From 55824eb0e3bc1a6de7d6891d7c20588d698b67ae Mon Sep 17 00:00:00 2001 From: Jan Larwig Date: Mon, 28 Sep 2026 17:18:26 +0200 Subject: [PATCH] ci: use upstream cncf/prow-github-actions; fix needs-kind label issue; consolidate prow workflow files Signed-off-by: Jan Larwig --- .github/prow.yaml | 1 + .github/workflows/prow-label-sync.yml | 20 -------- .github/workflows/prow.yml | 66 ++++++++++++++------------- CONTRIBUTING.md | 8 ++-- 4 files changed, 40 insertions(+), 55 deletions(-) delete mode 100644 .github/workflows/prow-label-sync.yml diff --git a/.github/prow.yaml b/.github/prow.yaml index 30d1863f..5986c1a0 100644 --- a/.github/prow.yaml +++ b/.github/prow.yaml @@ -50,4 +50,5 @@ require_matching_label: missing_comment: "Please add a kind label with /kind ." tide: + # Scheduled sweep/lgtm jobs ignore this setting; do not enable them. merge_on_events: false diff --git a/.github/workflows/prow-label-sync.yml b/.github/workflows/prow-label-sync.yml deleted file mode 100644 index b04715d0..00000000 --- a/.github/workflows/prow-label-sync.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: Sync Prow Labels - -on: - workflow_dispatch: - push: - branches: [master] - paths: [.github/prow.yaml] - -permissions: - contents: read - issues: write - -jobs: - sync: - runs-on: ubuntu-latest - steps: - - uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main - with: - jobs: label-sync - github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/prow.yml b/.github/workflows/prow.yml index a12d169f..6e454706 100644 --- a/.github/workflows/prow.yml +++ b/.github/workflows/prow.yml @@ -7,44 +7,46 @@ on: types: [opened, reopened, labeled, unlabeled] pull_request_target: types: [opened, reopened, synchronize, ready_for_review, labeled, unlabeled] + push: + branches: [master] + paths: [.github/prow.yaml, .github/workflows/prow.yml] + workflow_dispatch: permissions: contents: read - issues: write - pull-requests: write + +# Keep every comment command; never interrupt a run while it is updating labels. +concurrency: + group: prow-${{ github.event_name }}-${{ github.event.action }}-${{ github.event.comment.id || github.event.pull_request.number || github.event.issue.number || github.run_id }} + cancel-in-progress: false jobs: - public-commands: - if: github.event_name == 'issue_comment' + prow: + if: github.event_name != 'workflow_dispatch' && github.event_name != 'push' runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + issues: write + pull-requests: write + statuses: write steps: - - uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main - with: - prow-commands: /assign /unassign /area /kind /provider /help - github-token: ${{ secrets.GITHUB_TOKEN }} - - review-commands: - if: github.event_name == 'issue_comment' && github.event.issue.pull_request != null - runs-on: ubuntu-latest - steps: - - uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main - with: - prow-commands: /lgtm - github-token: ${{ secrets.GITHUB_TOKEN }} - - issue-label-requirements: - if: github.event_name == 'issues' - runs-on: ubuntu-latest - steps: - - uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main - with: - github-token: ${{ secrets.GITHUB_TOKEN }} - - pull-request-labels: - if: github.event_name == 'pull_request_target' - runs-on: ubuntu-latest - steps: - - uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main + # Never check out or execute PR code in this privileged workflow. + - uses: cncf/prow-github-actions@187c5e3cd95a329c43448e1bdb3b1f5249232e44 # v3.0.1 with: + prow-commands: /assign /unassign /area /kind /provider /help ${{ github.event.issue.pull_request != null && '/lgtm' || '' }} jobs: lgtm - github-token: ${{ secrets.GITHUB_TOKEN }} + github-token: ${{ github.token }} + + label-sync: + if: github.event_name == 'workflow_dispatch' || github.event_name == 'push' + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: read + issues: write + steps: + - uses: cncf/prow-github-actions@187c5e3cd95a329c43448e1bdb3b1f5249232e44 # v3.0.1 + with: + jobs: label-sync + github-token: ${{ github.token }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a05c5be6..882e26c3 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -105,9 +105,11 @@ comments: - `/help` adds the `help wanted` label. On pull requests only, project reviewers may also use `/lgtm` and -`/lgtm cancel` to manage the review-readiness label. A new commit removes the -`lgtm` label. The label does not merge a pull request or replace GitHub -approval requirements. +`/lgtm cancel` to manage the review-readiness label. +Use the command rather than manually applying the label. +The label does not merge a pull request or replace GitHub approval requirements. + +Issues and pull requests require a `kind/*` label. Use `/kind ` to add one. ## AI use