diff --git a/.github/workflows/dco.yaml b/.github/workflows/dco.yaml index 9a5124d8..ee4d1f7e 100644 --- a/.github/workflows/dco.yaml +++ b/.github/workflows/dco.yaml @@ -1,20 +1,37 @@ name: DCO on: - pull_request: + pull_request: {} + workflow_dispatch: {} merge_group: - push: - branches: - - main + types: + - checks_requested + +permissions: + contents: read + jobs: - check_dco: - runs-on: ubuntu-22.04 - permissions: - contents: read - name: Check DCO + check-dco: + runs-on: ubuntu-latest steps: - - name: Run dco-check - uses: christophebedard/dco-check@ec8bfc43106afe98b323ace9133650df10497e12 # 0.5.1 + - name: Checkout + uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 + - name: Skip DCO check in merge queue + if: github.event_name == 'merge_group' + run: | + echo "Skipping DCO check for merge queue - DCO is validated on PR commits before entering the queue" + exit 0 + - name: Set up Python 3.x + if: github.event_name != 'merge_group' + uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: - args: --exclude-pattern 'dependabot\[bot\]@users\.noreply\.github\.com' + python-version: '3.x' + - name: Check DCO + if: github.event_name != 'merge_group' env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + pip3 install -U dco-check + # sayadas@redhat.com: upstream commit fc4afb5e has a sign-off whose name + # ("Sayak Das") does not match the author name ("Sayak"), which dco-check + # rejects. The commit is already in spiffe/spire-controller-manager main. + dco-check --exclude-pattern 'dependabot\[bot\]@users\.noreply\.github\.com|sayadas@redhat\.com' diff --git a/.github/workflows/nightly_build.yaml b/.github/workflows/nightly_build.yaml index ffab0aa4..a3932357 100644 --- a/.github/workflows/nightly_build.yaml +++ b/.github/workflows/nightly_build.yaml @@ -1,9 +1,11 @@ name: Nightly Build on: - schedule: - # Random minute number to avoid GH scheduler stampede - - cron: '37 21 * * *' - workflow_dispatch: {} + push: + tags: + - 'nightly-*' + +env: + DATADOG_INSTRUMENTATION: "true" jobs: build-and-publish-images: @@ -36,4 +38,4 @@ jobs: username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Push images - run: ./.github/workflows/scripts/push-images.sh nightly + run: ./.github/workflows/scripts/push-images.sh "${GITHUB_REF#refs/tags/}" diff --git a/.github/workflows/release_build.yaml b/.github/workflows/release_build.yaml index 858196e0..3b0ad9f9 100644 --- a/.github/workflows/release_build.yaml +++ b/.github/workflows/release_build.yaml @@ -3,6 +3,10 @@ on: push: tags: - 'v[0-9].[0-9]+.[0-9]+' + +env: + DATADOG_INSTRUMENTATION: "true" + jobs: build-image: runs-on: ubuntu-22.04 diff --git a/Dockerfile b/Dockerfile index 3be98946..450caaf4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -23,14 +23,29 @@ FROM --platform=${BUILDPLATFORM} tonistiigi/xx@sha256:904fe94f236d36d65aeb5a2462 # Build FROM --platform=${BUILDPLATFORM} base AS builder +ARG datadog_instrumentation=false +ARG orchestrion_version=v1.11.0 ARG TARGETPLATFORM ARG TARGETARCH ENV CGO_ENABLED=0 COPY --link --from=xx / / + +RUN <