Skip to content

Configure Enterprise CI from settings, not by editing files #559

Configure Enterprise CI from settings, not by editing files

Configure Enterprise CI from settings, not by editing files #559

Workflow file for this run

name: quality
# Portable to a GitHub Enterprise Server fork by setting repository variables only.
# Every default below reproduces the public github.com run exactly, so an unconfigured fork
# behaves the way this repository always has. See docs/ci/enterprise-fork-v1.md for the
# variable list and for the two things a variable cannot express.
#
# The job appears twice because a `container.credentials` block cannot be made conditional: an
# empty one and a `null` one are both rejected before the job starts, and a placeholder credential
# makes an anonymous pull fail a `docker login` it never needed. So the choice is made where a
# choice survives -- `if:` at job level -- and the two jobs share every step through
# `.github/actions/quality`. Name no credential secrets and the first job is the only one that
# runs, exactly as before.
on:
push:
pull_request:
permissions:
contents: read
jobs:
quality:
if: vars.AART_IMAGE_USERNAME_SECRET == ''
name: quality (Python ${{ matrix.python-version }})
runs-on: ${{ fromJSON(vars.AART_RUNNER || '["ubuntu-latest"]') }}
# A company image already carries an interpreter. Leave AART_CI_IMAGE unset and this line
# is inert; set it and pin AART_PYTHON_VERSIONS to one entry, because one image is one Python.
container: ${{ vars.AART_CI_IMAGE }}
strategy:
fail-fast: false
matrix:
python-version: ${{ fromJSON(vars.AART_PYTHON_VERSIONS || '["3.10", "3.14"]') }}
env:
# The tool's own gates need ruff, mypy and coverage. That is the one place this repository
# needs a package index; the registry gates need none. The variable holds the bare host and
# names the secret holding `user:pass`, because a variable cannot hold a credential.
AART_INDEX_URL: ${{ vars.AART_PIP_INDEX_URL || 'https://pypi.org/simple' }}
AART_INDEX_CREDENTIALS: ${{ secrets[vars.AART_PIP_INDEX_CREDENTIALS_SECRET] }}
steps:
- name: Checkout
uses: actions/checkout@v4
- uses: ./.github/actions/quality
with:
python: ${{ vars.AART_PYTHON || 'python' }}
python-version: ${{ matrix.python-version }}
setup-python: ${{ vars.AART_CI_IMAGE == '' }}
quality-private-image:
if: vars.AART_IMAGE_USERNAME_SECRET != ''
name: quality (Python ${{ matrix.python-version }}, private image)
runs-on: ${{ fromJSON(vars.AART_RUNNER || '["ubuntu-latest"]') }}
container:
image: ${{ vars.AART_CI_IMAGE }}
credentials:
username: ${{ secrets[vars.AART_IMAGE_USERNAME_SECRET] }}
password: ${{ secrets[vars.AART_IMAGE_PASSWORD_SECRET] }}
strategy:
fail-fast: false
matrix:
python-version: ${{ fromJSON(vars.AART_PYTHON_VERSIONS || '["3.10", "3.14"]') }}
env:
AART_INDEX_URL: ${{ vars.AART_PIP_INDEX_URL || 'https://pypi.org/simple' }}
AART_INDEX_CREDENTIALS: ${{ secrets[vars.AART_PIP_INDEX_CREDENTIALS_SECRET] }}
steps:
- name: Checkout
uses: actions/checkout@v4
- uses: ./.github/actions/quality
with:
python: ${{ vars.AART_PYTHON || 'python' }}
python-version: ${{ matrix.python-version }}
setup-python: ${{ vars.AART_CI_IMAGE == '' }}