diff --git a/.github/renovate.json5 b/.github/renovate.json5 index f3bff148..e7e85120 100644 --- a/.github/renovate.json5 +++ b/.github/renovate.json5 @@ -24,12 +24,19 @@ // helpers:pinGitHubActionDigests, which would otherwise pin and then bump // projectbluefin/actions -> itself. SHA pinning is a defence against tag // hijacking on repos we do not control; it does not apply to our own code. - // Keep this rule last so it wins over the automerge rules above. - // Other projectbluefin repos (e.g. testsuite) are cross-repo and stay pinned. + // Keep first-party exemptions after the automerge rules so they win. { "matchManagers": ["github-actions"], "matchPackageNames": ["projectbluefin/actions"], "enabled": false + }, + // Testsuite advances v1 after each successful main-branch merge. Keeping + // the reusable workflow on that managed tag delivers both test and VM + // orchestration fixes to release gates without manual pin alignment. + { + "matchManagers": ["github-actions"], + "matchPackageNames": ["projectbluefin/testsuite"], + "enabled": false } ] } diff --git a/.github/workflows/reusable-execute-release.yml b/.github/workflows/reusable-execute-release.yml index 20b9bbc4..2cfd7418 100644 --- a/.github/workflows/reusable-execute-release.yml +++ b/.github/workflows/reusable-execute-release.yml @@ -122,7 +122,7 @@ jobs: fail-fast: true matrix: variant: ${{ fromJSON(inputs.variants) }} - uses: projectbluefin/testsuite/.github/workflows/e2e.yml@ee2a5b92376054807b32d67128438ff7eed0acc1 # v1 (matches projectbluefin/bluefin run-testsuite.yml pin) + uses: projectbluefin/testsuite/.github/workflows/e2e.yml@v1 with: image: ${{ format('{0}/{1}@{2}', inputs.registry, matrix.variant.image, fromJSON(needs.resolve.outputs.digests)[matrix.variant.image]) }} suites: ${{ inputs.gate_suites }} diff --git a/docs/skills/composite-actions/reusable-workflow.md b/docs/skills/composite-actions/reusable-workflow.md index cfc00a51..083cbd91 100644 --- a/docs/skills/composite-actions/reusable-workflow.md +++ b/docs/skills/composite-actions/reusable-workflow.md @@ -258,7 +258,7 @@ jobs: ### Gate behavior - The gate runs one matrix job per variant, so multi-variant promotions test each image independently. -- The e2e job calls `projectbluefin/testsuite/.github/workflows/e2e.yml` pinned to the current `v1` SHA. +- The e2e job calls `projectbluefin/testsuite/.github/workflows/e2e.yml@v1`. - The image ref passed to testsuite uses the digest resolved in the `resolve` job (`ghcr.io/projectbluefin/@sha256:…`), not the source tag. - Set `run_release_gate: false` only as an emergency escape hatch; changing the default affects every consumer of this reusable workflow. @@ -293,22 +293,29 @@ The legacy semver mode checks out with `fetch-depth: 0` (required by git-cliff), Promotes one or more OCI variants (e.g. `:testing` → `:stable`) for bootc image repos. The workflow resolves the source digest once, optionally runs testsuite e2e against that exact digest, then re-verifies cosign and promotes the same digest to the target tag. The digest is never re-resolved after the gate, eliminating TOCTOU drift between test and promotion. -### Testsuite e2e pin — keep aligned with bluefin's `run-testsuite.yml` +### Testsuite e2e refs — use managed `v1` for both layers -The `release-gate` job calls `projectbluefin/testsuite/.github/workflows/e2e.yml@ # v1`. This pin **must match the SHA in `projectbluefin/bluefin/.github/workflows/run-testsuite.yml` exactly.** The two workflows execute the same testsuite e2e code — bluefin at PR time, the release gate at promotion time. A drift between them means the gate and bluefin CI can disagree on the same image. +The `release-gate` job and Bluefin's `run-testsuite.yml` must both call +`projectbluefin/testsuite/.github/workflows/e2e.yml@v1`. Testsuite advances +that managed tag after each successful main-branch merge. -To verify alignment before merging a change to this workflow: +The reusable workflow's `uses` ref selects the workflow definition, including +VM disk sizing and setup. Its `test_ref` input only selects the test tree that +the workflow checks out. Setting `test_ref: v1` does not deliver workflow-level +fixes when `uses` remains pinned to an older SHA. + +Verify both callers before merging a change to this workflow: ```bash -# The pin in this workflow: grep 'testsuite.*e2e.yml@' .github/workflows/reusable-execute-release.yml -# The pin bluefin uses (the source of truth for the managed @v1 tag): gh api repos/projectbluefin/bluefin/contents/.github/workflows/run-testsuite.yml --jq .content \ | base64 -d | grep 'testsuite.*e2e.yml@' ``` -If they differ, bump this workflow's pin to bluefin's SHA in the same PR. Do not trust the `# v1 (matches ...)` comment — verify the SHAs themselves. The testsuite `v1` tag auto-tracks `main` on every testsuite merge, so the managed tag advances independently of this pin; the pin is the SHA the gate actually executes and must be a deliberate, verified match. +Both commands must report `@v1`. Disable `projectbluefin/testsuite` for +Renovate's `github-actions` manager so `config:best-practices` cannot replace +the managed tag with an immutable digest. ### Gate behavior