Skip to content

workflows: Run on ubuntu-26.04 and use bootc-ubuntu-setup - #122

Merged
cgwalters merged 2 commits into
bootc-dev:mainfrom
cgwalters-forge:bot/ghaw-ubuntu-2604
Oct 1, 2026
Merged

cgwalters merged 2 commits into
bootc-dev:mainfrom
cgwalters-forge:bot/ghaw-ubuntu-2604

Conversation

@cgwalters-bot

Copy link
Copy Markdown
Contributor

Follow-up to #117: run the gh-aw workflows on ubuntu-26.04, and install the drafter's and fix's tools with bootc-dev/actions/bootc-ubuntu-setup instead of apt-installing just directly.

The first commit sets runs-on: ubuntu-26.04 on all five workflows, their custom label jobs and the workflow_rerun safe-output job. The detection job needs safe-outputs.threat-detection.runs-on too: gh-aw 0.88.2 hardcodes ubuntu-latest for it despite its docs saying it follows runs-on. The framework jobs (activation, safe_outputs, conclusion) stay on gh-aw's default ubuntu-slim. gh-aw doesn't have ubuntu-26.04 on its list of known runners, so it treats it as a custom runner and adds an actions/setup-node step to the agent job.

The second commit replaces the apt step in shared/workflow-tools.md with bootc-ubuntu-setup (no inputs; libvirt stays off). That action installs just but not gh-aw, so the gh-aw runtime still provides the CLI. gh-aw pins @main to the SHA it resolved at compile time (40859f0, recorded in .github/aw/actions-lock.json), so the lock files only pick up later changes to the action after a recompile.

Caveat: the action also frees disk space. It removes packages with apt in the foreground, which adds time to each drafter/fix run, and it starts a background docker image prune --all. The AWF images are pulled later in the agent job, so they shouldn't collide, but that hasn't been exercised on a real run yet.

Testing, on devspace cgwalters-devspace-36783890622 with the gh-aw v0.88.2 release binary:

  • gh aw compile drafter review fix queue-triage ci-triage --approve succeeds for each commit. Rerunning ci.yml's check-drift steps on a fresh clone of each commit (node checks, node tests/workflow-rerun.test.js, compile, git diff --exit-code -- .github/workflows/) shows no drift.
  • actionlint 1.7.12 (the latest release) reports only one kind of finding that main doesn't: it doesn't know the ubuntu-26.04 label yet. With that label allowed in its config, its findings match main's exactly.
  • The workflows themselves haven't run on 26.04, since they need the org's app and secrets.

The Signed-off-by: Colin Walters <walters@verbum.org> on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#3 (review)

Generated-by: https://github.com/cgwalters/#llms

Match bootc's CI, which runs on ubuntu-26.04, and pin the image rather
than floating on ubuntu-latest as AGENTS.md asks. bootc-ubuntu-setup,
which the next commit uses for the drafter's tools, also only supports
24.04 and 26.04.

The detection job needs its own override: gh-aw hardcodes
ubuntu-latest for it rather than following runs-on. The framework jobs
stay on gh-aw's default ubuntu-slim. Since gh-aw doesn't know the
ubuntu-26.04 label, it treats it as a custom runner and adds a
setup-node step to the agent job.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
Use the org's standard runner setup action rather than an ad-hoc apt
install of just, so these agents get the same host environment as the
rest of bootc-dev's CI. It doesn't cover the gh-aw CLI, so that still
comes from the gh-aw runtime.

gh-aw pins the action to the SHA main resolved to at compile time
(recorded in .github/aw/actions-lock.json), so picking up later changes
to it needs a recompile.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
@cgwalters
cgwalters merged commit f1b7feb into bootc-dev:main Oct 1, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants