Skip to content

[improve][ci] Upgrade approved actions, check the ASF allowlist and fix the cert-manager version in CI - #720

Merged
lhotari merged 2 commits into
apache:masterfrom
lhotari:lh-improve-ci-approved-actions
Oct 6, 2026
Merged

lhotari merged 2 commits into
apache:masterfrom
lhotari:lh-improve-ci-approved-actions

Conversation

@lhotari

@lhotari lhotari commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Motivation

Keep CI actions on current revisions and detect ASF allowlist problems before they disrupt builds. This follows the action upgrades in apache/pulsar-client-cpp#610, with the allowlist check included.

Since 2026-10-02 the CI workflow has failed with startup_failure on master and on all PRs, because azure/setup-helm v5.0.0 (dda3372f752e) was removed from the ASF allowlist. A workflow that uses an action ref missing from the allowlist doesn't start at all, so no job reports the cause.

While reviewing the workflow, I also found that CI never installed the cert-manager version configured in the test matrix. The workflow read matrix.certmanager_version although the value is defined under matrix.k8sVersion, and ci::install_cert_manager didn't pass CERTMANAGER_VERSION to install-cert-manager.sh. Because of that, all jobs installed the script's default cert-manager version v1.12.17, and the k8s 1.36.1 jobs haven't tested cert-manager v1.21.0 as intended in #710.

Modifications

Add apache/infrastructure-actions/allowlist-check@main immediately after checkout in the main CI workflow. The added step has no if: condition and scans .github/**/*.y*ml, covering both workflow and local composite-action YAML files. It fails on refs missing from the allowlist and warns 30 days before an allowlisted ref expires, without failing the build.

Upgrade GitHub-owned actions to their latest stable majors and pin third-party actions to the latest revisions in ASF's actions.yml, with version comments:

Action Previous ref Updated ref
actions/setup-java v5 v6
actions/setup-python v6 v7
azure/setup-helm dda3372f752e (v5.0.0) v5.0.1 (9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310)

The other actions are already on their latest majors: actions/checkout@v7, actions/cache@v6 and actions/upload-artifact@v7.

Install the cert-manager version configured in the CI matrix:

  • Read matrix.k8sVersion.certmanager_version instead of matrix.certmanager_version.
  • Pass CERTMANAGER_VERSION to install-cert-manager.sh in ci::install_cert_manager when it's set. Otherwise, the script's default version v1.12.17 is installed as before.

Verifying this change

  • Ran the upstream ASF allowlist checker locally against the current allowlist and expiration metadata: all action refs passed.
  • Ran actionlint on the workflow. The finding about the undefined matrix.certmanager_version property is resolved, and no new findings were added.
  • Checked that the v1.21.0 CRD manifest downloaded by install-cert-manager.sh exists, and that cert-manager v1.21.0 still accepts the AdditionalCertificateOutputFormats=true feature gate set by the script (the gate is GA and not locked).
  • CI validates the action upgrades on GitHub-hosted runners, and the k8s 1.36.1 jobs install cert-manager v1.21.0.

Documentation

  • doc-not-needed: CI maintenance only; no public API or runtime dependency changes.

@lhotari
lhotari force-pushed the lh-improve-ci-approved-actions branch from de4c7e4 to 9c25a25 Compare October 6, 2026 17:14
The CI workflow read matrix.certmanager_version although the value is
defined under matrix.k8sVersion, and ci::install_cert_manager didn't pass
CERTMANAGER_VERSION to install-cert-manager.sh. Because of that, all jobs
installed the script's default cert-manager version, and the k8s 1.36.1
jobs didn't test cert-manager 1.21.0 as intended.
@lhotari lhotari changed the title [improve][ci] Upgrade approved actions and check the ASF allowlist [improve][ci] Upgrade approved actions, check the ASF allowlist and fix the cert-manager version in CI Oct 6, 2026
@lhotari
lhotari merged commit b4cb947 into apache:master Oct 6, 2026
41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant