Port Pull Request Checks to the Guksu self-hosted runner #3

Open
opened 2026-08-05 08:36:55 -04:00 by fidget · 0 comments
Owner

Problem

.github/workflows/pull-request-checks.yml is discovered by Forgejo, but its jobs are not compatible with Guksu's available runner.

The only pull request in the repository produced Actions run 4. Both jobs were cancelled at 0s; neither has ever completed in the current 37-run history.

Evidence

The workflow requests GitHub-hosted capacity:

  • pnpm-validate: runs-on: ubuntu-latest
  • container-build-test: runs-on: ubuntu-latest

Guksu's active runner is jebus-guksu-runner, running as hermes, with only these host labels:

  • self-hosted
  • linux
  • x64
  • nix

The runner is deliberately configured for rootless Podman host jobs with container.docker_host = "-". The container test instead assumes a Docker daemon and GitHub's Buildx stack:

  • docker/setup-buildx-action
  • docker/build-push-action
  • GitHub Actions cache (type=gha)

Changing only runs-on would therefore move the failure rather than fix it.

Proposed resolution

Port the workflow to Guksu's actual CI environment:

  1. Run project validation on [self-hosted, linux, x64, nix].
  2. Replace the Docker/Buildx job with a rootless Podman build using the same wrapper PATH and cgroup configuration as the working container publication workflow.
  3. Keep PR jobs read-only and do not expose registry or release credentials.
  4. Revisit paths-ignore so changes to Compose, launchers, installers, and platform sources are not silently excluded from all relevant validation.

If PR checks are not wanted, remove the workflow and any required-check configuration instead of leaving a permanently unavailable check.

Acceptance criteria

  • A real test PR schedules both intended jobs on available runners.
  • pnpm install --frozen-lockfile, pnpm check, version drift, and installer guards complete successfully.
  • The container test builds with rootless Podman and no Docker daemon/socket.
  • The built image is exercised with at least a startup/health probe rather than treating image creation alone as success.
  • PR code receives no publication credentials.
  • The final run reaches an explicit terminal result instead of remaining queued or being cancelled at 0s.
## Problem `.github/workflows/pull-request-checks.yml` is discovered by Forgejo, but its jobs are not compatible with Guksu's available runner. The only pull request in the repository produced [Actions run 4](https://git.birdintra.net/fidget/Guksu-Motor/actions/runs/4). Both jobs were cancelled at `0s`; neither has ever completed in the current 37-run history. ## Evidence The workflow requests GitHub-hosted capacity: - `pnpm-validate`: `runs-on: ubuntu-latest` - `container-build-test`: `runs-on: ubuntu-latest` Guksu's active runner is `jebus-guksu-runner`, running as `hermes`, with only these host labels: - `self-hosted` - `linux` - `x64` - `nix` The runner is deliberately configured for rootless Podman host jobs with `container.docker_host = "-"`. The container test instead assumes a Docker daemon and GitHub's Buildx stack: - `docker/setup-buildx-action` - `docker/build-push-action` - GitHub Actions cache (`type=gha`) Changing only `runs-on` would therefore move the failure rather than fix it. ## Proposed resolution Port the workflow to Guksu's actual CI environment: 1. Run project validation on `[self-hosted, linux, x64, nix]`. 2. Replace the Docker/Buildx job with a rootless Podman build using the same wrapper PATH and cgroup configuration as the working container publication workflow. 3. Keep PR jobs read-only and do not expose registry or release credentials. 4. Revisit `paths-ignore` so changes to Compose, launchers, installers, and platform sources are not silently excluded from all relevant validation. If PR checks are not wanted, remove the workflow and any required-check configuration instead of leaving a permanently unavailable check. ## Acceptance criteria - [ ] A real test PR schedules both intended jobs on available runners. - [ ] `pnpm install --frozen-lockfile`, `pnpm check`, version drift, and installer guards complete successfully. - [ ] The container test builds with rootless Podman and no Docker daemon/socket. - [ ] The built image is exercised with at least a startup/health probe rather than treating image creation alone as success. - [ ] PR code receives no publication credentials. - [ ] The final run reaches an explicit terminal result instead of remaining queued or being cancelled at `0s`.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fidget/Guksu-Motor#3
No description provided.