build.yml (Fast Production Build) push em toda branch, build:release completo, artefato que ninguém baixa só workflow_dispatch
dast-smoke.yml (DAST smoke (PR)) PRs para main e release/** PRs para main (onde builda em ~5,5 min) + workflow_dispatch
quality.yml — só o comentário do Build (advisory) (fork-only) atualizado; comportamento igual

Trade-off (explícito)

PRs de branch própria para release/** ficam sem build pré-merge — que já não vinha passando. O bundle continua validado pelo ci.yml (Build, pool omni-build) em todo merge na main e pelo nightly-release-green (mesmo pool) na release/**, que abre issue base-red em até um dia se um merge quebrar o build.

Achado colateral (follow-up, não nesta PR)

nightly-schemathesis, nightly-llm-security e nightly-resilience também fazem next build backend-only em ubuntu-latest → muito provavelmente mortos na .51 sem ninguém ver. Candidato natural ao pool omni-build (1×/dia, carga baixa) — decisão do dono.

Validação

check:workflows --ratchet sem regressão (194/194); check-workflows.test.ts 32/32; backend-only-smoke-workflows.test.ts 6/6; prettier limpo.

Closes #11946

…ption 3)

The hosted 7 GB runner cannot build release/v3.8.51 in any profile: `Build App`
(build.yml, push on every branch, full `build:release`) died in 19 of the last 30
runs — the branch tip included — with "The runner has received a shutdown signal"
~8 min into `next build`, swapfile and all; the advisory quality.yml build failed on
8/8 recent fork PRs with the same recipe; and `DAST smoke (PR)`'s backend-only build
died ~7 min in before the server even started, hidden as a permanently red
continue-on-error check. Together they painted every PR into release/** red with
zero signal and, on build.yml, produced an artefact nothing downloads.

- build.yml: workflow_dispatch only. The bundle is validated where a build fits —
  ci.yml `Build` on the self-hosted omni-build pool after every merge to main, and
  nightly-release-green.yml on the same pool for release/**.
- dast-smoke.yml: pull_request into main only (plus workflow_dispatch to smoke a
  release branch by hand); main's tree still builds on the hosted runner in ~5.5 min.
- quality.yml: the fork-only rationale of `Build (advisory)` updated to say why
  own-origin PRs no longer get a hosted build either. Behaviour unchanged.

check:workflows --ratchet: 194 zizmor findings, baseline 194. check-workflows and
backend-only-smoke-workflows suites pass. Trade-off stated in the PR: own-origin PRs
into release/** lose a pre-merge build that was not succeeding anyway; the nightly
rail files a base-red issue within a day if a merge breaks the build.
@diegosouzapw
diegosouzapw merged commit d7cdfca into release/v3.8.51 Aug 29, 2026
30 of 31 checks passed
@diegosouzapw
diegosouzapw deleted the fix/ci-11946-hosted-build-rail branch August 29, 2026 01:52
Bl0ck154 pushed a commit to Bl0ck154/OmniRoute that referenced this pull request Sep 20, 2026
…apw#11946, option 3) (diegosouzapw#11962)

The hosted 7 GB runner cannot build release/v3.8.51 in any profile: `Build App`
(build.yml, push on every branch, full `build:release`) died in 19 of the last 30
runs — the branch tip included — with "The runner has received a shutdown signal"
~8 min into `next build`, swapfile and all; the advisory quality.yml build failed on
8/8 recent fork PRs with the same recipe; and `DAST smoke (PR)`'s backend-only build
died ~7 min in before the server even started, hidden as a permanently red
continue-on-error check. Together they painted every PR into release/** red with
zero signal and, on build.yml, produced an artefact nothing downloads.

- build.yml: workflow_dispatch only. The bundle is validated where a build fits —
  ci.yml `Build` on the self-hosted omni-build pool after every merge to main, and
  nightly-release-green.yml on the same pool for release/**.
- dast-smoke.yml: pull_request into main only (plus workflow_dispatch to smoke a
  release branch by hand); main's tree still builds on the hosted runner in ~5.5 min.
- quality.yml: the fork-only rationale of `Build (advisory)` updated to say why
  own-origin PRs no longer get a hosted build either. Behaviour unchanged.

check:workflows --ratchet: 194 zizmor findings, baseline 194. check-workflows and
backend-only-smoke-workflows suites pass. Trade-off stated in the PR: own-origin PRs
into release/** lose a pre-merge build that was not succeeding anyway; the nightly
rail files a base-red issue within a day if a merge breaks the build.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…apw#11946, option 3) (diegosouzapw#11962)

The hosted 7 GB runner cannot build release/v3.8.51 in any profile: `Build App`
(build.yml, push on every branch, full `build:release`) died in 19 of the last 30
runs — the branch tip included — with "The runner has received a shutdown signal"
~8 min into `next build`, swapfile and all; the advisory quality.yml build failed on
8/8 recent fork PRs with the same recipe; and `DAST smoke (PR)`'s backend-only build
died ~7 min in before the server even started, hidden as a permanently red
continue-on-error check. Together they painted every PR into release/** red with
zero signal and, on build.yml, produced an artefact nothing downloads.

- build.yml: workflow_dispatch only. The bundle is validated where a build fits —
  ci.yml `Build` on the self-hosted omni-build pool after every merge to main, and
  nightly-release-green.yml on the same pool for release/**.
- dast-smoke.yml: pull_request into main only (plus workflow_dispatch to smoke a
  release branch by hand); main's tree still builds on the hosted runner in ~5.5 min.
- quality.yml: the fork-only rationale of `Build (advisory)` updated to say why
  own-origin PRs no longer get a hosted build either. Behaviour unchanged.

check:workflows --ratchet: 194 zizmor findings, baseline 194. check-workflows and
backend-only-smoke-workflows suites pass. Trade-off stated in the PR: own-origin PRs
into release/** lose a pre-merge build that was not succeeding anyway; the nightly
rail files a base-red issue within a day if a merge breaks the build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: Fast Production Build + dast-smoke (hosted 7 GB) OOM on release/v3.8.51 — 19/30 red, paints every PR

1 participant