Skip to content

chore(ci): delete the jobs that run on the self-hosted runners (ENG-2000) - #7

Open
lucas-koontz wants to merge 1 commit into
mainfrom
fix/eng-2000-drop-self-hosted-jobs
Open

lucas-koontz wants to merge 1 commit into
mainfrom
fix/eng-2000-drop-self-hosted-jobs

Conversation

@lucas-koontz

@lucas-koontz lucas-koontz commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

User story

As a maintainer of this public repository
I want CI to test every pull request on GitHub-hosted runners, and nothing to build, deploy or publish on a merge or a release
So that every pull request, forks included, gets the same checks, and a merge no longer ends in a red run

Why this matters

Each of the last three merges into main ended in a red Build and deploy to staging run: it built and pushed Docker images, then its deploy jobs failed before running a step (run 34555473260). This PR deletes that pipeline and the release pipeline, and keeps the unit tests on every pull request, on GitHub-hosted runners, as GitHub recommends for public repositories. A version bump now runs those tests before it merges, where until now only the deleted post-merge run tested it.

Acceptance criteria

  • After this merges, no workflow on main asks for mdb-dev or mdb-prod, directly or through a called workflow, and every remaining job runs on a GitHub-hosted runner.
  • A pull request into main, forks included, runs Run Unit Tests unless every file it changes is under docs/ or assets/, or is a Markdown file.
  • A pull request that changes only mindsdb/__about__.py runs Run Unit Tests, including Check pip installation.
  • All Tests Succeeded fails when Filter changed files fails or is cancelled, and when the filter sends a change to the unit tests and they do not pass.
  • Negative: a pull request that changes only Markdown files, or only files under docs/ or assets/, skips Run Unit Tests, and All Tests Succeeded passes.
  • Negative: merging a pull request or publishing a release starts no build, deploy or publish job.
  • Negative: tests_unit.yml, matrix_includes.json and the other remaining workflows are unchanged.

How to test

Start as a maintainer with write access to mindsdb/engine, with this PR open.

  1. Open this PR's Checks tab. Expect one Test pull request run with Filter changed files, Run Unit Tests and All Tests Succeeded. Run Unit Tests starts its jobs, which shows GitHub accepts the new permissions block. They run Python 3.11 on ubuntu-latest, windows-latest and macos-latest. No Get Deploy Envs, Build Docker Images, Scan cloud-cpu image or Push Docker Cache job appears.
  2. Open a draft PR from a branch in this repository that changes one line of README.md. Expect Run Unit Tests to be skipped and All Tests Succeeded to pass. Close the draft.
  3. Open a draft PR that changes only __version__ = "26.2.0" in mindsdb/__about__.py, for example to "26.2.1". Expect Run Unit Tests to run, including Check pip installation. Close the draft.
  4. Merge this PR, then open the Actions tab. Expect the merge to start MindsDB CLA Assistant and no Build and deploy to staging run.
  5. Run git fetch origin main && git grep -nE 'mdb-dev|mdb-prod|self-hosted' origin/main -- .github. Expect no output. This covers the paths no pull request run exercises, such as a published release.

Notes for the reviewer

The red unit-test check comes from dependency drift, not from this change. On this PR's run (37180001834), test collection fails on tests/unit/handlers/test_snowflake.py with AttributeError: module 'sqlalchemy.orm.context' has no attribute 'ORMSelectCompileState', so All Tests Succeeded goes red. The same matrix passed on 2026-09-10 (mindsdb/engine run 34439817062). This PR changes no dependency, test or tests_unit.yml file; editing build_deploy_dev.yml is what makes the full matrix run here. main requires no status check, so the red check does not block the merge.

Merge order: this PR depends on no other change. It can merge any time before the operator's final step, which happens outside these repositories. mindsdb/data-vault gets the same diff and the same commit message in its own PR.

Operator steps: none. After the merge, nothing in this repository reads the deploy-to-dev and deploy-to-alpha-dev labels or the alpha-dev, dev and staging environments. Deleting them is a separate cleanup, not part of this PR. github-pages stays, because docs.yml deploys to it.

Rollback: revert this PR's commit on main. That restores the four workflows and the old filter exactly as they were. The merge changes nothing outside this repository, so nothing else needs undoing.

The post-merge unit-test run is deleted, not kept. build_deploy_staging.yml ran tests_unit.yml after each merge, and tests_unit.yml checks out the pull request's head commit, not the merge commit. So for every pull request the filter sends to the unit tests, it repeated that pull request's own run on the same commit and matrix. The one case it alone covered, a version bump, now runs the tests before merge. A pull request that changes only docs, images or Markdown now gets no unit-test run at all. Of those files, the package build reads only README.md, which setup.py uses as long_description.

The release pipeline goes as a whole. build_deploy_prod.yml ran the unit tests only to gate the PyPI, Docker Hub and deploy jobs, which this PR deletes. This repository has no published releases. Publishing releases again would need a new pipeline.

A version bump now runs the unit tests before it merges. The filter counted a change to mindsdb/__about__.py alone as docs-only. setup.py reads the version from that file, and Check pip installation builds and installs the package, so a broken bump fails there. An edit to build_deploy_dev.yml alone runs the tests too, because that file now does nothing else.

All Tests Succeeded now fails when the filter job fails or is cancelled. Before, a failed filter left its output empty, so the exit step was skipped and the check went green with nothing tested. One visible side effect: when a newer push cancels a run before its filter finishes, the cancelled run shows a red All Tests Succeeded. The newer run on the same pull request replaces it.

Write permissions moved from the whole workflow onto the unit-test call. tests_unit.yml declares pull-requests, pages and id-token write, and a called workflow can only keep or lower what its caller grants. The filter and the final check now get read access only. The unit-test call also stops inheriting secrets, because tests_unit.yml reads none.

dorny/paths-filter is pinned to commit 0e4a8c6. That is the commit v3 points to today, tagged v3.0.4, so the code that runs does not change.

Only the workflow's display name changes. It is now Test pull request. The file stays build_deploy_dev.yml, so its run history stays in one place. All Tests Succeeded keeps its job id and name, so anything that matches the check by name still finds it.

The labeled trigger stays. tests_unit.yml publishes a coverage report when a pull request carries a publish_artifacts label, and adding the label is what starts that run.

Some files lose their CI caller and stay in place. tests/scripts/check_version.py served only the release pipeline. docker/docker-bake.hcl, the Makefile's integration-test targets and scripts/run_integration_tests.sh stay for local use.

Verified locally

Check What I observed
actionlint 1.7.12, changed file build_deploy_dev.yml is clean.
actionlint 1.7.12, whole workflow folder 29 findings on base, 8 on this branch. The 8 already exist on base, in files this PR does not touch: add_to_pr_review.yml (2), release_notes.yml (4) and tests_unit.yml (2). The other 21 were in the deleted files and jobs, 16 of them unknown runner labels.
zizmor 1.28.0, regular persona, offline build_deploy_dev.yml goes from 17 findings on base (11 high, 6 medium) to none. Both sides suppress 2 more.
Changed-files filter I ran the base and branch patterns through picomatch 2.3.1 with dot: true and the every quantifier, as paths-filter v3.0.4 does. A version bump, an edit to build_deploy_dev.yml alone, and a docs change plus a version bump go from skip to run. A docs page, the root README, a handler README and an image still skip. Python code, tests_unit.yml and this PR's own file list run on both.
All Tests Succeeded condition I evaluated the base and branch conditions with @actions/expressions 0.3.61, GitHub's expression library, in 7 cases without a deploy label. They agree on docs-only, passing, failing and cancelled tests. A failed or cancelled filter job passed on base and fails now.
Remaining workflows 7 workflows. Every needs names an existing job, and every local uses resolves. Every runs-on is ubuntu-latest or a hosted label from matrix_includes.json, and the CLA workflow's called job runs on ubuntu-latest.
Leftover references git grep finds no mdb-dev, mdb-prod, self-hosted, deploy-to-* label, deleted file name or old workflow name.
Callers in other repositories GitHub code search across the org finds the deleted workflows' paths and names only in their own files, here and in mindsdb/data-vault.
Post-merge and pull request matrices Post-merge run 34555473260 and pull request run 34439817062 ran the same three Python 3.11 entries on commit 7a160d8.
dorny/paths-filter pin gh api, 2026-10-03: tag v3 dereferences to 0e4a8c6effa4802afeda77dc8d303f8176d7dfad, the commit tagged v3.0.4.
pre-commit, the repository's own config On the changed files, check yaml, large files and merge conflicts pass. ruff and check toml have no files to check.
scripts/run_integration_tests.sh bash -n and shellcheck -S warning are clean.
Pre-PR sweep against origin/main No whitespace errors, ids in added comments or debug leftovers.

Ships with

Part of ENG-2000.

