From 9ad65f156a8a23416373182f99307084cfff74d8 Mon Sep 17 00:00:00 2001 From: Lari Hotari Date: Mon, 14 Sep 2026 08:39:40 +0300 Subject: [PATCH] [improve][ci] Configure SSH access action default and update Upterm --- .github/actions/ssh-access/action.yml | 31 ++++++++++++++++++++++---- .github/workflows/pulsar-ci-flaky.yaml | 1 + .github/workflows/pulsar-ci.yaml | 1 + 3 files changed, 29 insertions(+), 4 deletions(-) diff --git a/.github/actions/ssh-access/action.yml b/.github/actions/ssh-access/action.yml index 89f9b74e60404..11c10ceb3d7e7 100644 --- a/.github/actions/ssh-access/action.yml +++ b/.github/actions/ssh-access/action.yml @@ -17,6 +17,13 @@ # under the License. # +# CI_ENABLE_SSH=true or false explicitly enables or disables both start and wait. +# In particular, false disables SSH even for public repositories. +# Without an override, public workflow repositories are enabled; private, internal, +# and unknown visibility are disabled. The calling workflows map the repository +# variable CI_ENABLE_SSH into the environment; job/step environment overrides win. +# Callers still control when this action runs and which GitHub users' keys are allowed. + name: ssh access description: Sets up SSH access to build VM with upterm inputs: @@ -47,27 +54,43 @@ inputs: runs: using: composite steps: - - run: | + - name: Configure SSH access + env: + SSH_ACCESS_ENABLED: ${{ env.CI_ENABLE_SSH || (github.event.repository.visibility == 'public' && 'true' || 'false') }} + run: | + case "$SSH_ACCESS_ENABLED" in + false) + echo "SSH access is disabled. Set CI_ENABLE_SSH=true to enable it." + exit 0 + ;; + true) ;; + *) + echo "::error::CI_ENABLE_SSH must be true or false." + exit 1 + ;; + esac if [[ "${{ inputs.action }}" == "start" ]]; then echo "::group::Installing upterm & tmux" if [[ "$OSTYPE" == "linux-gnu"* ]]; then # install upterm - curl -sL https://github.com/owenthereal/upterm/releases/download/v0.20.0/upterm_linux_amd64.tar.gz | tar zxvf - -C /tmp upterm && sudo install /tmp/upterm /usr/local/bin/ && rm -rf /tmp/upterm + curl -fsSL https://github.com/owenthereal/upterm/releases/download/v0.27.0/upterm_linux_amd64.tar.gz | tar zxvf - -C /tmp upterm && sudo install /tmp/upterm /usr/local/bin/ && rm -rf /tmp/upterm # install tmux if it's not present if ! command -v tmux &>/dev/null; then sudo apt-get -y install tmux fi elif [[ "$OSTYPE" == "darwin"* ]]; then - brew install --cask owenthereal/upterm/upterm + # Fully qualifying the cask grants trust to this item; suppress installation prompts in CI. + HOMEBREW_NO_ASK=1 brew install --cask owenthereal/upterm/upterm # install tmux if it's not present if ! command -v tmux &>/dev/null; then - brew install tmux + HOMEBREW_NO_ASK=1 brew install tmux fi else echo "Unsupported $OSTYPE" exit 0 fi + upterm version echo '::endgroup::' echo "::group::Configuring ssh and ssh keys" # generate ssh key diff --git a/.github/workflows/pulsar-ci-flaky.yaml b/.github/workflows/pulsar-ci-flaky.yaml index 28d5485655ae0..687942125546f 100644 --- a/.github/workflows/pulsar-ci-flaky.yaml +++ b/.github/workflows/pulsar-ci-flaky.yaml @@ -75,6 +75,7 @@ concurrency: cancel-in-progress: true env: + CI_ENABLE_SSH: ${{ vars.CI_ENABLE_SSH }} # defines the retention period for the intermediate build artifacts needed for rerunning a failed build job # it's possible to rerun individual failed jobs when the build artifacts are available # if the artifacts have already been expired, the complete workflow can be rerun by closing and reopening the PR or by rebasing the PR diff --git a/.github/workflows/pulsar-ci.yaml b/.github/workflows/pulsar-ci.yaml index f2fe30f64c47f..a79842c540764 100644 --- a/.github/workflows/pulsar-ci.yaml +++ b/.github/workflows/pulsar-ci.yaml @@ -70,6 +70,7 @@ concurrency: cancel-in-progress: true env: + CI_ENABLE_SSH: ${{ vars.CI_ENABLE_SSH }} # defines the retention period for the intermediate build artifacts needed for rerunning a failed build job # it's possible to rerun individual failed jobs when the build artifacts are available # if the artifacts have already been expired, the complete workflow can be rerun by closing and reopening the PR or by rebasing the PR