Skip to content

Commit 9b45848

Browse files
authored
ci: auto-approve Renovate PRs after required checks (#1048)
* ci: auto-approve Renovate PRs after required checks Renovate cannot approve its own PRs, so github-actions[bot] approves when auto-merge is enabled. Always post a Buildkite status so docs-only PRs still satisfy an upcoming required acceptance check. * ci: skip acc sweep on docs-only PRs A leftover sweep failure would fail the required Buildkite check even when testacc was skipped. Ignore the sentinel so it cannot be committed. * ci: classify docs-only PRs without a grep pipeline grep -q can SIGPIPE echo under pipefail and invert to a false skip.
1 parent be170c9 commit 9b45848

9 files changed

Lines changed: 101 additions & 19 deletions

File tree

‎.buildkite/acceptance.sh‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,29 @@
11
#!/bin/bash
22
set -euo pipefail
33

4+
# Docs-only PRs still need a green Buildkite status: master requires
5+
# buildkite/terraform-provider-ec-acceptance, and skip_ci_on_only_changed would
6+
# leave that context missing (blocking merge). Exit 0 here instead of running
7+
# the paid suite.
8+
docs_only_pr() {
9+
[[ "${BUILDKITE_PULL_REQUEST:-false}" == "false" ]] && return 1
10+
local base="${BUILDKITE_PULL_REQUEST_BASE_BRANCH:-master}"
11+
# Fail-safe: if we cannot see the base, run the suite rather than skip.
12+
git fetch --depth=50 origin "$base" || return 1
13+
local files
14+
files=$(git diff --name-only "origin/${base}...HEAD") || return 1
15+
[[ -n "$files" ]] || return 1
16+
# Here-string: grep -q would SIGPIPE echo under pipefail and invert to a false skip.
17+
! grep -qvE '^(docs/|dev-docs/)' <<< "$files"
18+
}
19+
20+
if docs_only_pr; then
21+
echo "--- Skip acceptance tests (docs/dev-docs only)"
22+
# pre-exit still runs; skip sweep so a leftover cleanup failure cannot fail the required check.
23+
touch .buildkite/.skip-acceptance-sweep
24+
exit 0
25+
fi
26+
427
echo "--- Download dependencies"
528
make vendor
629

‎.buildkite/hooks/pre-exit‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,10 @@
33
set -euo pipefail
44

55
if [[ "$BUILDKITE_STEP_KEY" == "acceptance-tests" ]]; then
6+
if [[ -f .buildkite/.skip-acceptance-sweep ]]; then
7+
echo "--- Skip sweep (docs/dev-docs only)"
8+
exit 0
9+
fi
610
echo "--- Sweeps any deployments and serverless projects older than 3h."
711
EC_API_KEY=$TERRAFORM_PROVIDER_API_KEY_SECRET SWEEPARGS='-sweep-run=ec_deployments,ec_serverless_projects' make sweep
812
rm -rf reports bin

‎.buildkite/pull-requests.json‎

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,10 +13,7 @@
1313
"always_trigger_comment_regex": "^(?:(?:buildkite\\W+)?(?:build|test)\\W+(?:this|it))",
1414
"skip_ci_labels": [ ],
1515
"skip_target_branches": [ ],
16-
"skip_ci_on_only_changed": [
17-
"^docs/",
18-
"^dev-docs/"
19-
],
16+
"skip_ci_on_only_changed": [ ],
2017
"always_require_ci_on_changed": [ ]
2118
}
2219
]
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
name: Auto-approve Renovate
2+
3+
# github-actions[bot] approves Renovate PRs that already have auto-merge on
4+
# (Renovate cannot approve its own PRs). Majors never enable auto-merge.
5+
# synchronize re-approves after the NOTICE follow-up commit.
6+
7+
on:
8+
pull_request:
9+
branches:
10+
- master
11+
types: [auto_merge_enabled, synchronize]
12+
13+
permissions:
14+
contents: read
15+
pull-requests: write
16+
17+
jobs:
18+
approve:
19+
name: Approve
20+
runs-on: ubuntu-latest
21+
if: |
22+
(github.event.pull_request.user.login == 'elastic-renovate-prod[bot]' ||
23+
github.event.pull_request.user.login == 'elastic-renovate-dev[bot]') &&
24+
github.event.pull_request.auto_merge != null
25+
steps:
26+
- uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
27+
with:
28+
script: |
29+
try {
30+
await github.rest.pulls.createReview({
31+
owner: context.repo.owner,
32+
repo: context.repo.repo,
33+
pull_number: context.issue.number,
34+
event: 'APPROVE',
35+
})
36+
} catch (error) {
37+
// Duplicate approve on the same commit.
38+
if (error.status === 422) {
39+
core.info(`Skipping approve: ${error.message}`)
40+
return
41+
}
42+
throw error
43+
}

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,9 @@ dist
1212
.terraform.lock.hcl
1313
node_modules/
1414

15+
# CI sentinel: docs-only acc jobs write this so pre-exit skips make sweep
16+
.buildkite/.skip-acceptance-sweep
17+
1518
# agent local overrides (not committed)
1619
.agents/settings.local.json
1720
.agents/worktrees

‎AGENTS.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,8 @@ and related resources through the Elastic Cloud API.
2424
- Acceptance tests (`make testacc`, and anything gated by `TF_ACC=1`) create and destroy **real
2525
deployments** against the live Elastic Cloud API (`EC_API_KEY`) and cost real money. **Never run
2626
acceptance tests from an agentic workflow** — no live-cloud credentials are exposed to agents. The
27-
full suite runs on Buildkite per PR (a human reviews the result); a human working on a change
27+
full suite runs on Buildkite per PR and is a **required** status check on `master`
28+
(`buildkite/terraform-provider-ec-acceptance`); a human working on a change
2829
should run the targeted `TestAcc…` case(s) locally first. See [`testing.md`](./dev-docs/high-level/testing.md).
2930
- There is **no local Docker stack** for this provider (unlike the Elastic Stack provider). Unit
3031
tests (`make unit`) need no credentials and are always safe to run.

‎dev-docs/high-level/development-workflow.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,8 @@ fragments are the source of truth for exact behavior.
1515
> **Before opening a PR, run the _targeted_ test(s) covering your change locally** —
1616
> `make testacc TEST_NAME='TestAccMyThing'` — for fast feedback, then `make sweep` any leftovers.
1717
> Don't run the **full** suite locally for routine iteration (~2 hours); the Buildkite acceptance
18-
> pipeline runs the full suite for every PR and a human reviews the result. **Agents never run
19-
> acceptance tests** — no live-cloud credentials are exposed to agentic workflows. See
18+
> pipeline runs the full suite for every PR and is a required status check on `master`. **Agents
19+
> never run acceptance tests** — no live-cloud credentials are exposed to agentic workflows. See
2020
> [`testing.md`](./testing.md). `make unit` needs no credentials and is always safe. There is **no
2121
> local Docker stack** for this provider.
2222
@@ -68,5 +68,5 @@ full manual runbook see [`../RELEASE.md`](../RELEASE.md).
6868
7. Add a changelog entry at `.changelog/{PR}.txt` for any user-facing change (one file per PR; see
6969
[`contributing.md`](./contributing.md)).
7070

71-
The **full** acceptance suite runs on Buildkite for every PR; run only the targeted cases locally,
72-
and note that **agents never run acceptance tests** at all.
71+
The **full** acceptance suite runs on Buildkite for every PR and must pass before merge; run only
72+
the targeted cases locally, and note that **agents never run acceptance tests** at all.

‎dev-docs/high-level/repo-structure.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ the [terraform-plugin-framework](https://developer.hashicorp.com/terraform/plugi
2626
| `examples/` | Example Terraform configs, also pulled into the generated docs. |
2727
| `.changelog/` | Per-PR changelog fragments (`{PR}.txt`); consolidated into `CHANGELOG.md` at release. See [`contributing.md`](./contributing.md). |
2828
| `.buildkite/` | Buildkite pipelines — notably the per-PR **acceptance** pipeline. See [`testing.md`](./testing.md). |
29-
| `.github/` | GitHub Actions (unit/lint/docs via `go.yml`, OpenSpec via `openspec.yml`) and repo config. |
29+
| `.github/` | GitHub Actions (unit/lint/docs via `go.yml`, OpenSpec via `openspec.yml`, Renovate auto-approve via `approve-renovate.yml`) and repo config. |
3030
| `dev-docs/` | Developer docs (this set), including [`RELEASE.md`](../RELEASE.md) — the release runbook. |
3131
| `docs-elastic/` | AsciiDoc source (`index.asciidoc`) for the Elastic docs site. |
3232
| `tools/` | Tool dependencies (pinned via `go` tooling). |

‎dev-docs/high-level/testing.md‎

Lines changed: 20 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,9 @@ and destroying real deployments and serverless projects. All test wiring lives i
3434
> 🚫 **Don't run the _full_ suite locally for routine iteration, and agents never run acceptance
3535
> tests at all** — no `TF_ACC` in agentic workflows and no live-cloud credentials are exposed to
3636
> agents. The full suite runs automatically for every PR on the dedicated **Buildkite acceptance
37-
> pipeline** (the GitHub Actions `go.yml` CI runs unit/lint/docs only), and a human reviews the
38-
> result.
37+
> pipeline** (the GitHub Actions `go.yml` CI runs unit/lint/docs only). That Buildkite status is a
38+
> **required** check on `master`, so a PR cannot merge — including Renovate automerge — until it is
39+
> green.
3940
4041
Gating and recipe (from `build/Makefile.test`):
4142

@@ -78,17 +79,26 @@ Acceptance runs are wired through Buildkite, not run inline by contributors:
7879

7980
- [`.buildkite/pull-requests.json`](../../.buildkite/pull-requests.json) gates the
8081
`terraform-provider-ec-acceptance` pipeline: org users with `admin`/`write` (plus `renovate[bot]`)
81-
trigger it on commit or on a `build this` / `test this` comment; changes touching only `^docs/`
82-
or `^dev-docs/` are skipped.
82+
trigger it on commit or on a `build this` / `test this` comment. The pipeline always runs so the
83+
required `buildkite/terraform-provider-ec-acceptance` status is posted. Docs-only PRs still start
84+
an agent (`pre-command` still loads the API key) but skip `make testacc` and the `pre-exit` sweep.
8385
- [`.buildkite/acceptance_pipeline.yml`](../../.buildkite/acceptance_pipeline.yml) defines the
8486
single "Acceptance tests" step running [`.buildkite/acceptance.sh`](../../.buildkite/acceptance.sh)
8587
on a `golang` image.
86-
- `acceptance.sh` runs `make vendor` then `EC_API_KEY=$TERRAFORM_PROVIDER_API_KEY_SECRET make testacc`.
88+
- `acceptance.sh` exits 0 without `make testacc` when the PR only touches `docs/` or `dev-docs/`
89+
(and writes `.buildkite/.skip-acceptance-sweep` so `pre-exit` does not sweep); otherwise it
90+
runs `make vendor` then `EC_API_KEY=$TERRAFORM_PROVIDER_API_KEY_SECRET make testacc`.
91+
- Branch protection on `master` requires **CLA**, **Unit**, and
92+
`buildkite/terraform-provider-ec-acceptance`. GitHub auto-merge (used by Renovate) waits on those
93+
checks. Non-major Renovate PRs are auto-approved as `github-actions[bot]` by
94+
[`.github/workflows/approve-renovate.yml`](../../.github/workflows/approve-renovate.yml) once
95+
Renovate enables auto-merge.
8796
- The [`pre-command`](../../.buildkite/hooks/pre-command) hook loads the API key from Vault and
8897
exports `BUILD_ID` (which makes `make sweep` skip its interactive confirmation).
89-
- The [`pre-exit`](../../.buildkite/hooks/pre-exit) hook always sweeps afterward (see below).
98+
- The [`pre-exit`](../../.buildkite/hooks/pre-exit) hook sweeps afterward unless the docs-only
99+
skip file is present (see below).
90100

91-
A human reviews the Buildkite result as part of PR review.
101+
The Buildkite result is a required check; merge is blocked until it is green.
92102

93103
## Sweepers
94104

@@ -112,8 +122,9 @@ sweep:
112122
matching filters.
113123
- **CI cleans up automatically:** Buildkite's `pre-exit` hook (on the `acceptance-tests` step) runs
114124
`SWEEPARGS='-sweep-run=ec_deployments,ec_serverless_projects' make sweep` after every acceptance
115-
build — so stale deployments **and** projects are reaped on exit regardless of pass/fail. (The
116-
`acceptance.sh` step itself only runs `make vendor` + `make testacc`.)
125+
build except docs-only skips (`.buildkite/.skip-acceptance-sweep`) — so stale deployments
126+
**and** projects are reaped on exit regardless of pass/fail. (The `acceptance.sh` step itself
127+
only runs `make vendor` + `make testacc`, or exits early on docs-only PRs.)
117128
- **When to run manually:** after a *local* acceptance failure that may have left dangling
118129
infrastructure, or to reclaim serverless quota (see below).
119130

0 commit comments

Comments
 (0)