Commit Graph
1856 Commits
Author SHA1 Message Date
Nikola JokicandCopilot App 2aef0aeedd Remove dead spec hash helpers
Now that update propagation is tracked via ActionableRevision and
observedGeneration, the integrity-hash helpers have no callers:

- AutoscalingRunnerSet.Hash and AutoscalingListenerSpec.Hash lost their
  last callers in this change.
- ListenerSpecHash, RunnerSetSpecHash, EphemeralRunnerSet.EphemeralRunnerSpecHash
  and EphemeralRunnerSpec.Hash were already unreferenced.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-08 13:25:48 +02:00
Nikola JokicandCopilot App 95179fbf54 Remove dead blank-identifier block in helpers.go
Both ephemeralRunnerSetActionableSpecChanged and nextActionableRevision are
referenced from autoscalingrunnerset_controller.go, so the blank assignments
that suppressed unused-function warnings are no longer needed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-08 13:17:19 +02:00
Nikola Jokic e481f69cff Replace integrity-hash annotations with explicit API state fields
The `actions.github.com/integrity-hash` annotation was used as an opaque
fingerprint to detect spec drift across AutoscalingRunnerSet,
EphemeralRunnerSet and the listener resources. Hashes are brittle: they
change whenever unrelated serialization details change, they are invisible
to users, and they are not restart-safe. FNV-32a also carries a real
collision risk, where the consequence is an update silently never applied.

Replace it with explicit, typed state:

- `AutoscalingRunnerSetStatus.ObservedGeneration` drives the Pending phase
  transition via `metadata.generation` instead of an annotation hash.
- `EphemeralRunnerSetSpec.ActionableRevision` and
  `EphemeralRunnerSetStatus.AppliedActionableRevision` form a restart-safe
  applied marker. The revision is bumped by the AutoscalingRunnerSet
  controller when `EphemeralRunnerSpec` changes, and only advanced in status
  after idle/pending runner cleanup succeeds.
- `EphemeralRunnerSetStatus.FinishedRunnerCleanupPatchID` records the
  listener patch ID for which finished runners were reaped, so scale-up is
  suppressed until the listener publishes a fresh desired state. This
  prevents creating a replacement runner for a job that already completed.
- Listener pod recreation compares pod specs semantically instead of
  comparing hash annotations.

Drift detection uses `apiequality.Semantic`, not `cmp` or `reflect`:

- `Semantic.DeepEqual` for the EphemeralRunnerSpec. Most PodSpec collection
  fields carry `omitempty`, so a template containing an explicitly empty
  value (`env: []`) is dropped when the EphemeralRunnerSet is written and
  reads back as nil. A strict comparison reports drift on every reconcile,
  bumping ActionableRevision each time and deleting every idle and pending
  runner, forever. Semantic treats nil and empty as equal, understands
  resource.Quantity, and cannot panic on unexported fields the way cmp can.
  It is also roughly six times cheaper than cmp.Equal on a realistic spec.
- `Semantic.DeepDerivative` for the listener pod, because the live pod
  carries many fields the desired pod never sets (nodeName, dnsPolicy,
  default tolerations, the kube-api-access volume, ...). DeepEqual there
  would spin in a delete/create loop. Container port length is checked
  separately, since ports come from the --listener-metrics-addr flag rather
  than from a resource, so disabling metrics would otherwise leave the port
  on the pod forever.

Drift detection is deliberately not short-circuited on
metadata.generation. Re-registration changes the runner scale set ID
through an annotation, and metadata changes do not bump generation, so a
generation-based shortcut would leave the EphemeralRunnerSet pointing at a
scale set that no longer exists. The measured saving did not justify the
risk.

Additionally:

- Count deleting runners toward the scale-up total so terminating runners
  are not double-replaced.
- Cleanup of finished runners is no longer deferred; failures now surface as
  reconcile errors instead of being logged and swallowed.
- Status patches for the new fields use `RetryOnConflict` against a freshly
  read object.
- Keep merging EphemeralRunnerSet annotations and labels rather than
  overwriting them, so metadata applied by admission webhooks or other
  controllers is preserved. Drift detection compares against the merge
  result so foreign keys cannot cause a permanent patch loop.
- Add unit tests and benchmarks for both drift checks, including a guard
  that fails if the listener comparison is ever tightened to DeepEqual.
- Cover the re-registration path, which previously had no assertion that
  the new runner scale set ID reaches the EphemeralRunnerSet at all.
2026-09-07 22:08:17 +02:00
Nikola Jokic 54147cfa5e Introduce cache for lookups of desired resource state, to reduce the amount of allocations in the controller (#4568) 2026-09-07 13:49:28 +02:00
Junya Okabe 87592be6d3 Remove orphaned testserver package (#4620) 2026-09-07 10:40:28 +02:00
dependabot[bot] a4ac89e2a7 Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#4562)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-03 16:45:00 +01:00
Diogo Torres 3cfdcf59fe Re-register the runner scale set when it is gone from the Actions service (#4571) 2026-09-03 08:16:06 +01:00
github-actions[bot] 438440e92a Updates: runner to v2.337.0 (#4613)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-31 16:53:02 +01:00
github-actions[bot] a035c5a393 Updates: runner to v2.336.0 (#4578)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-21 15:51:06 +02:00
dependabot[bot]andNikola Jokic 252eb51766 Bump the actions group across 1 directory with 6 updates (#4559)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikola Jokic <jokicnikola07@gmail.com>
2026-07-15 14:44:09 +02:00
Nikola Jokic 03463c051c Fix deprecated calls (#4570) 2026-07-14 19:34:13 +02:00
Nikola Jokic f6a3d738de Use metrics to display runner statuses instead of status field for EphemeralRunnerSet and AutoscalingRunnerSet (#4557) 2026-07-14 19:31:11 +02:00
Nikola Jokic 368e2f28b8 Use Patch instead of Update (#4533) 2026-07-10 12:34:40 +02:00
Nikola Jokic 2fa72b510f Tag fields with optional allowing patches without issues (#4528) 2026-07-10 12:28:10 +02:00
Junya Okabe 68c0a86188 Mark generated files as linguist-generated (#4536) 2026-07-09 14:22:46 +02:00
Junya Okabe e06294f5de Make controller terminationGracePeriodSeconds configurable and align it with graceful shutdown timeout (#4556) 2026-07-07 00:28:57 +02:00
Junya Okabe 2ee6b3b8e8 Increase e2e wait timeouts to reduce flakiness (#4545) 2026-06-30 15:05:58 +02:00
dependabot[bot] 24686a974e Bump the actions group across 1 directory with 2 updates (#4539)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-27 18:30:32 +02:00
dependabot[bot] c7005c3696 Bump the gomod group across 1 directory with 11 updates (#4529)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-19 13:08:17 +02:00
Nikola Jokic 9c50514160 Fix typo and rename status to phase (#4506) 2026-06-15 12:51:13 +02:00
github-actions[bot] 391bc57773 Updates: runner to v2.335.1 (#4523)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-12 16:28:17 +02:00
Nikola Jokic 767e58e4b1 Upgrade resources in-place, causing 1-1 mapping between autoscaling runner set and ephemeral runner set (#4516) 2026-06-09 13:52:37 +02:00
dependabot[bot] 0acef229e2 Bump the actions group across 1 directory with 6 updates (#4518)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 10:50:43 +02:00
dependabot[bot]andJiaren Wu 0dc5f8a0c2 Bump the gomod group across 1 directory with 9 updates (#4508)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jiaren Wu <jiaren-wu@github.com>
2026-05-30 00:55:53 +02:00
Junya Okabe 631f39bb2a Add context: . to the docker/build-push-action (#4501) 2026-05-25 17:57:05 +02:00
Nikola Jokic 30879de182 Fix patch on autoscaling runner set when creating a runner scale set (#4502) 2026-05-22 17:51:47 +02:00
Nikola Jokic 5ca85bde2d Do not use EqualFold when checking u.Host (#4496) 2026-05-22 17:01:37 +02:00
Francesco RenziandCopilot 9bb16ae49d Prepare 0.14.2 release (#4503)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
gha-runner-scale-set-0.14.2
2026-05-22 12:07:13 +02:00
Nikola Jokic 7638475e3c Bump Go to 1.26.3 (#4504) 2026-05-22 12:04:06 +02:00
Nikola Jokic 8ecfbc63bf Revert "Fix typo and rename status to phase" (#4505) 2026-05-22 11:58:48 +02:00
Nikola Jokic 79ddd38442 Port rate limiter to experimental charts (#4478) 2026-05-22 11:45:09 +02:00
Nikola Jokic dfcbd8344b Fix helm chart validation workflow (#4479) 2026-05-22 11:43:54 +02:00
63ef8241a0 Bump Go to 1.26.2 to fix critical security vulnerabilities (#4491)
Co-authored-by: Dhawal Seth <dseth@linkedin.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-05-22 09:54:37 +01:00
Nikola Jokic 8cb3f49049 Update CODEOWNERS (#4495) 2026-05-13 00:18:57 +02:00
Nikola Jokic 8eb6cbe79f Fix typo and rename status to phase (#4466) 2026-05-13 00:17:08 +02:00
Nikola Jokic e7b6482761 Fix job execution duration when runner assign time is not set (#4472) 2026-05-11 15:57:43 +02:00
Nikola Jokic 081b9ce1ee Fix secret reconciliation updates for the listener pod (#4492) 2026-05-11 15:04:07 +02:00
Nikola Jokic ef48f429b3 Render empty arrays for kubernetes-novolume volumes fields (#4461) 2026-05-11 13:56:01 +02:00
dependabot[bot]andNikola Jokic 9d3ed7cb58 Bump the actions group with 3 updates (#4483)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nikola Jokic <jokicnikola07@gmail.com>
2026-05-11 13:52:41 +02:00
Junya Okabe 0f2a659878 Fix: Detect init container failure in EphemeralRunner controller (#4457) 2026-05-07 13:26:46 +02:00
Junya Okabe 8c84ab2f42 Fix empty GVK in OwnerReferences for modern controllers (#4475) 2026-04-29 19:29:09 +02:00
Junya Okabe 053b8f9ae5 Add health and readiness probes to controller manager (#4459) 2026-04-29 18:08:46 +02:00
Junya Okabe 13a03302c8 Add a flag for enabling pprof on the controller manager (#4449) 2026-04-24 10:03:26 +02:00
Junya Okabe a401686bd5 Add option to disable workqueue bucket rate limiter (#4451) 2026-04-22 23:26:39 +02:00
github-actions[bot] 012f1a5b23 Updates: runner to v2.334.0 (#4467)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-04-22 17:26:50 +02:00
Gleb Khaykin e0feb3b711 Fix orphan no-permission ServiceAccount in kubernetes-novolume mode (#4455) 2026-04-20 13:31:23 +02:00
Francesco Renzi 74cfc3855e Prepare 0.14.1 release (#4448) gha-runner-scale-set-0.14.1 2026-04-14 17:03:22 +01:00
Francesco Renzi eb1544f848 Bump actions/scaleset to v0.3.0 (#4447) 2026-04-14 14:08:22 +01:00
Nikola Jokic 79e7b17b56 Fix null field for resource metadata fields in experimental chart (#4419) 2026-04-02 23:44:37 +02:00
github-actions[bot] 39934ce5eb Updates: runner to v2.333.1 (#4427)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-31 19:35:28 -05:00