Skip to content
File

Blob: .github/workflows/internal-build.yml

yaml81 lines
1name: Run internal build
2 
3on:
4 pull_request_target:
5 
6# Read-only permissions are enough
7permissions: read-all
8 
9concurrency:
10 # Cancel existing builds for the same PR.
11 # Otherwise, all other builds will be allowed to run through.
12 group: internal-build-${{ github.event.pull_request.number || github.run_id }}
13 cancel-in-progress: true
14 
15jobs:
16 internal-build:
17 runs-on: ubuntu-latest
18 steps:
19 # Check if this is a fork and if the author is a Cloudflare org member
20 - name: Check fork status and org membership
21 if: github.event.pull_request.head.repo.fork
22 env:
23 GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
24 AUTHOR: ${{ github.event.pull_request.user.login }}
25 run: |
26 echo "Fork detected. Checking if $AUTHOR is a Cloudflare org member..."
27
28 if gh api orgs/cloudflare/members/$AUTHOR --silent 2>/dev/null; then
29 echo "✓ Cloudflare org member confirmed"
30 else
31 echo "✗ Not a Cloudflare org public member"
32 echo ""
33 echo "This workflow only runs for forks from Cloudflare organization public members."
34 echo "If you're an external contributor, please ask the auto-assigned reviewers"
35 echo "to run the internal build workflow on your behalf."
36 exit 1
37 fi
38 
39 # Try to checkout the merge commit - will fail if PR isn't mergeable
40 - uses: actions/checkout@v4
41 id: checkout_merge
42 continue-on-error: true
43 with:
44 ref: refs/pull/${{ github.event.pull_request.number }}/merge
45 show-progress: false
46 
47 # Fail the workflow if checkout failed (PR isn't mergeable)
48 - name: Fail if PR isn't mergeable
49 if: steps.checkout_merge.outcome != 'success'
50 run: |
51 echo "The pull request is not mergeable. Please rebase and resolve any conflicts."
52 exit 1
53
54 - name: Get merge commit SHA
55 id: get_sha
56 run: echo "sha=$(git rev-parse HEAD)" >> $GITHUB_OUTPUT
57 - name: Run internal build
58 env:
59 CI_URL: ${{ secrets.CI_URL }}
60 CI_CLIENT_ID: ${{ secrets.CI_CF_ACCESS_CLIENT_ID }}
61 CI_CLIENT_SECRET: ${{ secrets.CI_CF_ACCESS_CLIENT_SECRET }}
62 HEAD_REF: ${{ github.event.pull_request.head.ref }}
63 USER_LOGIN: ${{ github.event.pull_request.user.login }}
64 run: |
65 # Format ref based on whether this is a fork
66 if [ "${{ github.event.pull_request.head.repo.fork }}" = "true" ]; then
67 REF="$USER_LOGIN/$HEAD_REF"
68 else
69 REF="$HEAD_REF"
70 fi
71
72 python3 -u ./tools/cross/internal_build.py \
73 ${{github.event.pull_request.number}} \
74 ${{steps.get_sha.outputs.sha}} \
75 ${{github.event.pull_request.head.sha}} \
76 ${{github.run_attempt}} \
77 "$REF" \
78 $CI_URL \
79 $CI_CLIENT_ID \
80 $CI_CLIENT_SECRET