ci: use upstream cncf/prow-github-actions; fix needs-kind label issue; consolidate prow workflow files

Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
Jan Larwig
2026-09-28 17:18:26 +02:00
parent 4238ee1b32
commit 55824eb0e3
4 changed files with 40 additions and 55 deletions
+1
View File
@@ -50,4 +50,5 @@ require_matching_label:
missing_comment: "Please add a kind label with /kind <value>." missing_comment: "Please add a kind label with /kind <value>."
tide: tide:
# Scheduled sweep/lgtm jobs ignore this setting; do not enable them.
merge_on_events: false merge_on_events: false
-20
View File
@@ -1,20 +0,0 @@
name: Sync Prow Labels
on:
workflow_dispatch:
push:
branches: [master]
paths: [.github/prow.yaml]
permissions:
contents: read
issues: write
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main
with:
jobs: label-sync
github-token: ${{ secrets.GITHUB_TOKEN }}
+34 -32
View File
@@ -7,44 +7,46 @@ on:
types: [opened, reopened, labeled, unlabeled] types: [opened, reopened, labeled, unlabeled]
pull_request_target: pull_request_target:
types: [opened, reopened, synchronize, ready_for_review, labeled, unlabeled] types: [opened, reopened, synchronize, ready_for_review, labeled, unlabeled]
push:
branches: [master]
paths: [.github/prow.yaml, .github/workflows/prow.yml]
workflow_dispatch:
permissions: permissions:
contents: read contents: read
issues: write
pull-requests: write # Keep every comment command; never interrupt a run while it is updating labels.
concurrency:
group: prow-${{ github.event_name }}-${{ github.event.action }}-${{ github.event.comment.id || github.event.pull_request.number || github.event.issue.number || github.run_id }}
cancel-in-progress: false
jobs: jobs:
public-commands: prow:
if: github.event_name == 'issue_comment' if: github.event_name != 'workflow_dispatch' && github.event_name != 'push'
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
issues: write
pull-requests: write
statuses: write
steps: steps:
- uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main # Never check out or execute PR code in this privileged workflow.
with: - uses: cncf/prow-github-actions@187c5e3cd95a329c43448e1bdb3b1f5249232e44 # v3.0.1
prow-commands: /assign /unassign /area /kind /provider /help
github-token: ${{ secrets.GITHUB_TOKEN }}
review-commands:
if: github.event_name == 'issue_comment' && github.event.issue.pull_request != null
runs-on: ubuntu-latest
steps:
- uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main
with:
prow-commands: /lgtm
github-token: ${{ secrets.GITHUB_TOKEN }}
issue-label-requirements:
if: github.event_name == 'issues'
runs-on: ubuntu-latest
steps:
- uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
pull-request-labels:
if: github.event_name == 'pull_request_target'
runs-on: ubuntu-latest
steps:
- uses: oauth2-proxy/prow-github-actions@c5ba2c6994ab70e129b5d028ba885f02ba44db65 # main
with: with:
prow-commands: /assign /unassign /area /kind /provider /help ${{ github.event.issue.pull_request != null && '/lgtm' || '' }}
jobs: lgtm jobs: lgtm
github-token: ${{ secrets.GITHUB_TOKEN }} github-token: ${{ github.token }}
label-sync:
if: github.event_name == 'workflow_dispatch' || github.event_name == 'push'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
issues: write
steps:
- uses: cncf/prow-github-actions@187c5e3cd95a329c43448e1bdb3b1f5249232e44 # v3.0.1
with:
jobs: label-sync
github-token: ${{ github.token }}
+5 -3
View File
@@ -105,9 +105,11 @@ comments:
- `/help` adds the `help wanted` label. - `/help` adds the `help wanted` label.
On pull requests only, project reviewers may also use `/lgtm` and On pull requests only, project reviewers may also use `/lgtm` and
`/lgtm cancel` to manage the review-readiness label. A new commit removes the `/lgtm cancel` to manage the review-readiness label.
`lgtm` label. The label does not merge a pull request or replace GitHub Use the command rather than manually applying the label.
approval requirements. The label does not merge a pull request or replace GitHub approval requirements.
Issues and pull requests require a `kind/*` label. Use `/kind <value>` to add one.
## AI use ## AI use