Skip to content

Conformance KPR EKS (ci-kpr-eks) #270

Conformance KPR EKS (ci-kpr-eks)

Conformance KPR EKS (ci-kpr-eks) #270

name: Conformance KPR EKS (ci-kpr-eks)
# Any change in triggers needs to be reflected in the concurrency group.
on:
workflow_dispatch:
inputs:
PR-number:
description: "Pull request number."
required: true
context-ref:
description: "Context in which the workflow runs. If PR is from a fork, will be the PR target branch (general case). If PR is NOT from a fork, will be the PR branch itself (this allows committers to test changes to workflows directly from PRs)."
required: true
SHA:
description: "SHA under test (head of the PR branch)."
required: true
base-SHA:
description: "SHA of the base branch (target branch of the PR)."
required: false
extra-args:
description: "[JSON object] Arbitrary arguments passed from the trigger comment via regex capture group. Parse with 'fromJson(inputs.extra-args).argName' in workflow."
required: false
default: '{}'
# Run every 12 hours
schedule:
- cron: '0 4/12 * * *'
# By specifying the access of one of the scopes, all of those that are not
# specified are set to 'none'.
permissions:
# To be able to trigger eks-cluster-pool-manager.yaml workflow
actions: write
# To be able to access the repository with actions/checkout
contents: read
# To allow retrieving information from the PR API
pull-requests: read
# To be able to set commit status
statuses: write
# To be able to request the JWT from GitHub's OIDC provider
id-token: write
concurrency:
# Structure:
# - Parent concurrency group name to avoid deadlock with child workflows
# - Workflow name
# - Event type
# - A unique identifier depending on event type:
# - schedule: SHA
# - workflow_dispatch: PR number
#
# This structure ensures a unique concurrency group name is generated for each
# type of testing, such that re-runs will cancel the previous run.
group: |
parent
${{ github.workflow }}
${{ github.event_name }}
${{
(github.event_name == 'push' && github.sha) ||
(github.event_name == 'schedule' && github.sha) ||
(github.event_name == 'workflow_dispatch' && github.event.inputs.PR-number)
}}
cancel-in-progress: true
env:
# Single, in-file source of truth for the netkit quarantine. While "true",
# the netkit / netkit-l2 jobs may fail without failing the workflow (see the
# netkit jobs and the merge-upload-and-status gate). Set to "false" to re-arm
# them once the underlying netkit failures are fixed.
#
# This env cannot be referenced directly from a job's `with:` input or the
# status gate (the `env` context is not available there), so the `config` job
# below re-exports it as a job output, which `needs.config.outputs.*` can read
# in those positions. Keeping it as a workflow env means forks inherit the
# quarantine automatically, with nothing to configure.
QUARANTINE_NETKIT: "true"
jobs:
echo-inputs:
if: ${{ github.event_name == 'workflow_dispatch' }}
name: Echo Workflow Dispatch Inputs
runs-on: ubuntu-24.04
steps:
- name: Echo Workflow Dispatch Inputs
run: |
echo '${{ tojson(inputs) }}'
config:
name: Config
runs-on: ubuntu-24.04
outputs:
# Re-export the workflow-level QUARANTINE_NETKIT env so it can be consumed
# from `with:` inputs and the status gate via needs.config.outputs.
quarantine_netkit: ${{ steps.vars.outputs.quarantine_netkit }}
steps:
- name: Export quarantine flag
id: vars
run: echo "quarantine_netkit=${QUARANTINE_NETKIT}" >> "$GITHUB_OUTPUT"
commit-status-start:
name: Commit Status Start
runs-on: ubuntu-24.04
steps:
- name: Set initial commit status
uses: cilium/actions/set-commit-status@fe0702f5df0d8e44d48f1baa226c023b73ff6b5e # main
with:
sha: ${{ inputs.SHA || github.sha }}
wait-for-images:
name: Wait for images
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- name: Checkout context ref (trusted)
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.context-ref || github.sha }}
persist-credentials: false
- name: Wait for images
uses: ./.github/actions/wait-for-images
with:
SHA: ${{ inputs.SHA || github.sha }}
images: cilium-ci operator-generic-ci hubble-relay-ci
login-host: ${{ vars.DOCKER_READ_HOST }}
login-username: ${{ vars.DOCKER_READ_USERNAME }}
login-password: ${{ secrets.DOCKER_READ_PASSWORD }}
auth-required: ${{ vars.DOCKER_AUTH_REQUIRED }}
conformance-eks-kpr:
name: Conformance EKS with KPR
needs: wait-for-images
uses: ./.github/workflows/conformance-eks.yaml
secrets: inherit
with:
PR-number: ${{ inputs.PR-number || github.ref_name }}
UID: 1
context-ref: ${{ inputs.context-ref || github.sha }}
SHA: ${{ inputs.SHA || github.sha }}
extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true}'
test-concurrency: 2
conformance-eks-kpr-ipsec:
name: Conformance EKS with KPR + IPsec
needs: wait-for-images
uses: ./.github/workflows/conformance-eks.yaml
secrets: inherit
with:
PR-number: ${{ inputs.PR-number || github.ref_name }}
UID: 2
context-ref: ${{ inputs.context-ref || github.sha }}
SHA: ${{ inputs.SHA || github.sha }}
extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true, "ipsec": true}'
test-concurrency: 2
conformance-eks-kpr-wireguard:
name: Conformance EKS with KPR + WireGuard
needs: wait-for-images
uses: ./.github/workflows/conformance-eks.yaml
secrets: inherit
with:
PR-number: ${{ inputs.PR-number || github.ref_name }}
UID: 3
context-ref: ${{ inputs.context-ref || github.sha }}
SHA: ${{ inputs.SHA || github.sha }}
extra-args: '{"kpr": true, "bpf-masq-v4": true, "advanced-features": true, "wireguard": true}'
test-concurrency: 2
# The netkit / netkit-l2 jobs are quarantined: they currently fail (e.g. the
# l7-lb pod-to-l7-lb-service hairpinning connectivity test, plus on-demand
# capacity / nodegroup-creation flakes in some regions), and the failures are
# still under investigation. The QUARANTINE_NETKIT flag (see the config job)
# lets them fail without breaking the run, while still collecting artifacts
# and emitting a warning annotation. Set QUARANTINE_NETKIT to "false" to
# re-arm them once the failures are fixed.
#
# Both jobs run on scheduled events only (they are skipped on
# workflow_dispatch and PR ci-* comments); the status gate below tolerates
# that skip.
conformance-eks-kpr-netkit:
name: Conformance EKS with KPR + Netkit
if: ${{ github.event_name == 'schedule' }}
needs: [wait-for-images, config]
uses: ./.github/workflows/conformance-eks.yaml
secrets: inherit
with:
PR-number: ${{ inputs.PR-number || github.ref_name }}
UID: 4
context-ref: ${{ inputs.context-ref || github.sha }}
SHA: ${{ inputs.SHA || github.sha }}
extra-args: '{"kpr": true, "bpf-datapath": "netkit", "bpf-masq-v4": true }'
test-concurrency: 2
quarantine: ${{ needs.config.outputs.quarantine_netkit == 'true' }}
conformance-eks-kpr-netkit-l2:
name: Conformance EKS with KPR + Netkit-L2
if: ${{ github.event_name == 'schedule' }}
needs: [wait-for-images, config]
uses: ./.github/workflows/conformance-eks.yaml
secrets: inherit
with:
PR-number: ${{ inputs.PR-number || github.ref_name }}
UID: 5
context-ref: ${{ inputs.context-ref || github.sha }}
SHA: ${{ inputs.SHA || github.sha }}
extra-args: '{"kpr": true, "bpf-datapath": "netkit-l2", "bpf-masq-v4": true }'
test-concurrency: 2
quarantine: ${{ needs.config.outputs.quarantine_netkit == 'true' }}
# Re-surface a quarantined netkit failure at this (parent) workflow level. The
# warning annotation emitted inside the reusable conformance-eks.yaml is
# attached to the called workflow's job, so it does not show up on this
# workflow's run summary. This job emits an equivalent annotation here when a
# quarantined netkit job failed but was tolerated.
quarantine-warning:
name: Quarantine Warning
if: ${{ always() && needs.config.outputs.quarantine_netkit == 'true' && (needs.conformance-eks-kpr-netkit.result == 'failure' || needs.conformance-eks-kpr-netkit-l2.result == 'failure') }}
needs: [config, conformance-eks-kpr-netkit, conformance-eks-kpr-netkit-l2]
runs-on: ubuntu-24.04
steps:
- name: Warn on quarantined netkit failure
run: |
echo "::warning title=Quarantined job failed::A netkit conformance job failed but is quarantined (QUARANTINE_NETKIT), so it did not fail this workflow. Investigate the failures in the netkit / netkit-l2 jobs; set QUARANTINE_NETKIT to \"false\" to re-arm them."
merge-upload-and-status:
name: Merge Upload and Status
if: ${{ always() }}
needs: [config, conformance-eks-kpr, conformance-eks-kpr-ipsec, conformance-eks-kpr-wireguard, conformance-eks-kpr-netkit, conformance-eks-kpr-netkit-l2]
uses: ./.github/workflows/common-post-jobs.yaml
secrets: inherit
with:
context-ref: ${{ inputs.context-ref || github.sha }}
sha: ${{ inputs.SHA || github.sha }}
# The core KPR jobs must pass on every trigger. The quarantined netkit
# jobs are tolerated while QUARANTINE_NETKIT is "true": each netkit result
# is OR'd with the quarantine flag exported by the config job, so a
# quarantined netkit failure does not flip the commit status, while the
# jobs stay listed so they still gate against being cancelled. Both netkit
# jobs only run on scheduled events, so on other triggers their result is
# 'skipped', which is also tolerated. Set QUARANTINE_NETKIT to "false" to
# re-arm the netkit jobs once the failures are fixed.
success: >-
${{
needs.conformance-eks-kpr.result == 'success' &&
needs.conformance-eks-kpr-ipsec.result == 'success' &&
needs.conformance-eks-kpr-wireguard.result == 'success' &&
(needs.conformance-eks-kpr-netkit.result == 'success' || needs.conformance-eks-kpr-netkit.result == 'skipped' || needs.config.outputs.quarantine_netkit == 'true') &&
(needs.conformance-eks-kpr-netkit-l2.result == 'success' || needs.conformance-eks-kpr-netkit-l2.result == 'skipped' || needs.config.outputs.quarantine_netkit == 'true')
}}