Skip to content

Add CI for the shared workflows - #3

Merged
nickhart merged 1 commit into
mainfrom
ci/validate-workflows
Sep 14, 2026
Merged

nickhart merged 1 commit into
mainfrom
ci/validate-workflows

Conversation

@nickhart

Copy link
Copy Markdown
Contributor

This repo has no tests and nothing to build, but a mistake here breaks all three sites at once — and a workflow that fails to load reports only startup_failure, with no logs and nothing on the annotations endpoint. Finding one of those cost a five-cycle bisection.

So the checks target the failure modes that actually happened here.

actionlint

It earned its place before being installed: it caught github.job_workflow_sha as an undefined property — a bug already shipped and documented as a fix, which five production runs then confirmed resolved to an empty string. Fixed in #2.

It also runs shellcheck over every run: block, which matters because the worst bugs in these workflows have been shell rather than YAML:

  • a || true that swallowed an exit code and emailed gh's error body in place of a link
  • a heredoc that fed only its first line to the interpreter

What it does not catch, recorded in the comments so nobody assumes more of it: semantic workflow_call rules. vars.X being unavailable in a called workflow, and runner.temp in a with: block, both lint clean and both cost a bisection cycle.

The other two checks

  • node --check on the shared script, which is fetched and executed at runtime — so a syntax error there surfaces as a failed notification, not a parse error.
  • A declared-inputs check. A workflow_call input used but never declared parses fine and arrives empty, the same silent class as the pin bug. Verified it fails on an undeclared input and an undeclared secret, and anchored on ^ workflow_call: so a mention in a comment does not count.

Green on arrival

actionlint exits 0 on this branch now that #2 has landed. That ordering was deliberate — shipping a check that is already failing is how checks get ignored, which is the mistake made with the MDX check earlier.

.github/actionlint.yaml (already on main) suppresses one style-only shellcheck rule with its reason recorded. Anything that could be a real bug stays on.

After merging

Add ci as a required status check on this repo's ruleset, matching post-inbox. The context is the bare job id — ci, not ci / ci — because this job is inline rather than a reusable workflow.

🤖 Generated with Claude Code

This repo has no tests and nothing to build, but a mistake here breaks all
three sites at once, and a workflow that fails to load reports only
`startup_failure` with no logs and nothing on the annotations endpoint.
Finding one of those cost a five-cycle bisection.

So the checks target the failure modes that actually happened:

- **actionlint**, which validates expressions against real context types and
  runs shellcheck over every `run:` block. It earned its place before being
  installed: it flagged `github.job_workflow_sha` as undefined, which five
  production runs then confirmed resolves to an empty string — a pin that was
  not pinning anything. And the worst bugs in these workflows have been shell
  rather than YAML: a `|| true` that swallowed an exit code and emailed an
  error body as a link, and a heredoc that fed one line to the interpreter.
- **`node --check`** on the shared script, which is fetched and run at runtime,
  so a syntax error in it surfaces as a failed notification.
- **A declared-inputs check**, since a `workflow_call` input used but never
  declared parses fine and arrives empty — the same silent class as the pin
  bug. Verified it fails on an undeclared input and an undeclared secret.

The comments say what actionlint does *not* catch, so nobody assumes more of
it than it gives: `vars.X` in a called workflow and `runner.temp` in a `with:`
block both lint clean and both cost a cycle.

`.github/actionlint.yaml` suppresses one style-only shellcheck rule with the
reason recorded. Everything that could be a real bug stays on, which is why
this currently exits non-zero on the `job_workflow_sha` line — so the pin fix
must land first, rather than CI going red on its first run for a pre-existing
issue.
@nickhart
nickhart merged commit 8b5ad43 into main Sep 14, 2026
1 check passed
@nickhart
nickhart deleted the ci/validate-workflows branch September 14, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant