Run Nightly Builds #594
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Run Nightly Builds | |
| on: | |
| workflow_dispatch: {} | |
| schedule: | |
| # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#onschedule | |
| - cron: '0 0 * * *' # Every day at 0AM | |
| permissions: | |
| contents: read # for dorny/paths-filter to fetch a list of changed files | |
| pull-requests: read # for dorny/paths-filter to read pull requests | |
| actions: write # to trigger branch nightly builds | |
| jobs: | |
| workflow-requirements: | |
| name: Check Workflow Requirements | |
| # Job-level gate: skip entirely on private repos and forks unless | |
| # RUN_SCHEDULED_BUILDS=1 is set on the repo. A skipped job allocates no | |
| # runner and bills no minutes -- important on private repos where every | |
| # scheduled tick was costing ~30s of runner time for a run that always | |
| # ended up saying "requirements-met=false". Trigger-branch-nightly-builds | |
| # depends on this job via `needs:`, so when it skips, downstream skips | |
| # too (with no `if: always()` override), giving a truly free scheduled | |
| # tick on private/fork repos. | |
| # | |
| # workflow_dispatch triggers always pass through this gate -- ad-hoc | |
| # dispatches on private/fork repos should still run. | |
| if: > | |
| github.event_name != 'schedule' || | |
| vars.RUN_SCHEDULED_BUILDS == '1' || | |
| (github.event.repository.fork != true && github.event.repository.private != true) | |
| runs-on: ubuntu-22.04 | |
| outputs: | |
| requirements-met: ${{ steps.check-requirements.outputs.requirements-met }} | |
| steps: | |
| - name: Check Requirements | |
| id: check-requirements | |
| run: | | |
| # Reaching this step means the job-level `if:` already accepted | |
| # the run. Emit requirements-met=true so downstream jobs proceed. | |
| # The prior shell-based fork/private detection has been promoted | |
| # to the job-level `if:` above. | |
| MSG="Running workflow on ${{ github.repository }} (event=${{ github.event_name }})" | |
| echo "${MSG}" | |
| echo "${MSG}" >> "${GITHUB_STEP_SUMMARY}" | |
| echo "requirements-met=true" >> "${GITHUB_OUTPUT}" | |
| trigger-branch-nightly-builds: | |
| name: Trigger Branch Workflows | |
| # Repo-level opt-out. Set `SKIP_RUN_NIGHTLY=true` on repos that should | |
| # not dispatch nightlies — e.g. saltstack/salt, once nightlies run on | |
| # saltstack/salt-nightlies. Without this, the daily cron above triggers | |
| # nightly.yml on every branch here as a duplicate of the fork's builds. | |
| if: ${{ fromJSON(needs.workflow-requirements.outputs.requirements-met) && vars.SKIP_RUN_NIGHTLY != 'true' }} | |
| runs-on: ubuntu-24.04 | |
| needs: | |
| - workflow-requirements | |
| environment: workflow-restart | |
| strategy: | |
| matrix: | |
| branch: [3006.x, 3007.x, 3008.x, master] | |
| steps: | |
| - name: Generate a token | |
| id: generate-token | |
| uses: actions/create-github-app-token@v1 | |
| with: | |
| app-id: ${{ vars.APP_ID }} | |
| private-key: ${{ secrets.APP_PRIVATE_KEY }} | |
| - name: Trigger ${{ matrix.branch }} branch | |
| env: | |
| GH_TOKEN: ${{ steps.generate-token.outputs.token }} | |
| run: | | |
| gh workflow run nightly.yml --repo ${{ github.repository }} --ref ${{ matrix.branch }} |