Track runner spec updates with an actionable revision

When the AutoscalingRunnerSet's runner spec changes, the EphemeralRunnerSet
has to delete its idle and pending runners so they are rebuilt from the new
spec. That was detected by hashing Spec.EphemeralRunnerSpec into the
actions.github.com/integrity-hash annotation and comparing the annotation
against a freshly computed hash.

Replace it with a monotonic revision counter split across spec and status.
The AutoscalingRunnerSet controller bumps Spec.ActionableRevision when it
patches a new runner spec across; the EphemeralRunnerSet controller advances
Status.AppliedActionableRevision only after the cleanup has actually
succeeded. Because the applied marker lives in status and is written last, a
controller that crashes part-way through the cleanup comes back with the
applied revision still behind the spec revision and redoes the work, instead
of skipping runners that are still running the old spec.

The drift check uses apiequality.Semantic.DeepEqual rather than cmp.Equal or
reflect.DeepEqual. Most PodSpec collection fields carry omitempty, so a
template containing an explicitly empty value (`env: []`) is dropped when the
EphemeralRunnerSet is written and reads back as nil. A strict comparison would
report drift on every reconcile, bump the revision each time, and delete every
idle and pending runner forever. helpers_drift_test.go pins that behaviour with
a round-trip-through-JSON test.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Nikola Jokic
2026-09-10 22:56:48 +02:00
co-authored by Copilot App
parent b830b658d6
commit ec793dfe9f
13 changed files with 854 additions and 40 deletions
@@ -36,12 +36,22 @@ type EphemeralRunnerSetSpec struct {
// but does not apply to existing ephemeral runners.
// +optional
EphemeralRunnerMetadata *ResourceMeta `json:"ephemeralRunnerMetadata,omitempty"`
// ActionableRevision is a restart-safe applied marker that increments whenever
// Spec.EphemeralRunnerSpec changes, enabling detection of spec updates.
// Unset defaults to 0.
// +optional
ActionableRevision int64 `json:"actionableRevision,omitempty"`
}
// EphemeralRunnerSetStatus defines the observed state of EphemeralRunnerSet
type EphemeralRunnerSetStatus struct {
// +optional
Phase EphemeralRunnerSetPhase `json:"phase"`
// AppliedActionableRevision is a restart-safe applied marker tracking the last successfully
// applied ActionableRevision value. Advances only after spec cleanup succeeds.
// Unset defaults to 0.
// +optional
AppliedActionableRevision int64 `json:"appliedActionableRevision,omitempty"`
}
// EphemeralRunnerSetPhase is the phase of the ephemeral runner set resource
@@ -71,11 +81,6 @@ type EphemeralRunnerSet struct {
Status EphemeralRunnerSetStatus `json:"status,omitempty"`
}
// EphemeralRunnerSpecHash computes the hash value of the EphemeralRunnerSpec and returns it as a string.
func (ers *EphemeralRunnerSet) EphemeralRunnerSpecHash() string {
return ers.Spec.EphemeralRunnerSpec.Hash()
}
func (ers *EphemeralRunnerSet) GitHubConfigSecret() string {
return ers.Spec.EphemeralRunnerSpec.GitHubConfigSecret
}