Skip to content

ci: a fork repository runs on GitHub's runners - #122

Merged
askalf merged 5 commits into
mainfrom
ci/fork-repo-runs-hosted
Oct 6, 2026
Merged

askalf merged 5 commits into
mainfrom
ci/fork-repo-runs-hosted

Conversation

@askalf

@askalf askalf commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

A fix to the runner split that moved this repo's own-code CI to cordon-exec. In a fork repository of askalf/cordon, a push, schedule or dispatch carries no pull_request, so the expression picked cordon-exec. A fork has no such runner, so the job would wait forever. (Redline caught this on the same change in askalf/dario.)

  • The own-code expression now also sends any run outside askalf/cordon to ubuntu-latest:
    (github.repository != 'askalf/cordon' || github.event.pull_request && (<fork or Dependabot PR>)) && 'ubuntu-latest' || fromJSON('["self-hosted","cordon-exec"]')

  • The jobs that never run PR code and used the literal label (fleet-status.yml, fleet-status-backfill.yml) now use ${{ github.repository == 'askalf/cordon' && fromJSON('["self-hosted","cordon-exec"]') || 'ubuntu-latest' }}.

  • The runner comments state the constraint: a fork's PR and a Dependabot PR run code nobody here wrote, and a fork repository has no cordon-exec runners. They no longer mention where the runners are deployed.

  • CodeQL goes back to GitHub's runners. The analyze job runs on ubuntu-latest again, without the ram/threads inputs. CodeQL sizes itself to the machine, and the exec runners of every repo share one host, so concurrent analyses from several repos exhausted its memory: six at once on 2026-10-06 drove host load past 150.

Apart from CodeQL, nothing changes for runs in this repository: same-repo PRs, pushes, schedules and dispatches still run on cordon-exec.

Tests

  • node scripts/fleet-status.test.mjs: 176 pass, 0 fail, locally. The runner checks now cover every event in a fork repository (someone/cordon → GitHub's runners) besides fork PRs, fork reviews and Dependabot PRs; the repository-only expression is checked to run here for every event and in a fork on GitHub's runners, and only on jobs that never run PR code.
  • This PR's own checks run on cordon-exec-e1.

In a fork of this repository a push, schedule or dispatch carries no
pull_request, so the own-code expression chose cordon-exec, which a fork
does not have, and the job would wait for a runner forever. The
expression now also sends any run outside askalf/cordon to GitHub's
runners, and the jobs that never run PR code use cordon-exec only here.
The runner comments state the constraint without the runners'
deployment details. scripts/fleet-status.test.mjs checks every event
in a fork repository.
@github-actions github-actions Bot added github_actions Pull requests that update GitHub Actions code size/M 50-199 hand-written lines labels Oct 6, 2026
CodeQL sizes itself to the machine, and the exec runners of every repo
share one host, so concurrent analyses from several repos exhausted its
memory (six at once on 2026-10-06 drove host load past 150). The
analyze job goes back to ubuntu-latest, without the ram and threads
inputs it needed on the shared host.

@sprayberry-redline sprayberry-redline left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: approve. The runner expressions send fork-repository runs to GitHub-hosted runners while preserving the existing PR isolation and home-repository routing. The tests exercise the new repository branch, and CodeQL consistently uses hosted runners with default resource sizing.

askalf added 3 commits October 6, 2026 16:50
Docker reads a Dockerfile-specific ignore file, Dockerfile.dockerignore,
in preference to .dockerignore. A PR that added one could drop the
image's entry point while the input check said nothing changed, so the
image smoke was skipped and the required docker-build passed.

@sprayberry-redline sprayberry-redline left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: approve. The runner expressions send fork-repository runs to hosted runners while preserving this repository's runner split, with tests covering both cases. CodeQL now uses hosted resources, and the image-input filter correctly includes Dockerfile.dockerignore.

@askalf
askalf merged commit a824876 into main Oct 6, 2026
17 checks passed
@askalf
askalf deleted the ci/fork-repo-runs-hosted branch October 6, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code size/M 50-199 hand-written lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants