Skip to content

chore(ci): delete the workflows that build and deploy the blog (ENG-2000) - #39

Open
lucas-koontz wants to merge 1 commit into
mainfrom
chore/eng-2000-drop-cluster-deploys
Open

lucas-koontz wants to merge 1 commit into
mainfrom
chore/eng-2000-drop-cluster-deploys

Conversation

@lucas-koontz

@lucas-koontz lucas-koontz commented Oct 4, 2026 •

Copy link
Copy Markdown

User story

As a maintainer of this repository
I want main to hold no workflow that builds or deploys the old blog
So that a push to main or a manual dispatch starts no job on a self-hosted runner

Why this matters

A maintainer who merges to main today rebuilds the blog image and redeploys its charts into the dev namespace, and a published release does the same in prod. No reader sees either deploy, because https://mindsdb.com/blog redirects to https://mindshub.ai/blog, a site this repository does not build. Both workflows run on self-hosted runners, and GitHub recommends GitHub-hosted runners for public repositories. Moving the jobs to GitHub-hosted runners would only keep an unused deploy alive, so this PR deletes both workflows.

Acceptance criteria

  • After the merge, main has no .github directory, and gh api 'repos/mindsdb/hashnode-starter-kit/contents/.github/workflows?ref=main' returns 404.
  • The push that the merge makes to main starts no workflow run.
  • No tracked file names mdb-dev, mdb-prod, mindsdb/github-actions or either deleted workflow.
  • Negative: nothing outside .github/workflows/ changes. deployment/, the Dockerfile and both chart READMEs stay as they are.

How to test

Start from a checkout of chore/eng-2000-drop-cluster-deploys, with gh signed in to any GitHub account.

  1. Run git diff --name-status origin/main...HEAD. Expect exactly two D lines, for .github/workflows/dev-build-deploy-on-main.yaml and .github/workflows/prod-build-deploy-on-release.yaml, and nothing else.
  2. Run git grep -n -E 'mdb-dev|mdb-prod|mindsdb/github-actions|build-deploy-on-(main|release)'. Expect no output.
  3. Run curl -sI https://mindsdb.com/blog. Expect a 301 with location: https://mindshub.ai/blog, which shows no reader depends on these deploys.
  4. After the merge, run gh api 'repos/mindsdb/hashnode-starter-kit/contents/.github/workflows?ref=main'. Expect HTTP 404.
  5. After the merge, run gh api "repos/mindsdb/hashnode-starter-kit/actions/runs?head_sha=$(gh api repos/mindsdb/hashnode-starter-kit/commits/main --jq .sha)" --jq .total_count. Expect 0. A workflow that survived the merge would start a run here, so this is the check most likely to catch a partial fix.

Notes for the reviewer

Merge order: independent. This PR depends on no sibling, and no sibling depends on it, so it can merge as soon as it is approved.

Operator steps: none. Nothing has to run before or after the merge.

Rollback: revert the squash commit on main. The revert restores both workflows exactly as they were, triggers included, so the next push to main would build and deploy into dev again.

This PR uninstalls nothing. It deletes the workflow files only. Anything an earlier run installed stays until someone removes it with helm uninstall.

Deliberate omissions.

  • deployment/ and the Dockerfile stay. Nothing in this repository uses them after this change. Their READMEs describe a manual helm install and never mention these workflows, so they stay accurate. Removing them is a separate choice.
  • No README changes. The top-level README is Hashnode's upstream text about deploying to Vercel, and no README in this repository describes these workflows.
  • No replacement workflow. The blog moved to a site this repository does not build, so nothing here needs building or deploying.

No checks run on this PR. No workflow remains to run, and main requires none to merge.

Verified locally

Check Result
git fetch origin, then origin/main compared with the branch base origin/main is still c3669aa, the commit this branch starts from, so the rebase changed nothing
git diff --stat origin/main...HEAD Two deleted files, 51 and 52 lines, and nothing else
actionlint 1.7.12 on the two workflows at origin/main Exit 1 with 4 unknown-runner-label errors: mdb-dev three times and mdb-prod once
actionlint 1.7.12 at the branch head Exit 3, because no .github/workflows directory remains
zizmor 1.28.0, regular persona, offline, on the workflows at origin/main 30 findings, 6 of them suppressed: 10 high and 14 medium
zizmor 1.28.0, regular persona, offline, at the branch head Exit 3: no workflow, action or Dependabot config left to audit
git grep at the branch head over the tracked files except .env*, for mdb-dev, mdb-prod, mindsdb/github-actions, setup-env, build-push-ecr, aws-helm, DevOps-Nirvana and both workflow names No match
GitHub code search across the mindsdb organization No other repository names either workflow file or this repository
curl on 2026-10-04 at 05:13 UTC https://mindsdb.com/blog and https://www.mindsdb.com/blog return 301 to https://mindshub.ai/blog, which serves 200 from an Astro site. https://hashnode.dev.mindsdb.com/blog, the dev environment URL, returns 404
GitHub deployments API The last dev deployment ran on 2025-06-04 at c3669aa. The last prod deployment ran on 2025-02-13 at v25.2.3.0
Pre-PR sweep against origin/main No whitespace errors, ticket ids in added comments or debug leftovers

Ships with

Part of ENG-2000. This PR deploys nothing, so it carries no Deploys: lines and no deploy label.

Merge order

  1. mindsdb/terraform#239 merges, and the operator applies it: the GitHub OIDC providers, the image build and installer upload roles, the dev-tier image repositories and the deployment environment settings.
  2. mindsdb/github-actions#71 merges.
  3. The operator creates mindsdb/deployer, a new private repository, and the deployer PR opens then. That PR merges once it re-pins argocd-pr-env-deploy to the github-actions merge commit from step 2. The operator also creates the deployer's GitHub App and sets its client ID and private key in the staging and prod environments of cowork and cowork-server.
  4. mindsdb/anton#526, mindsdb/cowork#1117 and mindsdb/cowork-server#621 merge into staging. mindsdb/minds_python_sdk#90, mindsdb/engine#7, mindsdb/data-vault#4 and this PR merge into main. These four depend on no other step.
  5. Once each dev-tier image repository holds its staging tag, mindsdb/scratchpad-controller#80 and mindsdb/argocd-envs#25 merge.
  6. anton, cowork and cowork-server each promote staging to main in their next release.
  7. mindsdb/terraform#240 applies once the main builds push through the prod writer roles.
  8. mindsdb/Kubernetes-Foundational-Services#166 merges, and the operator upgrades it on both clusters, once cowork-server's change is on main and staging.
  9. The operator finishes with one step outside these repositories.

Sibling PRs, in merge order:

  • mindsdb/terraform#239: creates the GitHub OIDC providers, the image build and installer upload roles and the dev-tier image repositories, and sets up the deployment environments.
  • mindsdb/github-actions#71: build-push-ecr gains builder: local for GitHub-hosted builds, and argocd-pr-env-deploy takes the pull request as inputs and checks its image in the dev tier.
  • mindsdb/deployer, a new private repository whose PR opens in step 3: rolls cowork and cowork-server out to staging and prod, and syncs their PR environments.
  • mindsdb/anton#526: builds the scratchpad image on GitHub-hosted runners, and pushes pull request and staging builds to the dev tier.
  • mindsdb/cowork#1117: runs every cowork job on GitHub-hosted runners, and rolls staging and prod out through mindsdb/deployer.
  • mindsdb/cowork-server#621: runs every job on GitHub-hosted runners, and deploys staging and prod through mindsdb/deployer.
  • mindsdb/minds_python_sdk#90: runs the release tests and the PyPI publish on GitHub-hosted runners, and publishes only after the release tests pass.
  • mindsdb/engine#7: deletes the jobs that ran on self-hosted runners, and keeps the pull request unit tests on GitHub-hosted runners.
  • mindsdb/data-vault#4: deletes the jobs that ran on self-hosted runners, and keeps the pull request unit tests on GitHub-hosted runners.
  • mindsdb/scratchpad-controller#80: points the dev and staging scratchpad workers at the dev-tier image.
  • mindsdb/argocd-envs#25: points PR environments at the dev-tier images of cowork, cowork-server and the scratchpad worker.
  • mindsdb/terraform#240, the second terraform change: sets the prod-tier image repository policies.
  • mindsdb/Kubernetes-Foundational-Services#166: updates the self-hosted runner chart on both clusters.

Delete the only two workflows in this repository.

dev-build-deploy-on-main.yaml ran on every push to main. It built the
blog image and helm-installed every chart under deployment/ into the
dev namespace. prod-build-deploy-on-release.yaml ran on a published
release or a manual dispatch, and did the same into the prod
namespace.

Both workflows ran on the mdb-dev and mdb-prod self-hosted runners.
GitHub recommends GitHub-hosted runners for public repositories, but
moving these jobs there would keep deploying a blog that no public URL
reaches. mindsdb.com/blog now redirects to https://mindshub.ai/blog, a
site this repository does not build. The last deploys ran on
2025-06-04 (dev) and 2025-02-13 (prod).

With no workflow on main, a push to main or a manual dispatch starts
no job. The charts under deployment/ and the Dockerfile stay. Their
READMEs describe a manual helm install, which this change leaves as
it is.

Part of Lucas Koontz's ticket "Take the public repos off the
credentialed runner group and require devops to release a privileged
run".

Refs: ENG-2000

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant