Skip to content

Commit 7a91bca

Browse files
kylos101codex
andauthored
Stop provisioning GitHub integration-test credentials in CI (#21631)
* Remove GitHub user credentials from integration test suites Co-authored-by: Codex <noreply@openai.com> * Keep the workspace workflow dedicated to workspace tests Co-authored-by: Codex <noreply@openai.com> * Preserve manual integration tests while omitting CI credentials Co-authored-by: Codex <noreply@openai.com> * Check stderr for process-limit fork diagnostics Co-authored-by: Codex <noreply@openai.com> --------- Co-authored-by: Codex <noreply@openai.com>
1 parent 9b1fad0 commit 7a91bca

12 files changed

Lines changed: 56 additions & 51 deletions

File tree

‎.github/actions/integration-tests/action.yml‎

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -27,12 +27,6 @@ inputs:
2727
test_build_ref:
2828
description: "The build ref of the test run. Used in the IDE integration tests."
2929
required: false
30-
integration_test_username:
31-
description: "The username for integration test"
32-
required: true
33-
integration_test_usertoken:
34-
description: "The username for integration test"
35-
required: true
3630
identity_provider:
3731
description: "GCP workload identity provider"
3832
required: true
@@ -83,8 +77,6 @@ runs:
8377
shell: bash
8478
env:
8579
ROBOQUAT_TOKEN: ${{ inputs.github_token }}
86-
INTEGRATION_TEST_USERNAME: ${{ inputs.integration_test_username }}
87-
INTEGRATION_TEST_USER_TOKEN: ${{ inputs.integration_test_usertoken }}
8880
PREVIEW_NAME: ${{ inputs.preview_name }}
8981
TEST_USE_LATEST_VERSION: ${{ inputs.latest_ide_version }}
9082
TEST_BUILD_ID: ${{ inputs.test_build_id }}
@@ -122,6 +114,11 @@ runs:
122114
paths: "test/**/TEST-*.xml"
123115
show: "all"
124116
if: always()
117+
- name: Explain skipped IDE coverage
118+
if: ${{ always() && contains(fromJSON('["ide", "jetbrains", "vscode", "ssh", "all", ""]'), inputs.test_suite) }}
119+
shell: bash
120+
run: |
121+
printf '%s\n' 'GitHub-backed IDE tests skip in CI because no GitHub test-user credentials are supplied. They remain available for manually configured runs. Skipped tests do not validate IDE or SSH gateway functionality. See test/README.md.' >> "$GITHUB_STEP_SUMMARY"
125122
- name: Slack Notification
126123
uses: rtCamp/action-slack-notify@v2
127124
if: ${{ (success() || failure()) && inputs.notify_slack_webhook != '' }}

‎.github/workflows/branch-build.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -576,8 +576,6 @@ jobs:
576576
identity_provider: ${{ secrets.DEV_PREVIEW_PROVIDER }}
577577
service_account: ${{ secrets.DEV_PREVIEW_SA }}
578578
leeway_segment_key: ${{ secrets.LEEWAY_SEGMENT_KEY }}
579-
integration_test_username: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USERNAME }}
580-
integration_test_usertoken: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USER_TOKEN }}
581579

582580
workspace-integration-tests-main:
583581
name: "Run workspace integration tests on main branch"

‎.github/workflows/build.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -614,8 +614,6 @@ jobs:
614614
identity_provider: ${{ secrets.DEV_PREVIEW_PROVIDER }}
615615
service_account: ${{ secrets.DEV_PREVIEW_SA }}
616616
leeway_segment_key: ${{ secrets.LEEWAY_SEGMENT_KEY }}
617-
integration_test_username: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USERNAME }}
618-
integration_test_usertoken: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USER_TOKEN }}
619617

620618
workspace-integration-tests-main:
621619
name: "Run workspace integration tests on main branch"

‎.github/workflows/ide-integration-tests.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -145,8 +145,6 @@ jobs:
145145
shell: bash
146146
env:
147147
ROBOQUAT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
148-
USERNAME: ${{ secrets.IDE_INTEGRATION_TEST_USERNAME }}
149-
USER_TOKEN: ${{ secrets.IDE_INTEGRATION_TEST_USER_TOKEN }}
150148
PREVIEW_NAME: ${{ needs.configuration.outputs.name }}
151149
TEST_BUILD_ID: ${{ github.run_id }}
152150
TEST_BUILD_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
@@ -165,7 +163,6 @@ jobs:
165163
args=()
166164
args+=( "-kubeconfig=$HOME/.kube/config" )
167165
args+=( "-namespace=default" )
168-
[[ "$USERNAME" != "" ]] && args+=( "-username=$USERNAME" )
169166
args+=( "-timeout=60m" )
170167
171168
IDE_TESTS_DIR="$GITHUB_WORKSPACE/test/tests/ide"
@@ -201,13 +198,18 @@ jobs:
201198
with:
202199
paths: "test/tests/**/TEST-*.xml"
203200
if: always()
201+
- name: Explain skipped IDE coverage
202+
if: always()
203+
shell: bash
204+
run: |
205+
printf '%s\n' 'The 13 IDE integration tests skip in this workflow because no GitHub test-user credentials are supplied. They remain available for manually configured runs. Deployment/readiness and skipped-test reports provide no functional IDE or SSH gateway coverage.' >> "$GITHUB_STEP_SUMMARY"
204206
- name: Slack Notification
205207
uses: rtCamp/action-slack-notify@cdf0a2130cbcdfd82ba5fcac8e076370bf381b36 # pin@v2
206208
if: success() || failure()
207209
env:
208210
SLACK_WEBHOOK: ${{ secrets.IDE_SLACK_WEBHOOK }}
209211
SLACK_COLOR: ${{ job.status }}
210-
SLACK_MESSAGE: ${{ steps.test_summary.outputs.passed }}/${{ steps.test_summary.outputs.total }} tests passed
212+
SLACK_MESSAGE: "GitHub-backed IDE tests skip in CI (no test-user credentials). ${{ steps.test_summary.outputs.passed }} passed, ${{ steps.test_summary.outputs.failed }} failed, ${{ steps.test_summary.outputs.skipped }} skipped."
211213
SLACK_FOOTER: "<https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}|Workflow logs>"
212214

213215
delete:

‎.github/workflows/preview-env-check-regressions.yml‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -110,8 +110,6 @@ jobs:
110110
shell: bash
111111
env:
112112
ROBOQUAT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
113-
USERNAME: ${{ secrets.IDE_INTEGRATION_TEST_USERNAME }}
114-
USER_TOKEN: ${{ secrets.IDE_INTEGRATION_TEST_USER_TOKEN }}
115113
PREVIEW_NAME: ${{ needs.configuration.outputs.name }}
116114
run: |
117115
set -euo pipefail
@@ -126,7 +124,6 @@ jobs:
126124
args=()
127125
args+=( "-kubeconfig=/home/gitpod/.kube/config" )
128126
args+=( "-namespace=default" )
129-
[[ "$USERNAME" != "" ]] && args+=( "-username=$USERNAME" )
130127
args+=( "-timeout=60m" )
131128
132129
TESTS_DIR="$GITHUB_WORKSPACE/test/tests/smoke-test"
@@ -150,6 +147,11 @@ jobs:
150147
with:
151148
paths: "test/tests/**/TEST.xml"
152149
if: always()
150+
- name: Explain skipped workspace smoke coverage
151+
if: always()
152+
shell: bash
153+
run: |
154+
printf '%s\n' 'The workspace creation/image-build smoke test skips in CI because no GitHub test-user credentials are supplied; it remains available manually. Gitpod API smoke tests require explicit opt-in and separate Gitpod credentials, which this workflow does not supply. Skipped-only runs provide no functional smoke coverage.' >> "$GITHUB_STEP_SUMMARY"
153155
- id: auth
154156
if: failure()
155157
uses: google-github-actions/auth@955352c3b43196640b567e4646256d2fbb4aa1c7 # pin@v1

‎.github/workflows/workspace-integration-tests.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -174,8 +174,6 @@ jobs:
174174
identity_provider: ${{ secrets.DEV_PREVIEW_PROVIDER }}
175175
service_account: ${{ secrets.DEV_PREVIEW_SA }}
176176
leeway_segment_key: ${{ secrets.LEEWAY_SEGMENT_KEY }}
177-
integration_test_username: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USERNAME }}
178-
integration_test_usertoken: ${{ secrets.WORKSPACE_INTEGRATION_TEST_USER_TOKEN }}
179177

180178
delete:
181179
name: Delete preview environment

‎test/README.md‎

Lines changed: 31 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -22,17 +22,19 @@ Such tests are for example:
2222

2323
## Automatically at Gitpod
2424

25-
You can opt-in to run the integrations tests as part of the build job. that runs the integration tests against preview environments.
25+
The **Branch Build** workflow runs webapp tests when the PR description selects:
2626

27-
> For tests that require an existing user the framework tries to automatically select one from the DB.
28-
> - On preview envs make sure to create one before running tests against it!
29-
> - If it's important to use a certain user (with fixed settings, for example) pass the additional `username` parameter.
27+
```markdown
28+
- [x] with-integration-tests=webapp
29+
```
3030

31-
Example command:
31+
This builds and deploys the branch to a large preview and runs the server/database
32+
suite. The **Workspace integration tests** workflow always runs `workspace`.
3233

33-
```console
34-
werft job run github -a with-preview=true -a with-integration-tests=webapp -f
35-
```
34+
CI does not supply GitHub test-user credentials. Tests requiring them skip;
35+
other workspace, component, and webapp tests continue to run. Default IDE and
36+
workspace-creation smoke runs have no functional coverage when all tests skip.
37+
The implementations and manual entry points remain available.
3638

3739
## Manually
3840

@@ -69,9 +71,27 @@ If you want to run an entire test suite, the easiest is to use `./test/run.sh`:
6971

7072
If you're iterating on a single test, the easiest is to use `go test` directly.
7173

72-
If your integration tests depends on having having a user token available, then you'll have to set `USER_NAME` and `USER_TOKEN` environment variables. This can be done a couple ways:
73-
1. Get credentials persisted as secrets (either in Github Actions, or GCP Secret Manager via the `core-dev` project), which vary by job that trigger tests. Refer to `run.sh` for details.
74-
2. In your Gitpod (preview) environment, log into the preview environment, set `USER_NAME` to the user you logged in with, and set `USER_TOKEN` to any (does not have to be valid).
74+
For GitHub-backed tests, explicitly supply `USER_NAME` (or `-username`) and
75+
`USER_TOKEN`, where `USER_TOKEN` is a **GitHub user token**. The runner preserves
76+
these manual inputs and no longer loads credentials from CI environment aliases
77+
or the Kubernetes test-user secret. Use a preview with a working GitHub auth
78+
provider. Disk tests require the selected user to already have a usable GitHub
79+
identity/token in the preview database; they skip when no username is supplied.
80+
81+
```sh
82+
export USER_NAME='<test username>'
83+
export USER_TOKEN='<GitHub user token>'
84+
./test/run.sh -s workspace
85+
```
86+
87+
Without these variables, credential-dependent tests skip and the remaining tests
88+
use their builtin or temporary user paths. IDE tests retain their additional
89+
setup requirements; see [JetBrains manual instructions](../dev/jetbrains-test/README.md).
90+
91+
The opt-in collaborator smoke tests use `USER_TOKEN` for a different purpose: a
92+
**Gitpod PAT or session cookie**, with `TEST_COLLABORATOR=true`. Temporary-token
93+
smoke tests use `INSTALLATION_ADMIN_PAT` / `MEMBER_USER_PAT` and
94+
`TEST_CREATE_TMP_TOKEN=true`. Those interfaces are unchanged.
7595

7696
```console
7797
cd test

‎test/pkg/integration/disk-client.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ func (d DiskClient) Fallocate(testFilePath string, spaceToAllocate string) error
3636
return fmt.Errorf("returned returned rc: %d err: %v", resp.ExitCode, resp.Stderr)
3737
}
3838
if strings.Contains(resp.Stdout, NoSpaceErrorMsg) {
39-
return fmt.Errorf(resp.Stdout)
39+
return fmt.Errorf("%s", resp.Stdout)
4040
}
4141

4242
return nil

‎test/pkg/integration/setup.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -249,7 +249,7 @@ func logGitpodStatus(t *testing.T, client klient.Client, namespace string) {
249249
}
250250
}
251251
tw.Flush()
252-
t.Logf("Gitpod components status:\n" + buf.String())
252+
t.Logf("Gitpod components status:\n%s", buf.String())
253253
}
254254

255255
func isPreviewReady(client klient.Client, namespace string) (ready bool, reason string, err error) {

‎test/run.sh‎

Lines changed: 2 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -83,21 +83,8 @@ args+=( "-kubeconfig=${KUBECONFIG:-/home/gitpod/.kube/config}" )
8383
args+=( "-namespace=${NAMESPACE:-default}" )
8484
args+=( "-timeout=120m" )
8585

86-
if [[ "${GITPOD_REPO_ROOT:-}" != "" ]]; then
87-
echo "Running in Gitpod workspace. Fetching USER_NAME and USER_TOKEN"
88-
USER_NAME="$(kubectl --context=dev -n werft get secret integration-test-user -o jsonpath='{.data.username}' | base64 -d)"
89-
USER_TOKEN="$(kubectl --context=dev -n werft get secret integration-test-user -o jsonpath='{.data.token}' | base64 -d)"
90-
export USER_NAME
91-
export USER_TOKEN
92-
else
93-
echo "Using INTEGRATION_TEST_USERNAME and INTEGRATION_TEST_USER_TOKEN for USER_NAME and USER_TOKEN"
94-
USER_NAME="${INTEGRATION_TEST_USERNAME}"
95-
USER_TOKEN="${INTEGRATION_TEST_USER_TOKEN}"
96-
export USER_NAME
97-
export USER_TOKEN
98-
fi
99-
100-
[[ "$USER_NAME" != "" ]] && args+=( "-username=$USER_NAME" )
86+
# Tests use builtin or temporary Gitpod users unless one is explicitly selected.
87+
[[ -n "${USER_NAME:-}" ]] && args+=( "-username=$USER_NAME" )
10188

10289
go install github.com/jstemmer/go-junit-report/v2@latest
10390

0 commit comments

Comments
 (0)