Run selftest pull requests on GitHub-hosted runners - #72
Merged
Merged
Conversation
This repo is public, so a pull_request run can carry code from a fork, and arc-workflows is a pod on the production cluster with sudo. Every selftest job only needs the internet, so the hosted runner checks the same thing. Pushes, which need write access, stay on arc-workflows. Refs cshuttle/Monitoring#1285 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part A of cshuttle/Monitoring#1285 (option B, owner decision 2026-10-02). Part B, the network fence on the runner pods, is a separate PR in cshuttle/main.
What changes
selftest.ymlnow picks its runner per event:pull_requestruns go to GitHub-hostedubuntu-latest. This repo is public, so these runs can carry a stranger's code from a fork. Before this change, that code ran onarc-workflows: a pod on the production cluster, with sudo.pushruns stay onarc-workflows. Only someone with write access can push.Why hosted runners, not skipping fork PRs
Selftest needs nothing on the LAN. Its jobs are an apt install, GitHub release downloads (lefthook, actionlint), a stdlib Python test, and a grep. So on a hosted runner it tests exactly the same thing, and it still runs on every PR, including fork PRs. If we skipped fork PRs instead, a fork PR would get no selftest at all, and this repo is the supply-chain root for every cshuttle repo. Hosted minutes are free on a public repo, so the estate's zero-
ubuntu-latestrule (a billing rule) does not apply here.A lazier option is a one-line
if: github.event.pull_request.head.repo.full_name == github.repositoryon each job. It closes the same hole, but fork PRs then get no CI.This PR runs its own selftest on the hosted runner, because a
pull_requestrun uses the workflow file from the PR head. The other checks still run onarc-workflows.Repo-settings change for the human (not done here; agents may not change repo settings)
Settings → Actions → General → "Approval for running fork pull request workflows from contributors": change it from "Require approval for first-time contributors" to "Require approval for all outside collaborators".
With this PR, fork PRs no longer touch the cluster. The setting is the second layer: no fork run of any workflow starts until you approve it.
actionlint -shellcheck=passes on the whole repo.🤖 Generated with Claude Code