Skip to content

Scope CI by visibility: private repositories run on pull requests and dispatch only - #2

Merged
kalidke merged 5 commits into
mainfrom
ci/template-pr-only
Sep 28, 2026
Merged

kalidke merged 5 commits into
mainfrom
ci/template-pr-only

Conversation

@kalidke

@kalidke kalidke commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

This PR implements admiral decision 0025 as Keith revised it. Actions minutes are free on public repositories, so they keep push and scheduled CI and the warm cache. Private repositories test on pull requests and by hand (workflow_dispatch) only.

The merge is a squash. The earlier commits on this branch removed the caller's triggers outright; 7942c1c and a5fabb7 replace them, so the net diff against main is what is described here.

Change

  • templates/CI.yml: unchanged. It is byte-identical to main, so no package copy has to change. GaussMLE's copy, from its commit c8d4a77, differs and needs reverting to match.

  • julia-ci.yml, which events may run: the job conditions list what may run instead of what to skip. A job may run on:

    • pull_request (not a draft);
    • workflow_dispatch;
    • any event of a public repository, read from github.event.repository.private;
    • a scheduled run that the visibility job found public.

    A scheduled event carries no repository object, so the visibility job looks the repository up with gh api, on scheduled runs only. An event a private caller adds later, such as merge_group, release or repository_dispatch, therefore runs nothing. No condition tests private == false, because null == false is true.

  • julia-ci.yml, per-job rules:

    • A private repository tests Julia 1 only; its floor is in the local record.
    • downgrade and pre run in public repositories only. Downgrade's gate is the public test alone.
    • Public repositories keep the min/1 matrix and run on every event, as before.
  • Caches:

    • A public repository saves from its default branch only, including a push to main.
    • A private repository has no push runs, so every one of its runs saves: JULIA_CACHE_SAVE gains || github.event.repository.private.
    • The Runic job gains actions: write and drops delete-old-caches: 'false'. After a save off the default branch, julia-actions/cache deletes the caches that save replaces, and that needs the permission.
  • Superseded pull-request runs: the template's concurrency (cancel-in-progress on pull_request) already cancels them. It is unchanged.

  • selftest.yml: keeps push (this repository is public). It gains the template's pull_request types, so a draft marked ready gets a real run. It also gains workflow_dispatch.

  • README.md: states the private-repository rule, how each kind of repository's cache is seeded, and that GitHub drops a cache unused for 7 days. It also corrects the timeout to 60 minutes.

Test

The Self-test is green on a5fabb7 for both push (run 36450435050) and pull_request (run 36450441599).

  • Public path. Core - Julia min and Core - Julia 1, QA, Core - lowest compat and Runic ran and passed. Visibility and pre were skipped.
  • Private and scheduled paths. These were proven on a throwaway branch, diag/visibility, with the self-test. The branch and its caches are now deleted.
Simulation Event Result
github.event.repository.private set to true push every job skipped (run 36450441614)
same workflow_dispatch Core - Julia 1, QA and Runic only; downgrade and pre skipped; all three saved a cache (run 36450449804)
same, second dispatch workflow_dispatch each job saved a cache and deleted the one it replaced, Runic included (run 36450587759)
a scheduled event without a repository object: the repository field renamed, dispatch removed from the list, 'schedule' read as 'workflow_dispatch' dispatch Visibility found the repository public; every job ran, including downgrade and pre (run 36450737114)
same, with the lookup reporting private dispatch only Visibility ran; every other job skipped (run 36451009448)

Notes for review

  • Required checks. A private repository whose branch protection requires the Core - Julia min check would wait on it forever. No lab repository is known to require it.
  • Private cache budget. A private repository's pull-request caches share its 10 GB budget with the default branch's cache. Each job keeps one cache per ref, and GitHub drops caches unused for 7 days.
  • v2. The change is backward-compatible for callers: nothing that passed can turn red, and no input changed. The release is the merge plus moving v2.

🤖 Generated with Claude Code

kalidke and others added 4 commits September 28, 2026 07:47
Admiral decision 0025: CI tests run on pull requests only, plus workflow_dispatch; never on a
push (main included) and never on a schedule. Drops the push block (branches, tags,
paths-ignore) and the schedule block from templates/CI.yml, the same change as
JuliaSMLM/GaussMLE c8d4a77, whose copy now differs from this one only in its with: lines.
The README's trigger description follows. No file in this repository records the template's
hash.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Decision 0025 covers every test workflow, so the self-test also drops its push trigger and gains
workflow_dispatch. The pre job ran only on a schedule, which decision 0025 rules out for test
workflows and the caller template no longer has, so it is removed rather than kept as dead code;
the registered input now adds only the downgrade job. The schedule clause in JULIA_CACHE_SAVE
goes with it (a scheduled run is on the default branch anyway). The README follows, and its
timeout now reads 60 minutes, as the jobs have been since PR 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e note

The self-test's pull_request trigger takes the template's types, so a draft marked ready for
review gets a real run; without ready_for_review its only run is the draft one, whose skipped
jobs count as success. The README notes that only a manual workflow_dispatch run on main seeds
a Julia cache.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…chedule

Keith revised decision 0025: Actions minutes are free on public repositories, so they keep push
and scheduled CI and the warm cache; private repositories test on pull requests and by hand only.
This replaces the trigger removal of the earlier commits on this branch:

- templates/CI.yml is back to main's version, byte for byte, so no package copy has to change.
- julia-ci.yml skips every job on a push or scheduled event in a private repository. Push, pull
  request and dispatch events carry github.event.repository.private; a scheduled event carries
  no repository, so a visibility job looks it up via the API, on scheduled runs only.
- A private repository tests Julia 1 only (its floor is in the local record); downgrade and pre
  run in public repositories only. Public repositories keep the min/1 matrix.
- The cache rule is unchanged: the default branch saves, including a public repository's push to
  main; the schedule clause stays because a scheduled event carries no default_branch.
- The self-test keeps push and gains the template's pull_request types and workflow_dispatch.
- README: the private-repository rule, how a private cache is seeded, and the 60-minute timeout.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kalidke kalidke changed the title Caller template: run on pull requests and manual dispatch only Scope CI by visibility: private repositories run on pull requests and dispatch only Sep 28, 2026
Review of PR 2: the job conditions now list what may run (pull_request, workflow_dispatch, a
public repository's event, or a scheduled run the visibility job found public) instead of what
to skip, so an event a private caller adds later cannot run paid jobs. The downgrade job's gate
is the public test alone, which makes its old push clause and private check redundant.

A private repository has no push runs, so every one of its runs now saves the Julia cache; the
Runic job gains actions: write for the old-cache deletion that follows a save off the default
branch, and loses delete-old-caches: false. The README says how each kind is seeded and that
GitHub drops a cache unused for 7 days.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kalidke
kalidke merged commit 5bd89d7 into main Sep 28, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant