workflows: Run on ubuntu-26.04 and use bootc-ubuntu-setup - #122
Merged
Merged
Conversation
Match bootc's CI, which runs on ubuntu-26.04, and pin the image rather than floating on ubuntu-latest as AGENTS.md asks. bootc-ubuntu-setup, which the next commit uses for the drafter's tools, also only supports 24.04 and 26.04. The detection job needs its own override: gh-aw hardcodes ubuntu-latest for it rather than following runs-on. The framework jobs stay on gh-aw's default ubuntu-slim. Since gh-aw doesn't know the ubuntu-26.04 label, it treats it as a custom runner and adds a setup-node step to the agent job. Generated-by: AI Signed-off-by: Colin Walters <walters@verbum.org>
Use the org's standard runner setup action rather than an ad-hoc apt install of just, so these agents get the same host environment as the rest of bootc-dev's CI. It doesn't cover the gh-aw CLI, so that still comes from the gh-aw runtime. gh-aw pins the action to the SHA main resolved to at compile time (recorded in .github/aw/actions-lock.json), so picking up later changes to it needs a recompile. Generated-by: AI Signed-off-by: Colin Walters <walters@verbum.org>
cgwalters
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #117: run the gh-aw workflows on
ubuntu-26.04, and install the drafter's and fix's tools withbootc-dev/actions/bootc-ubuntu-setupinstead of apt-installingjustdirectly.The first commit sets
runs-on: ubuntu-26.04on all five workflows, their custom label jobs and theworkflow_rerunsafe-output job. The detection job needssafe-outputs.threat-detection.runs-ontoo: gh-aw 0.88.2 hardcodesubuntu-latestfor it despite its docs saying it followsruns-on. The framework jobs (activation, safe_outputs, conclusion) stay on gh-aw's defaultubuntu-slim. gh-aw doesn't haveubuntu-26.04on its list of known runners, so it treats it as a custom runner and adds anactions/setup-nodestep to the agent job.The second commit replaces the apt step in
shared/workflow-tools.mdwithbootc-ubuntu-setup(no inputs; libvirt stays off). That action installsjustbut not gh-aw, so the gh-aw runtime still provides the CLI. gh-aw pins@mainto the SHA it resolved at compile time (40859f0, recorded in.github/aw/actions-lock.json), so the lock files only pick up later changes to the action after a recompile.Caveat: the action also frees disk space. It removes packages with apt in the foreground, which adds time to each drafter/fix run, and it starts a background
docker image prune --all. The AWF images are pulled later in the agent job, so they shouldn't collide, but that hasn't been exercised on a real run yet.Testing, on devspace cgwalters-devspace-36783890622 with the gh-aw v0.88.2 release binary:
gh aw compile drafter review fix queue-triage ci-triage --approvesucceeds for each commit. Rerunningci.yml's check-drift steps on a fresh clone of each commit (node checks,node tests/workflow-rerun.test.js, compile,git diff --exit-code -- .github/workflows/) shows no drift.ubuntu-26.04label yet. With that label allowed in its config, its findings match main's exactly.The
Signed-off-by: Colin Walters <walters@verbum.org>on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#3 (review)Generated-by: https://github.com/cgwalters/#llms