chore(ENG-1053): refine CI workflows for PR runner security and merge efficiency - #504
Open
lucas-koontz wants to merge 3 commits into
Open
chore(ENG-1053): refine CI workflows for PR runner security and merge efficiency#504lucas-koontz wants to merge 3 commits into
lucas-koontz wants to merge 3 commits into
Conversation
… efficiency Introduce guardrails for self-hosted runner use in fork PRs to protect infrastructure credentials. Consolidate redundant workflows into unified pipelines to ensure a consistent and single source of truth for PR and push build statuses. This change reduces duplication and minimizes security risks by ensuring that forked repositories cannot execute code on internal runners.
…uild logic Integrate installer builds into a singular pipeline to reduce redundancy and complexity. Updates ensure the correct environment host is propagated, maintaining consistency across PR deployments. Adjustments reflect the operational shift pointed out in ENG-1053.
PR environment is up ·
|
| Hub (console) | https://pr-cowork-504.dev.mindshub.ai |
| Auth API | https://auth-pr-cowork-504.dev.mindshub.ai |
| Keycloak admin | https://auth-pr-cowork-504.dev.mindshub.ai/auth/admin/ |
| Inference API | https://api-pr-cowork-504.dev.mindshub.ai/v1 |
| cowork-server | https://cowork-pr-cowork-504.dev.mindshub.ai/api |
| Namespace | pr-cowork-504 |
Every service is in this namespace. The ones this PR does not build run the staging image unless you link them with Deploys: in the PR body.
Updated on every push to this PR.
lucas-koontz
temporarily deployed
to
pr-cowork-504
July 27, 2026 01:12 — with
GitHub Actions
Inactive
Installers built ·
|
Update the Kubernetes deployment status check to use `kubectl rollout status` instead of waiting for pod readiness. This change avoids issues with terminating pods in older ReplicaSets causing false negatives, ensuring more reliable deployment confirmations.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change.
Fixes #issue_number
Screenshots
Type of change
Please delete options that are not relevant.
Checklist: