Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 9 additions & 3 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,14 +32,20 @@ jobs:
# https://mirror.keellinux.org/layers, verified, assembled into a scratch
# rootfs, booted in LXC and checked by tests/boot-test.sh. Nothing is
# built there; the build host publishes the layer
# (docs/releases-host.md of the keel repository).
# (docs/releases-host.md of the keel repository). So what boots is the
# layer the mirror publishes, never this branch: a pull request that
# changes the recipe is not exercised by this check, which is why the
# reusable job is called boot-published-layer.
#
# test-appliance.yml targets the labels "self-hosted, keel-lxc"; a job
# aimed at a label no runner carries stays queued until GitHub cancels it
# after 24 hours, so the reusable workflow's contract is that callers gate
# on the organization variable KEEL_LXC_RUNNER (docs/ci-cd.md section 5 of
# the keel repository). This job produces the check
# "appliance / build-and-boot".
# the keel repository). A layer that has never been published fails this
# job instead of passing it; the bootstrap exemption for a repository
# whose first layer does not exist yet is allow_unpublished, and this
# layer is published, so it is not used here. This job produces the check
# "appliance / boot-published-layer".
if: vars.KEEL_LXC_RUNNER == 'true'
uses: keel-linux/.github/.github/workflows/test-appliance.yml@main
with:
Expand Down
9 changes: 7 additions & 2 deletions COVERAGE.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,11 @@ self-hosted `keel-lxc` runner, which fetches the published layer from
`https://mirror.keellinux.org/layers`, verifies it, assembles it, boots it in
LXC and runs `tests/boot-test.sh` against it. Nothing is built there: the
runner has no fab, deck or buildtasks. That job produces the check
`appliance / build-and-boot`.
`appliance / boot-published-layer`, and the name is the point: what boots is
the layer the mirror publishes and not this branch, so a pull request that
changes the recipe is not exercised by it. A layer that has never been
published fails it rather than passing it (keel-linux/.github pull request
12).

### What the gate found once the layer booted (2026-09-27)

Expand Down Expand Up @@ -118,7 +122,8 @@ got, and the removal of the build time source with the disabled
## Plan

- Rebuild and publish `nodebb` now that pull request 1 fixed the conffile
prompt, then require `appliance / build-and-boot` on `main`. Separately,
prompt, then require `appliance / boot-published-layer` on `main`.
Separately,
`bt-layer` should refuse to pack a build whose `make` failed (buildtasks
issue 6), so a broken layer cannot reach the mirror again.
- Keep every decision in lib/nodebb.sh so the hook stays a thin caller.
Expand Down
Loading