fix(cloud): run pre-checkout steps from the repo root and reach the lease tests from cloud/

defaults.run.working-directory: cloud does not exist before actions/checkout,
so the eight guard/gate steps that run first (and the two checkout-free jobs,
clock-skew and requeue) failed to start. Pin those steps to '.'. The pretest
lease-action paths are ../.github from cloud/, and the two bare pnpm setups
read cloud/package.json instead of the root's pnpm 12. Cloud Verify now also
triggers on the lease action.
This commit is contained in:
Jinwoo-H
2026-09-03 06:35:31 -04:00
parent 477509683f
commit ddab2bbede
11 changed files with 15 additions and 1 deletions
@@ -66,6 +66,7 @@ jobs:
SOURCE_WAVE_RUN_ID: ${{ inputs.source-wave-run-id }}
steps:
- name: Require exact reusable-workflow invocation
working-directory: .
run: |
[[ "${DEPLOY_MODE}" =~ ^(verify|apply|rollback)$ ]]
if test "${EVIDENCE_MODE}" = continuation; then
@@ -86,6 +87,7 @@ jobs:
fi
- name: Require production workflow configuration
working-directory: .
env:
DEPLOY_WORKLOAD_IDENTITY_PROVIDER: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_WORKLOAD_IDENTITY_PROVIDER }}
DEPLOY_SERVICE_ACCOUNT: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }}
@@ -119,6 +119,7 @@ jobs:
WAVE_CELL_IDS: ${{ inputs.wave-cell-ids }}
steps:
- name: Require production workflow configuration
working-directory: .
env:
DEPLOY_WORKLOAD_IDENTITY_PROVIDER: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_WORKLOAD_IDENTITY_PROVIDER }}
DEPLOY_SERVICE_ACCOUNT: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }}
@@ -55,6 +55,7 @@ jobs:
OUTPUT_DIRECTORY: ${{ github.workspace }}/relay-monitor-evidence
steps:
- name: Require exact reusable-workflow configuration
working-directory: .
env:
DEPLOY_WIF: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_WORKLOAD_IDENTITY_PROVIDER }}
DEPLOY_SERVICE_ACCOUNT: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }}
@@ -24,6 +24,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Measure Date-header skew for every relay cell
working-directory: .
run: |
set -u
# Date headers carry whole seconds; compare floored seconds on both
@@ -172,6 +172,8 @@ jobs:
node-version: 24
- uses: pnpm/action-setup@v4
with:
package_json_file: cloud/package.json
if: ${{ inputs.environment == 'production' && inputs.mode == 'promote' && inputs.cell-ids == 'production-gce-c27' }}
- name: Install exact C27 canary dependencies
@@ -58,6 +58,7 @@ jobs:
OUTPUT_DIRECTORY: ${{ github.workspace }}/relay-monitor-evidence
steps:
- name: Require exact reusable-workflow configuration
working-directory: .
env:
DEPLOY_WIF: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_WORKLOAD_IDENTITY_PROVIDER }}
DEPLOY_SERVICE_ACCOUNT: ${{ vars.PRODUCTION_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }}
@@ -85,6 +85,8 @@ jobs:
node-version: 24
- uses: pnpm/action-setup@v4
with:
package_json_file: cloud/package.json
- name: Require the exact staging director image before promotion
env:
@@ -29,6 +29,7 @@ jobs:
recover: ${{ steps.trigger.outputs.recover }}
steps:
- name: Bind recovery to the exact failed C4 job
working-directory: .
id: trigger
env:
CONFIRMATION: ${{ inputs.confirmation }}
@@ -24,6 +24,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Requeue only a cancelled protected recovery job
working-directory: .
env:
GH_TOKEN: ${{ github.token }}
SOURCE_RUN_ID: ${{ github.event.workflow_run.id }}
+2
View File
@@ -5,11 +5,13 @@ on:
paths:
- cloud/**
- .github/workflows/cloud-*.yml
- .github/actions/cloud-sql-rollout-lease/**
push:
branches: [main]
paths:
- cloud/**
- .github/workflows/cloud-*.yml
- .github/actions/cloud-sql-rollout-lease/**
permissions:
contents: read