You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Migrate quality.yml's inline ci-target router onto the shared ci-router.yml #2571
quality.yml still carries the trust-gate + heartbeat-liveness script as an inline ci-target job (~120 lines), while #2568 introduced the shared reusable router .github/workflows/ci-router.yml that containers.yml / security.yml / pages.yml already consume.
Why migrate
One decision procedure instead of two copies that can drift (the shared copy already treats schedule as trusted; the inline copy predates that).
Frees quality.yml's header comment of the router mechanics; the full rationale then lives once, in ci-router.yml and docs/CI-CD.md.
quality.yml must grant actions: write at workflow level (caller-obligation documented in ci-router.yml's header: a called reusable workflow can never exceed the caller's GITHUB_TOKEN envelope, and under-granting startup-fails the whole run as "Invalid workflow file" — hit live on ci: route all workflows homeserver-first with GitHub-hosted fallback #2568's first push). Today quality.yml's inline router elevates actions: write at its own job level, which is why it never needed the workflow-level grant.
The check-run name changes shape: inline router = Pick CI executor, reusable = Pick CI executor / Pick CI executor (caller/callee). No branch protection exists on main, so nothing matches on the exact name today — keep it that way or note the rename wherever it matters.
Acceptance
quality.yml routes identically on a same-repo PR (homeserver=true when the box answers the heartbeat, fallback otherwise), with the inline job gone.
quality.yml still carries the trust-gate + heartbeat-liveness script as an inline
ci-targetjob (~120 lines), while #2568 introduced the shared reusable router.github/workflows/ci-router.ymlthat containers.yml / security.yml / pages.yml already consume.Why migrate
scheduleas trusted; the inline copy predates that).What it takes
ci-targetjob withuses: ./.github/workflows/ci-router.yml+with: ci_homeserver_prs: ${{ vars.CI_HOMESERVER_PRS || '' }}.actions: writeat workflow level (caller-obligation documented in ci-router.yml's header: a called reusable workflow can never exceed the caller's GITHUB_TOKEN envelope, and under-granting startup-fails the whole run as "Invalid workflow file" — hit live on ci: route all workflows homeserver-first with GitHub-hosted fallback #2568's first push). Today quality.yml's inline router elevatesactions: writeat its own job level, which is why it never needed the workflow-level grant.Pick CI executor, reusable =Pick CI executor / Pick CI executor(caller/callee). No branch protection exists onmain, so nothing matches on the exact name today — keep it that way or note the rename wherever it matters.Acceptance