Conformance KPR EKS (ci-kpr-eks) #223
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Conformance KPR EKS (ci-kpr-eks) | |
| # Any change in triggers needs to be reflected in the concurrency group. | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| PR-number: | |
| description: "Pull request number." | |
| required: true | |
| context-ref: | |
| description: "Context in which the workflow runs. If PR is from a fork, will be the PR target branch (general case). If PR is NOT from a fork, will be the PR branch itself (this allows committers to test changes to workflows directly from PRs)." | |
| required: true | |
| SHA: | |
| description: "SHA under test (head of the PR branch)." | |
| required: true | |
| base-SHA: | |
| description: "SHA of the base branch (target branch of the PR)." | |
| required: false | |
| extra-args: | |
| description: "[JSON object] Arbitrary arguments passed from the trigger comment via regex capture group. Parse with 'fromJson(inputs.extra-args).argName' in workflow." | |
| required: false | |
| default: '{}' | |
| # Run every 12 hours | |
| schedule: | |
| - cron: '0 4/12 * * *' | |
| # By specifying the access of one of the scopes, all of those that are not | |
| # specified are set to 'none'. | |
| permissions: | |
| # To be able to trigger eks-cluster-pool-manager.yaml workflow | |
| actions: write | |
| # To be able to access the repository with actions/checkout | |
| contents: read | |
| # To allow retrieving information from the PR API | |
| pull-requests: read | |
| # To be able to set commit status | |
| statuses: write | |
| # To be able to request the JWT from GitHub's OIDC provider | |
| id-token: write | |
| concurrency: | |
| # Structure: | |
| # - Parent concurrency group name to avoid deadlock with child workflows | |
| # - Workflow name | |
| # - Event type | |
| # - A unique identifier depending on event type: | |
| # - schedule: SHA | |
| # - workflow_dispatch: PR number | |
| # | |
| # This structure ensures a unique concurrency group name is generated for each | |
| # type of testing, such that re-runs will cancel the previous run. | |
| group: | | |
| parent | |
| ${{ github.workflow }} | |
| ${{ github.event_name }} | |
| ${{ | |
| (github.event_name == 'push' && github.sha) || | |
| (github.event_name == 'schedule' && github.sha) || | |
| (github.event_name == 'workflow_dispatch' && github.event.inputs.PR-number) | |
| }} | |
| cancel-in-progress: true | |
| env: | |
| # Single, in-file source of truth for the netkit quarantine. While "true", | |
| # the netkit / netkit-l2 jobs may fail without failing the workflow (see the | |
| # netkit jobs and the merge-upload-and-status gate). Set to "false" to re-arm | |
| # them once the underlying netkit failures are fixed. | |
| # | |
| # This env cannot be referenced directly from a job's `with:` input or the | |
| # status gate (the `env` context is not available there), so the `config` job | |
| # below re-exports it as a job output, which `needs.config.outputs.*` can read | |
| # in those positions. Keeping it as a workflow env means forks inherit the | |
| # quarantine automatically, with nothing to configure. | |
| QUARANTINE_NETKIT: "true" | |
| jobs: | |
| echo-inputs: | |
| if: ${{ github.event_name == 'workflow_dispatch' }} | |
| name: Echo Workflow Dispatch Inputs | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Echo Workflow Dispatch Inputs | |
| run: | | |
| echo '${{ tojson(inputs) }}' | |
| config: | |
| name: Config | |
| runs-on: ubuntu-24.04 | |
| outputs: | |
| # Re-export the workflow-level QUARANTINE_NETKIT env so it can be consumed | |
| # from `with:` inputs and the status gate via needs.config.outputs. | |
| quarantine_netkit: ${{ steps.vars.outputs.quarantine_netkit }} | |
| steps: | |
| - name: Export quarantine flag | |
| id: vars | |
| run: echo "quarantine_netkit=${QUARANTINE_NETKIT}" >> "$GITHUB_OUTPUT" | |
| commit-status-start: | |
| name: Commit Status Start | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Set initial commit status | |
| uses: cilium/cilium/.github/actions/set-commit-status@main # main | |
| with: | |
| sha: ${{ inputs.SHA || github.sha }} | |
| wait-for-images: | |
| name: Wait for images | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Checkout context ref (trusted) | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| ref: ${{ inputs.context-ref || github.sha }} | |
| persist-credentials: false | |
| - name: Wait for images | |
| uses: ./.github/actions/wait-for-images | |
| with: | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| images: cilium-ci operator-generic-ci hubble-relay-ci | |
| login-host: ${{ vars.DOCKER_READ_HOST }} | |
| login-username: ${{ vars.DOCKER_READ_USERNAME }} | |
| login-password: ${{ secrets.DOCKER_READ_PASSWORD }} | |
| auth-required: ${{ vars.DOCKER_AUTH_REQUIRED }} | |
| conformance-eks-kpr: | |
| name: Conformance EKS with KPR | |
| needs: wait-for-images | |
| uses: ./.github/workflows/conformance-eks.yaml | |
| secrets: inherit | |
| with: | |
| PR-number: ${{ inputs.PR-number || github.ref_name }} | |
| UID: 1 | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true}' | |
| test-concurrency: 2 | |
| conformance-eks-kpr-ipsec: | |
| name: Conformance EKS with KPR + IPsec | |
| needs: wait-for-images | |
| uses: ./.github/workflows/conformance-eks.yaml | |
| secrets: inherit | |
| with: | |
| PR-number: ${{ inputs.PR-number || github.ref_name }} | |
| UID: 2 | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true, "ipsec": true}' | |
| test-concurrency: 2 | |
| conformance-eks-kpr-wireguard: | |
| name: Conformance EKS with KPR + WireGuard | |
| needs: wait-for-images | |
| uses: ./.github/workflows/conformance-eks.yaml | |
| secrets: inherit | |
| with: | |
| PR-number: ${{ inputs.PR-number || github.ref_name }} | |
| UID: 3 | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true, "wireguard": true}' | |
| test-concurrency: 2 | |
| # The netkit / netkit-l2 jobs are quarantined: they currently fail (e.g. the | |
| # l7-lb pod-to-l7-lb-service hairpinning connectivity test, plus on-demand | |
| # capacity / nodegroup-creation flakes in some regions), and the failures are | |
| # still under investigation. The QUARANTINE_NETKIT flag (see the config job) | |
| # lets them fail without breaking the run, while still collecting artifacts | |
| # and emitting a warning annotation. Set QUARANTINE_NETKIT to "false" to | |
| # re-arm them once the failures are fixed. | |
| # | |
| # Both jobs run on scheduled events only (they are skipped on | |
| # workflow_dispatch and PR ci-* comments); the status gate below tolerates | |
| # that skip. | |
| conformance-eks-kpr-netkit: | |
| name: Conformance EKS with KPR + Netkit | |
| if: ${{ github.event_name == 'schedule' }} | |
| needs: [wait-for-images, config] | |
| uses: ./.github/workflows/conformance-eks.yaml | |
| secrets: inherit | |
| with: | |
| PR-number: ${{ inputs.PR-number || github.ref_name }} | |
| UID: 4 | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| extra-args: '{"kpr": true, "bpf-datapath": "netkit", "bpf-masq-v4": true }' | |
| test-concurrency: 2 | |
| quarantine: ${{ needs.config.outputs.quarantine_netkit == 'true' }} | |
| conformance-eks-kpr-netkit-l2: | |
| name: Conformance EKS with KPR + Netkit-L2 | |
| if: ${{ github.event_name == 'schedule' }} | |
| needs: [wait-for-images, config] | |
| uses: ./.github/workflows/conformance-eks.yaml | |
| secrets: inherit | |
| with: | |
| PR-number: ${{ inputs.PR-number || github.ref_name }} | |
| UID: 5 | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| SHA: ${{ inputs.SHA || github.sha }} | |
| extra-args: '{"kpr": true, "bpf-datapath": "netkit-l2", "bpf-masq-v4": true }' | |
| test-concurrency: 2 | |
| quarantine: ${{ needs.config.outputs.quarantine_netkit == 'true' }} | |
| # Re-surface a quarantined netkit failure at this (parent) workflow level. The | |
| # warning annotation emitted inside the reusable conformance-eks.yaml is | |
| # attached to the called workflow's job, so it does not show up on this | |
| # workflow's run summary. This job emits an equivalent annotation here when a | |
| # quarantined netkit job failed but was tolerated. | |
| quarantine-warning: | |
| name: Quarantine Warning | |
| if: ${{ always() && needs.config.outputs.quarantine_netkit == 'true' && (needs.conformance-eks-kpr-netkit.result == 'failure' || needs.conformance-eks-kpr-netkit-l2.result == 'failure') }} | |
| needs: [config, conformance-eks-kpr-netkit, conformance-eks-kpr-netkit-l2] | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - name: Warn on quarantined netkit failure | |
| run: | | |
| echo "::warning title=Quarantined job failed::A netkit conformance job failed but is quarantined (QUARANTINE_NETKIT), so it did not fail this workflow. Investigate the failures in the netkit / netkit-l2 jobs; set QUARANTINE_NETKIT to \"false\" to re-arm them." | |
| merge-upload-and-status: | |
| name: Merge Upload and Status | |
| if: ${{ always() }} | |
| needs: [config, conformance-eks-kpr, conformance-eks-kpr-ipsec, conformance-eks-kpr-wireguard, conformance-eks-kpr-netkit, conformance-eks-kpr-netkit-l2] | |
| uses: ./.github/workflows/common-post-jobs.yaml | |
| secrets: inherit | |
| with: | |
| context-ref: ${{ inputs.context-ref || github.sha }} | |
| sha: ${{ inputs.SHA || github.sha }} | |
| # The core KPR jobs must pass on every trigger. The quarantined netkit | |
| # jobs are tolerated while QUARANTINE_NETKIT is "true": each netkit result | |
| # is OR'd with the quarantine flag exported by the config job, so a | |
| # quarantined netkit failure does not flip the commit status, while the | |
| # jobs stay listed so they still gate against being cancelled. Both netkit | |
| # jobs only run on scheduled events, so on other triggers their result is | |
| # 'skipped', which is also tolerated. Set QUARANTINE_NETKIT to "false" to | |
| # re-arm the netkit jobs once the failures are fixed. | |
| success: >- | |
| ${{ | |
| needs.conformance-eks-kpr.result == 'success' && | |
| needs.conformance-eks-kpr-ipsec.result == 'success' && | |
| needs.conformance-eks-kpr-wireguard.result == 'success' && | |
| (needs.conformance-eks-kpr-netkit.result == 'success' || needs.conformance-eks-kpr-netkit.result == 'skipped' || needs.config.outputs.quarantine_netkit == 'true') && | |
| (needs.conformance-eks-kpr-netkit-l2.result == 'success' || needs.conformance-eks-kpr-netkit-l2.result == 'skipped' || needs.config.outputs.quarantine_netkit == 'true') | |
| }} |