Merge order

  1. mindsdb/terraform#239 merges, and the operator applies it: the GitHub OIDC providers, the image build and installer upload roles, the dev-tier image repositories and the deployment environment settings.
  2. mindsdb/github-actions#71 merges.
  3. The operator creates mindsdb/deployer, a new private repository, and the deployer PR opens then. That PR merges once it re-pins argocd-pr-env-deploy to the github-actions merge commit from step 2. The operator also creates the deployer's GitHub App and sets its client ID and private key in the staging and prod environments of cowork and cowork-server.
  4. mindsdb/anton#526, mindsdb/cowork#1117 and mindsdb/cowork-server#621 merge into staging. mindsdb/minds_python_sdk#90, this PR, mindsdb/data-vault#4 and mindsdb/hashnode-starter-kit#39 merge into main. These four depend on no other step.
  5. Once each dev-tier image repository holds its staging tag, mindsdb/scratchpad-controller#80 and mindsdb/argocd-envs#25 merge.
  6. anton, cowork and cowork-server each promote staging to main in their next release.
  7. mindsdb/terraform#240 applies once the main builds push through the prod writer roles.
  8. mindsdb/Kubernetes-Foundational-Services#166 merges, and the operator upgrades it on both clusters, once cowork-server's change is on main and staging.
  9. The operator finishes with one step outside these repositories.

Sibling PRs, in merge order:

  • mindsdb/terraform#239: creates the GitHub OIDC providers, the image build and installer upload roles and the dev-tier image repositories, and sets up the deployment environments.
  • mindsdb/github-actions#71: build-push-ecr gains builder: local for GitHub-hosted builds, and argocd-pr-env-deploy takes the pull request as inputs and checks its image in the dev tier.
  • mindsdb/deployer, a new private repository whose PR opens in step 3: rolls cowork and cowork-server out to staging and prod, and syncs their PR environments.
  • mindsdb/anton#526: builds the scratchpad image on GitHub-hosted runners, and pushes pull request and staging builds to the dev tier.
  • mindsdb/cowork#1117: runs every cowork job on GitHub-hosted runners, and rolls staging and prod out through mindsdb/deployer.
  • mindsdb/cowork-server#621: runs every job on GitHub-hosted runners, and deploys staging and prod through mindsdb/deployer.
  • mindsdb/minds_python_sdk#90: runs the release tests and the PyPI publish on GitHub-hosted runners, and publishes only after the release tests pass.
  • mindsdb/data-vault#4: deletes the jobs that ran on self-hosted runners, and keeps the pull request unit tests on GitHub-hosted runners.
  • mindsdb/hashnode-starter-kit#39: deletes the two workflows that build and deploy the blog.
  • mindsdb/scratchpad-controller#80: points the dev and staging scratchpad workers at the dev-tier image.
  • mindsdb/argocd-envs#25: points PR environments at the dev-tier images of cowork, cowork-server and the scratchpad worker.
  • mindsdb/terraform#240, the second terraform change: sets the prod-tier image repository policies.
  • mindsdb/Kubernetes-Foundational-Services#166: updates the self-hosted runner chart on both clusters.

…000)

This change deletes every job that asks for mdb-dev or mdb-prod, along
with four workflows built around those jobs. Every remaining job runs
on a GitHub-hosted runner, which GitHub recommends for public
repositories. Pull requests, forks included, still run the unit tests.

The four deleted workflows:

- deploy.yml and tests_integration.yml ran only on mdb-dev or mdb-prod.
- build_deploy_staging.yml built and pushed the Docker images after
  each merge, then deployed and tested through those two files. Its one
  hosted job ran the unit tests after the merge.
- build_deploy_prod.yml was the release pipeline. On a published
  release it pushed the mindsdb package to PyPI and Docker Hub, then
  deployed it. Its one hosted job ran the unit tests ahead of those
  steps. This repository has no published releases.

build_deploy_dev.yml keeps the changed-files filter, the unit tests and
All Tests Succeeded. Its workflow is renamed "Test pull request",
because it no longer builds or deploys anything.

- A pull request that changes only files under docs/ or assets/, or
  only Markdown files, still skips the unit tests. Every other change
  runs them.
- A version bump in mindsdb/__about__.py now runs the unit tests,
  because setup.py builds the package from that file. Until now, the
  deleted post-merge run was the only test a version bump got.
- An edit to build_deploy_dev.yml alone now runs the unit tests too.
  The filter also drops an exclusion for test_on_deploy.yml, a file
  that does not exist.
- All Tests Succeeded fails when the filter job fails or is cancelled.
  It also fails when the filter sends a change to the unit tests and
  they do not pass.
- The write permissions move from the whole workflow onto the unit-test
  call, because tests_unit.yml asks for them. The filter and the final
  check get read access only.
- dorny/paths-filter is pinned to the v3.0.4 commit that v3 points to.
- The unit-test call stops inheriting secrets, because tests_unit.yml
  reads none.

scripts/run_integration_tests.sh no longer points at the deleted
tests_integration.yml.

Part of "Take the public repos off the credentialed runner group and
require devops to release a privileged run", owned by Lucas Koontz.

Refs: ENG-2000

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant