Skip to content

ci(grc): stage central self-hosted Product producer - #2602

Draft
seonghobae wants to merge 10 commits into
ci/sdp-all-self-hosted-20261003from
ci/grc-product-central-split-20261008
Draft

seonghobae wants to merge 10 commits into
ci/sdp-all-self-hosted-20261003from
ci/grc-product-central-split-20261008

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Stage the GRC-owned central workflow_call Product producer on the canonical runner-routing owner #2565. The producer keeps fixed GRC caller admission, same-repository PR policy, dedicated self-hosted group/labels, and no hosted fallback or inherited secrets.

The GRC delta remains four additive paths:

  • .github/workflows/grc-product.yml
  • docs/doctoring/grc-product-central-execution.md
  • docs/templates/grc-product.yml.in
  • tests/test_grc_product_reusable_workflow_contract.py

The comparison also exposes #2609's one prerequisite-owned clock fixture. No implementation from either owner is copied.

Current exact-head topology — 2026-10-09

  • Exact head: ab4a39d818a1d865852e25a97b4200e08ece0bbb
  • Exact tree: 056e49de04c025e2b48ca54c5b53cc11e2612a69
  • First ordinary merge: bb5b297be7b99f584ddf0d587e595e3bbdf0fac2, parents prior GRC head 3f832395800efac06690616b322443ca96e55109 and current runner-policy owner ci: stage all workflows on isolated self-hosted runners #2565 a206770680895adba000d7538fc3d5a5b499149e
  • Second ordinary merge: current head, parents bb5b297be7b99f584ddf0d587e595e3bbdf0fac2 and current-time fixture owner test(codeql): keep current-time fixtures fresh #2609 8ba032a3df47c8f401a7017ae84302c725c2f9c8
  • Base: ci/sdp-all-self-hosted-20261003@a206770680895adba000d7538fc3d5a5b499149e
  • The branch advanced with an expected-head protected, non-force update. No rebase or Force Push occurred.
  • GitHub comparison is ahead 8 / behind 0 with merge-base exactly ci: stage all workflows on isolated self-hosted runners #2565; effective comparison is five files.

Root cause and repair

The prior GRC head was still based on #2565 predecessor 6e924f32a2dbaa0950709c6d8f1391fc1058ef43, while canonical #2565 had advanced to a206770…. The two heads had diverged and the GRC body named stale owner evidence.

The first ordinary merge refreshes the stack without changing the four GRC files. #2609 is added as a second prerequisite because its test fixture is required for a truthful current-date full-suite result. Runner-routing conflicts introduced through #2609's protected-main ancestry were resolved at the single writer: #2565's CWL CI isolated + cwlab-ci-isolated contracts remain byte-equivalent to the owner.

Exact-tree verification

  • GRC + runner-policy + CodeQL-time contracts: 173 passed normally and 173 passed with GITHUB_ACTIONS=true
  • Warning-fatal complete repository suite: 5,498 passed, 10 skipped, 40 subtests
  • 39/39 workflow YAML files parse
  • Python compileall, git diff --check, and clean worktree: GREEN
  • The earlier exact four-file source review is retained as historical source evidence, not formal GitHub approval and not transferred as exact-head acceptance.
  • Current exact-head CodeQL run 37896130857 is in progress. It was not rerun or replaced.

Activation and publication HOLD

Draft / Proposed / merge HOLD. Draft is required because mutable runner-policy prerequisite #2565 is not runtime-ready: isolated capacity, cleanup canary, terminal exact-head Checks, and qualifying approval remain absent.

seonghobae and others added 5 commits October 6, 2026 19:51
GitHub-hosted jobs fail before any step while the account is billing-locked.
These six default-branch schedules now use the CWL MCP remediation group,
which already admits this repository and has online runners.
…lers-to-self-hosted-20261006

ci: run billing-locked central schedules on existing self-hosted runners
The static runner group map left the audit job in the default pool while
those runners were idle. Select the group with the same trusted-main
expression the jobs that already reach it use.
…n-runs-on-20261006

ci: attach trusted schedules to the MCP runner group
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Current authority — exact refreshed stack

This COMMENT is evidence, not approval. No bypass, auto-merge, merge, runner relabeling, ACL expansion, or source-neutral event is authorized.

Copy link
Copy Markdown
Contributor Author

Current authority — exact head efb53f7b44d09614993702e4a20d75c06a190a37

This Draft stack now consumes #2565 causal owner repair 8d4a2eb1061c060360741d4015e4350ffde6a3eb as an ordinary merge parent.

  • exact tree: fd2c357652c17ed865a80d3f12dd24251d935488
  • base: ci/sdp-all-self-hosted-20261003 at that exact owner head
  • child delta remains bounded; the only inherited change is the fail-closed CWL law CI ↔ law-ai-agent-ci contract
  • affected contracts: 43 passed normally and 43 passed with GITHUB_ACTIONS=true
  • git diff --check: GREEN
  • Draft reason remains the mutable owner prerequisite; queued Checks or missing approval are merge blockers only
  • no force push, destructive rebase, rerun, or state toggle

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant