Repository navigation
chore(ci): delete the jobs that run on the self-hosted runners (ENG-2000) - #7
Open
lucas-koontz wants to merge 1 commit into
Open
lucas-koontz wants to merge 1 commit into
lucas-koontz wants to merge 1 commit into
Conversation
…000) This change deletes every job that asks for mdb-dev or mdb-prod, along with four workflows built around those jobs. Every remaining job runs on a GitHub-hosted runner, which GitHub recommends for public repositories. Pull requests, forks included, still run the unit tests. The four deleted workflows: - deploy.yml and tests_integration.yml ran only on mdb-dev or mdb-prod. - build_deploy_staging.yml built and pushed the Docker images after each merge, then deployed and tested through those two files. Its one hosted job ran the unit tests after the merge. - build_deploy_prod.yml was the release pipeline. On a published release it pushed the mindsdb package to PyPI and Docker Hub, then deployed it. Its one hosted job ran the unit tests ahead of those steps. This repository has no published releases. build_deploy_dev.yml keeps the changed-files filter, the unit tests and All Tests Succeeded. Its workflow is renamed "Test pull request", because it no longer builds or deploys anything. - A pull request that changes only files under docs/ or assets/, or only Markdown files, still skips the unit tests. Every other change runs them. - A version bump in mindsdb/__about__.py now runs the unit tests, because setup.py builds the package from that file. Until now, the deleted post-merge run was the only test a version bump got. - An edit to build_deploy_dev.yml alone now runs the unit tests too. The filter also drops an exclusion for test_on_deploy.yml, a file that does not exist. - All Tests Succeeded fails when the filter job fails or is cancelled. It also fails when the filter sends a change to the unit tests and they do not pass. - The write permissions move from the whole workflow onto the unit-test call, because tests_unit.yml asks for them. The filter and the final check get read access only. - dorny/paths-filter is pinned to the v3.0.4 commit that v3 points to. - The unit-test call stops inheriting secrets, because tests_unit.yml reads none. scripts/run_integration_tests.sh no longer points at the deleted tests_integration.yml. Part of "Take the public repos off the credentialed runner group and require devops to release a privileged run", owned by Lucas Koontz. Refs: ENG-2000
This was referenced Oct 4, 2026
Draft
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User story
As a maintainer of this public repository
I want CI to test every pull request on GitHub-hosted runners, and nothing to build, deploy or publish on a merge or a release
So that every pull request, forks included, gets the same checks, and a merge no longer ends in a red run
Why this matters
Each of the last three merges into
mainended in a redBuild and deploy to stagingrun: it built and pushed Docker images, then its deploy jobs failed before running a step (run 34555473260). This PR deletes that pipeline and the release pipeline, and keeps the unit tests on every pull request, on GitHub-hosted runners, as GitHub recommends for public repositories. A version bump now runs those tests before it merges, where until now only the deleted post-merge run tested it.Acceptance criteria
mainasks formdb-devormdb-prod, directly or through a called workflow, and every remaining job runs on a GitHub-hosted runner.main, forks included, runsRun Unit Testsunless every file it changes is underdocs/orassets/, or is a Markdown file.mindsdb/__about__.pyrunsRun Unit Tests, includingCheck pip installation.All Tests Succeededfails whenFilter changed filesfails or is cancelled, and when the filter sends a change to the unit tests and they do not pass.docs/orassets/, skipsRun Unit Tests, andAll Tests Succeededpasses.tests_unit.yml,matrix_includes.jsonand the other remaining workflows are unchanged.How to test
Start as a maintainer with write access to mindsdb/engine, with this PR open.
Test pull requestrun withFilter changed files,Run Unit TestsandAll Tests Succeeded.Run Unit Testsstarts its jobs, which shows GitHub accepts the new permissions block. They run Python 3.11 onubuntu-latest,windows-latestandmacos-latest. NoGet Deploy Envs,Build Docker Images,Scan cloud-cpu imageorPush Docker Cachejob appears.README.md. ExpectRun Unit Teststo be skipped andAll Tests Succeededto pass. Close the draft.__version__ = "26.2.0"inmindsdb/__about__.py, for example to"26.2.1". ExpectRun Unit Teststo run, includingCheck pip installation. Close the draft.MindsDB CLA Assistantand noBuild and deploy to stagingrun.git fetch origin main && git grep -nE 'mdb-dev|mdb-prod|self-hosted' origin/main -- .github. Expect no output. This covers the paths no pull request run exercises, such as a published release.Notes for the reviewer
The red unit-test check comes from dependency drift, not from this change. On this PR's run (37180001834), test collection fails on
tests/unit/handlers/test_snowflake.pywithAttributeError: module 'sqlalchemy.orm.context' has no attribute 'ORMSelectCompileState', soAll Tests Succeededgoes red. The same matrix passed on 2026-09-10 (mindsdb/engine run 34439817062). This PR changes no dependency, test ortests_unit.ymlfile; editingbuild_deploy_dev.ymlis what makes the full matrix run here.mainrequires no status check, so the red check does not block the merge.Merge order: this PR depends on no other change. It can merge any time before the operator's final step, which happens outside these repositories. mindsdb/data-vault gets the same diff and the same commit message in its own PR.
Operator steps: none. After the merge, nothing in this repository reads the
deploy-to-devanddeploy-to-alpha-devlabels or thealpha-dev,devandstagingenvironments. Deleting them is a separate cleanup, not part of this PR.github-pagesstays, becausedocs.ymldeploys to it.Rollback: revert this PR's commit on
main. That restores the four workflows and the old filter exactly as they were. The merge changes nothing outside this repository, so nothing else needs undoing.The post-merge unit-test run is deleted, not kept.
build_deploy_staging.ymlrantests_unit.ymlafter each merge, andtests_unit.ymlchecks out the pull request's head commit, not the merge commit. So for every pull request the filter sends to the unit tests, it repeated that pull request's own run on the same commit and matrix. The one case it alone covered, a version bump, now runs the tests before merge. A pull request that changes only docs, images or Markdown now gets no unit-test run at all. Of those files, the package build reads onlyREADME.md, whichsetup.pyuses aslong_description.The release pipeline goes as a whole.
build_deploy_prod.ymlran the unit tests only to gate the PyPI, Docker Hub and deploy jobs, which this PR deletes. This repository has no published releases. Publishing releases again would need a new pipeline.A version bump now runs the unit tests before it merges. The filter counted a change to
mindsdb/__about__.pyalone as docs-only.setup.pyreads the version from that file, andCheck pip installationbuilds and installs the package, so a broken bump fails there. An edit tobuild_deploy_dev.ymlalone runs the tests too, because that file now does nothing else.All Tests Succeedednow fails when the filter job fails or is cancelled. Before, a failed filter left its output empty, so the exit step was skipped and the check went green with nothing tested. One visible side effect: when a newer push cancels a run before its filter finishes, the cancelled run shows a redAll Tests Succeeded. The newer run on the same pull request replaces it.Write permissions moved from the whole workflow onto the unit-test call.
tests_unit.ymldeclarespull-requests,pagesandid-tokenwrite, and a called workflow can only keep or lower what its caller grants. The filter and the final check now get read access only. The unit-test call also stops inheriting secrets, becausetests_unit.ymlreads none.dorny/paths-filteris pinned to commit0e4a8c6. That is the commitv3points to today, taggedv3.0.4, so the code that runs does not change.Only the workflow's display name changes. It is now
Test pull request. The file staysbuild_deploy_dev.yml, so its run history stays in one place.All Tests Succeededkeeps its job id and name, so anything that matches the check by name still finds it.The
labeledtrigger stays.tests_unit.ymlpublishes a coverage report when a pull request carries apublish_artifactslabel, and adding the label is what starts that run.Some files lose their CI caller and stay in place.
tests/scripts/check_version.pyserved only the release pipeline.docker/docker-bake.hcl, the Makefile's integration-test targets andscripts/run_integration_tests.shstay for local use.Verified locally
actionlint1.7.12, changed filebuild_deploy_dev.ymlis clean.actionlint1.7.12, whole workflow folderadd_to_pr_review.yml(2),release_notes.yml(4) andtests_unit.yml(2). The other 21 were in the deleted files and jobs, 16 of them unknown runner labels.zizmor1.28.0, regular persona, offlinebuild_deploy_dev.ymlgoes from 17 findings on base (11 high, 6 medium) to none. Both sides suppress 2 more.dot: trueand theeveryquantifier, aspaths-filterv3.0.4 does. A version bump, an edit tobuild_deploy_dev.ymlalone, and a docs change plus a version bump go from skip to run. A docs page, the root README, a handler README and an image still skip. Python code,tests_unit.ymland this PR's own file list run on both.All Tests Succeededcondition@actions/expressions0.3.61, GitHub's expression library, in 7 cases without a deploy label. They agree on docs-only, passing, failing and cancelled tests. A failed or cancelled filter job passed on base and fails now.needsnames an existing job, and every localusesresolves. Everyruns-onisubuntu-latestor a hosted label frommatrix_includes.json, and the CLA workflow's called job runs onubuntu-latest.git grepfinds nomdb-dev,mdb-prod,self-hosted,deploy-to-*label, deleted file name or old workflow name.7a160d8.dorny/paths-filterpingh api, 2026-10-03: tagv3dereferences to0e4a8c6effa4802afeda77dc8d303f8176d7dfad, the commit taggedv3.0.4.scripts/run_integration_tests.shbash -nandshellcheck -S warningare clean.origin/mainShips with
Part of ENG-2000.
Merge order
argocd-pr-env-deployto the github-actions merge commit from step 2. The operator also creates the deployer's GitHub App and sets its client ID and private key in thestagingandprodenvironments of cowork and cowork-server.staging. mindsdb/minds_python_sdk#90, this PR, mindsdb/data-vault#4 and mindsdb/hashnode-starter-kit#39 merge intomain. These four depend on no other step.stagingtag, mindsdb/scratchpad-controller#80 and mindsdb/argocd-envs#25 merge.stagingtomainin their next release.mainbuilds push through the prod writer roles.mainandstaging.Sibling PRs, in merge order:
build-push-ecrgainsbuilder: localfor GitHub-hosted builds, andargocd-pr-env-deploytakes the pull request as inputs and checks its image in the dev tier.