Repository navigation
[improve][ci] Upgrade approved actions, check the ASF allowlist and fix the cert-manager version in CI - #720
Merged
Conversation
Assisted-by: Codex
lhotari
force-pushed
the
lh-improve-ci-approved-actions
branch
from
October 6, 2026 17:14
de4c7e4 to
9c25a25
Compare
The CI workflow read matrix.certmanager_version although the value is defined under matrix.k8sVersion, and ci::install_cert_manager didn't pass CERTMANAGER_VERSION to install-cert-manager.sh. Because of that, all jobs installed the script's default cert-manager version, and the k8s 1.36.1 jobs didn't test cert-manager 1.21.0 as intended.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Keep CI actions on current revisions and detect ASF allowlist problems before they disrupt builds. This follows the action upgrades in apache/pulsar-client-cpp#610, with the allowlist check included.
Since 2026-10-02 the CI workflow has failed with
startup_failureon master and on all PRs, becauseazure/setup-helmv5.0.0 (dda3372f752e) was removed from the ASF allowlist. A workflow that uses an action ref missing from the allowlist doesn't start at all, so no job reports the cause.While reviewing the workflow, I also found that CI never installed the cert-manager version configured in the test matrix. The workflow read
matrix.certmanager_versionalthough the value is defined undermatrix.k8sVersion, andci::install_cert_managerdidn't passCERTMANAGER_VERSIONtoinstall-cert-manager.sh. Because of that, all jobs installed the script's default cert-manager version v1.12.17, and the k8s 1.36.1 jobs haven't tested cert-manager v1.21.0 as intended in #710.Modifications
Add
apache/infrastructure-actions/allowlist-check@mainimmediately after checkout in the main CI workflow. The added step has noif:condition and scans.github/**/*.y*ml, covering both workflow and local composite-action YAML files. It fails on refs missing from the allowlist and warns 30 days before an allowlisted ref expires, without failing the build.Upgrade GitHub-owned actions to their latest stable majors and pin third-party actions to the latest revisions in ASF's actions.yml, with version comments:
actions/setup-javav5v6actions/setup-pythonv6v7azure/setup-helmdda3372f752e(v5.0.0)9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310)The other actions are already on their latest majors:
actions/checkout@v7,actions/cache@v6andactions/upload-artifact@v7.Install the cert-manager version configured in the CI matrix:
matrix.k8sVersion.certmanager_versioninstead ofmatrix.certmanager_version.CERTMANAGER_VERSIONtoinstall-cert-manager.shinci::install_cert_managerwhen it's set. Otherwise, the script's default version v1.12.17 is installed as before.Verifying this change
actionlinton the workflow. The finding about the undefinedmatrix.certmanager_versionproperty is resolved, and no new findings were added.install-cert-manager.shexists, and that cert-manager v1.21.0 still accepts theAdditionalCertificateOutputFormats=truefeature gate set by the script (the gate is GA and not locked).Documentation
doc-not-needed: CI maintenance only; no public API or runtime dependency changes.