File
Blob: .github/workflows/internal-build.yml
| 1 | name: Run internal build |
| 2 | |
| 3 | on: |
| 4 | pull_request_target: |
| 5 | |
| 6 | # Read-only permissions are enough |
| 7 | permissions: read-all |
| 8 | |
| 9 | concurrency: |
| 10 | # Cancel existing builds for the same PR. |
| 11 | # Otherwise, all other builds will be allowed to run through. |
| 12 | group: internal-build-${{ github.event.pull_request.number || github.run_id }} |
| 13 | cancel-in-progress: true |
| 14 | |
| 15 | jobs: |
| 16 | internal-build: |
| 17 | runs-on: ubuntu-latest |
| 18 | steps: |
| 19 | # Check if this is a fork and if the author is a Cloudflare org member |
| 20 | - name: Check fork status and org membership |
| 21 | if: github.event.pull_request.head.repo.fork |
| 22 | env: |
| 23 | GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
| 24 | AUTHOR: ${{ github.event.pull_request.user.login }} |
| 25 | run: | |
| 26 | echo "Fork detected. Checking if $AUTHOR is a Cloudflare org member..." |
| 27 | |
| 28 | if gh api orgs/cloudflare/members/$AUTHOR --silent 2>/dev/null; then |
| 29 | echo "✓ Cloudflare org member confirmed" |
| 30 | else |
| 31 | echo "✗ Not a Cloudflare org public member" |
| 32 | echo "" |
| 33 | echo "This workflow only runs for forks from Cloudflare organization public members." |
| 34 | echo "If you're an external contributor, please ask the auto-assigned reviewers" |
| 35 | echo "to run the internal build workflow on your behalf." |
| 36 | exit 1 |
| 37 | fi |
| 38 | |
| 39 | # Try to checkout the merge commit - will fail if PR isn't mergeable |
| 40 | - uses: actions/checkout@v4 |
| 41 | id: checkout_merge |
| 42 | continue-on-error: true |
| 43 | with: |
| 44 | ref: refs/pull/${{ github.event.pull_request.number }}/merge |
| 45 | show-progress: false |
| 46 | |
| 47 | # Fail the workflow if checkout failed (PR isn't mergeable) |
| 48 | - name: Fail if PR isn't mergeable |
| 49 | if: steps.checkout_merge.outcome != 'success' |
| 50 | run: | |
| 51 | echo "The pull request is not mergeable. Please rebase and resolve any conflicts." |
| 52 | exit 1 |
| 53 | |
| 54 | - name: Get merge commit SHA |
| 55 | id: get_sha |
| 56 | run: echo "sha=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT |
| 57 | - name: Run internal build |
| 58 | env: |
| 59 | CI_URL: ${{ secrets.CI_URL }} |
| 60 | CI_CLIENT_ID: ${{ secrets.CI_CF_ACCESS_CLIENT_ID }} |
| 61 | CI_CLIENT_SECRET: ${{ secrets.CI_CF_ACCESS_CLIENT_SECRET }} |
| 62 | HEAD_REF: ${{ github.event.pull_request.head.ref }} |
| 63 | USER_LOGIN: ${{ github.event.pull_request.user.login }} |
| 64 | run: | |
| 65 | # Format ref based on whether this is a fork |
| 66 | if [ "${{ github.event.pull_request.head.repo.fork }}" = "true" ]; then |
| 67 | REF="$USER_LOGIN/$HEAD_REF" |
| 68 | else |
| 69 | REF="$HEAD_REF" |
| 70 | fi |
| 71 | |
| 72 | python3 -u ./tools/cross/internal_build.py \ |
| 73 | ${{github.event.pull_request.number}} \ |
| 74 | ${{steps.get_sha.outputs.sha}} \ |
| 75 | ${{github.event.pull_request.head.sha}} \ |
| 76 | ${{github.run_attempt}} \ |
| 77 | "$REF" \ |
| 78 | $CI_URL \ |
| 79 | $CI_CLIENT_ID \ |
| 80 | $CI_CLIENT_SECRET |