Skip to content

Stop provisioning GitHub integration-test credentials in CI - #21631

Merged
kylos101 merged 4 commits into
mainfrom
kb/remove-github-user-token-from-integration-tests
Oct 2, 2026
Merged

kylos101 merged 4 commits into
mainfrom
kb/remove-github-user-token-from-integration-tests

Conversation

@kylos101

@kylos101 kylos101 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Stop provisioning GitHub test-user credentials in CI so integration runs do not depend on that credential. Preserve the original tests, helpers, and manual commands; tests requiring credentials skip when they are absent.

Add the missing username guard to the disk test and retain the Go 1.25 formatting fixes. CI validation also exposed a process-limit assertion that inspected only stdout: inspect stderr too, where bash writes fork diagnostics, while retaining the required error check.

Related Issue(s)

None.

How to test

  • Workspace suite: passed on 84cabdac3: 32 passed, 13 expected skips, zero failures; both maintenance checks passed separately. Confirmed all ten GitHub-context-dependent workspace entry points skipped. Cgroup and process-limit checks passed.
  • Webapp suite: passed: server user lookup and builtin database user checks passed; two expected skips. The subsequent commit changes only the workspace process-limit assertion.
  • Workspace validation used Branch Build with the existing on-demand preview option. Standalone attempts hit deployment/Spot-capacity problems; a reused-preview retry rejected its object-storage key. The successful run used a fresh preview after cleanup.
  • All affected Go suites compile. Isolated credential-guard checks confirm 24 entry points skip without username/token, with no Git operations. Runner checks confirm explicit manual credentials are preserved and failures propagate.
  • A bounded local process-limit reproduction confirmed the fork diagnostic is on stderr and the corrected assertion detects it.
  • Formatting, golangci-lint for new issues, actionlint for the integration workflows, and pre-commit passed. IDE/default smoke workflows were not dispatched because their absent-credential paths provide no functional coverage.

Documentation

No public documentation changes required. Integration test documentation is updated.

Preview status

Disposable validation previews were removed. Final cleanup passed.

Build Options

Build
  • /werft with-werft
    Run the build with werft instead of GHA
  • leeway-no-cache
  • /werft no-test
    Run Leeway with --dont-test
Publish
  • /werft publish-to-npm
  • /werft publish-to-jb-marketplace
Installer
  • analytics=segment
  • with-dedicated-emulation
  • workspace-feature-flags
    Add desired feature flags to the end of the line above, space separated
Preview Environment / Integration Tests
  • /werft with-local-preview
    If enabled this will build install/preview
  • /werft with-preview
  • /werft with-large-vm
  • /werft with-gce-vm
    If enabled this will create the environment on GCE infra
  • /werft preemptible
    Saves cost. Untick this only if you're really sure you need a non-preemtible machine.
  • with-integration-tests=workspace
    Valid options are all, workspace, webapp, ide, jetbrains, vscode, ssh. If enabled, with-preview and with-large-vm will be enabled.
  • with-monitoring

/hold

Co-authored-by: Codex <noreply@openai.com>
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:15 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:15 — with GitHub Actions Active
Comment on lines -30 to -35
integration_test_username:
description: "The username for integration test"
required: true
integration_test_usertoken:
description: "The username for integration test"
required: true

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ditch the dependency on Github PAT

Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
@kylos101 kylos101 changed the title Remove GitHub user-token dependency from integration tests Stop provisioning GitHub integration-test credentials in CI Oct 1, 2026
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:34 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:34 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:34 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:36 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 17:47 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:03 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:22 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:22 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:22 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:24 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 18:34 — with GitHub Actions Active
Co-authored-by: Codex <noreply@openai.com>
@kylos101
kylos101 deployed to branch-build October 1, 2026 19:29 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 19:29 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 19:29 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 19:31 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 19:43 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:17 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:17 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:17 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:21 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:28 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 20:43 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 21:09 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 21:09 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 21:20 — with GitHub Actions Active
@kylos101
kylos101 deployed to branch-build October 1, 2026 21:20 — with GitHub Actions Active
@kylos101
kylos101 marked this pull request as ready for review October 2, 2026 12:17
@kylos101
kylos101 requested a review from a team as a code owner October 2, 2026 12:17
@kylos101
kylos101 merged commit 7a91bca into main Oct 2, 2026
49 of 50 checks passed
@kylos101
kylos101 deleted the kb/remove-github-user-token-from-integration-tests branch October 2, 2026 12:17

This branch was successfully deployed

1 active deployment
branch-build — 84cabdac Deployed Oct 1, 2026 by kylos101 via Build Gitpod #379
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants