Skip to content

Run selftest pull requests on GitHub-hosted runners - #72

Merged
cshuttle merged 1 commit into
mainfrom
selftest-hosted-pr-1285
Oct 3, 2026
Merged

cshuttle merged 1 commit into
mainfrom
selftest-hosted-pr-1285

Conversation

@cshuttle

@cshuttle cshuttle commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Part A of cshuttle/Monitoring#1285 (option B, owner decision 2026-10-02). Part B, the network fence on the runner pods, is a separate PR in cshuttle/main.

What changes

selftest.yml now picks its runner per event:

runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || 'arc-workflows' }}
  • pull_request runs go to GitHub-hosted ubuntu-latest. This repo is public, so these runs can carry a stranger's code from a fork. Before this change, that code ran on arc-workflows: a pod on the production cluster, with sudo.
  • push runs stay on arc-workflows. Only someone with write access can push.

Why hosted runners, not skipping fork PRs

Selftest needs nothing on the LAN. Its jobs are an apt install, GitHub release downloads (lefthook, actionlint), a stdlib Python test, and a grep. So on a hosted runner it tests exactly the same thing, and it still runs on every PR, including fork PRs. If we skipped fork PRs instead, a fork PR would get no selftest at all, and this repo is the supply-chain root for every cshuttle repo. Hosted minutes are free on a public repo, so the estate's zero-ubuntu-latest rule (a billing rule) does not apply here.

A lazier option is a one-line if: github.event.pull_request.head.repo.full_name == github.repository on each job. It closes the same hole, but fork PRs then get no CI.

This PR runs its own selftest on the hosted runner, because a pull_request run uses the workflow file from the PR head. The other checks still run on arc-workflows.

Repo-settings change for the human (not done here; agents may not change repo settings)

Settings → Actions → General → "Approval for running fork pull request workflows from contributors": change it from "Require approval for first-time contributors" to "Require approval for all outside collaborators".

With this PR, fork PRs no longer touch the cluster. The setting is the second layer: no fork run of any workflow starts until you approve it.

actionlint -shellcheck= passes on the whole repo.

🤖 Generated with Claude Code

This repo is public, so a pull_request run can carry code from a fork,
and arc-workflows is a pod on the production cluster with sudo. Every
selftest job only needs the internet, so the hosted runner checks the
same thing. Pushes, which need write access, stay on arc-workflows.

Refs cshuttle/Monitoring#1285

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cshuttle
cshuttle merged commit 25a9415 into main Oct 3, 2026
11 checks passed
@cshuttle
cshuttle deleted the selftest-hosted-pr-1285 branch October 3, 2026 02:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant