Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 27 additions & 4 deletions .github/actions/ssh-access/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,13 @@
# under the License.
#

# CI_ENABLE_SSH=true or false explicitly enables or disables both start and wait.
# In particular, false disables SSH even for public repositories.
# Without an override, public workflow repositories are enabled; private, internal,
# and unknown visibility are disabled. The calling workflows map the repository
# variable CI_ENABLE_SSH into the environment; job/step environment overrides win.
# Callers still control when this action runs and which GitHub users' keys are allowed.

name: ssh access
description: Sets up SSH access to build VM with upterm
inputs:
Expand Down Expand Up @@ -47,27 +54,43 @@ inputs:
runs:
using: composite
steps:
- run: |
- name: Configure SSH access
env:
SSH_ACCESS_ENABLED: ${{ env.CI_ENABLE_SSH || (github.event.repository.visibility == 'public' && 'true' || 'false') }}
run: |
case "$SSH_ACCESS_ENABLED" in
false)
echo "SSH access is disabled. Set CI_ENABLE_SSH=true to enable it."
exit 0
;;
true) ;;
*)
echo "::error::CI_ENABLE_SSH must be true or false."
exit 1
;;
esac
if [[ "${{ inputs.action }}" == "start" ]]; then
echo "::group::Installing upterm & tmux"
if [[ "$OSTYPE" == "linux-gnu"* ]]; then
# install upterm
curl -sL https://github.com/owenthereal/upterm/releases/download/v0.20.0/upterm_linux_amd64.tar.gz | tar zxvf - -C /tmp upterm && sudo install /tmp/upterm /usr/local/bin/ && rm -rf /tmp/upterm
curl -fsSL https://github.com/owenthereal/upterm/releases/download/v0.27.0/upterm_linux_amd64.tar.gz | tar zxvf - -C /tmp upterm && sudo install /tmp/upterm /usr/local/bin/ && rm -rf /tmp/upterm

# install tmux if it's not present
if ! command -v tmux &>/dev/null; then
sudo apt-get -y install tmux
fi
elif [[ "$OSTYPE" == "darwin"* ]]; then
brew install --cask owenthereal/upterm/upterm
# Fully qualifying the cask grants trust to this item; suppress installation prompts in CI.
HOMEBREW_NO_ASK=1 brew install --cask owenthereal/upterm/upterm
# install tmux if it's not present
if ! command -v tmux &>/dev/null; then
brew install tmux
HOMEBREW_NO_ASK=1 brew install tmux
fi
else
echo "Unsupported $OSTYPE"
exit 0
fi
upterm version
echo '::endgroup::'
echo "::group::Configuring ssh and ssh keys"
# generate ssh key
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/pulsar-ci-flaky.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,7 @@ concurrency:
cancel-in-progress: true

env:
CI_ENABLE_SSH: ${{ vars.CI_ENABLE_SSH }}
# defines the retention period for the intermediate build artifacts needed for rerunning a failed build job
# it's possible to rerun individual failed jobs when the build artifacts are available
# if the artifacts have already been expired, the complete workflow can be rerun by closing and reopening the PR or by rebasing the PR
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/pulsar-ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ concurrency:
cancel-in-progress: true

env:
CI_ENABLE_SSH: ${{ vars.CI_ENABLE_SSH }}
# defines the retention period for the intermediate build artifacts needed for rerunning a failed build job
# it's possible to rerun individual failed jobs when the build artifacts are available
# if the artifacts have already been expired, the complete workflow can be rerun by closing and reopening the PR or by rebasing the PR
Expand Down
Loading