Repository navigation
ci: Move CI/CD from Prow to GitHub Actions - #101
Merged
Merged
Conversation
The image compiled jsonnet and jsonnetfmt v0.18.0 with Go in a builder stage. plantbuild already downloads v0.22.0 for vendored projects, so a project got a different jsonnet version with and without jsonnetfile.json. This change makes the image download the go-jsonnet v0.22.0 release binaries, and checks them against checksums.txt of the release. The binaries are statically linked, so they run on Alpine. The image no longer needs the golang image and a Go compile, so it builds faster. Alpine has no good package for this. The community jsonnet package is the C++ implementation, and go-jsonnet is only in edge/testing. Both have v0.21.0. The jsonnet files in this repository pass the v0.22.0 format check without change. Projects that use plantbuild fmt-check can see new format errors if v0.22.0 formats their code differently. Jira: SRE-6507
dzvon
force-pushed
the
sre-6507-github-actions
branch
from
September 23, 2026 03:55
eb744f7 to
6e3ca3c
Compare
Prow runs the plantbuild tests, the jsonnet format check and the image push today. This change adds GitHub Actions workflows that do the same jobs, so that the Prow jobs in theplant/test-infra can be removed. - test.yaml downloads jsonnet from the go-jsonnet release and runs test.sh on each pull request and each push to master. - jsonnet-verify.yaml downloads jsonnetfmt from the go-jsonnet release and runs hack/verify-jsonnet.sh when a .jsonnet file changes. - image.yaml builds and pushes the image to ghcr.io on a push to master or a push of a v* tag. The image workflow uses the Docker actions in place of build.sh and `plantbuild push`. That command ran the published image to make the compose file, and built the image again for each tag. build-push-action builds once, pushes all tags, and keeps the layer cache in the GitHub Actions cache. The image tags stay the same: the short commit hash, latest, and the git tag name. test.sh no longer builds the image and runs `plantbuild show`. It runs jsonnet against ./jsonnetlib directly, with the same arguments that entry.sh gives in the image. Thus, the tests need only jsonnet, not Docker. test.sh also no longer formats the jsonnet files, because a test must not change the source, and jsonnet-verify.yaml checks the format. This change removes build.sh and the root build.jsonnet, because nothing else uses them. The image workflow uses GITHUB_TOKEN in place of the classic PAT of the theplant-ci user. It watches Dockerfile and the fmt scripts, because they change the image. It does not watch plantbuild, because the script is not in the image. The Prow job mounted AWS credentials, but the push does not use AWS, so the workflow does not have them. The hack/ scripts now use bash. On the Ubuntu runner, /bin/sh is dash, and dash has no pipefail option. Prow ran them in Alpine, where the BusyBox sh has it. Jira: SRE-6507
dzvon
force-pushed
the
sre-6507-github-actions
branch
from
September 23, 2026 04:08
6e3ca3c to
b580a60
Compare
geckofu
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Provide context or links (Jira ticket, Slack thread) for both the reviewer and your future self:
What this PR does
This PR moves the CI/CD of plantbuild from Prow to GitHub Actions. It has two commits.
Dockerfile: Download jsonnet v0.22.0 from the releasechecksums.txt. Before, it compiled v0.18.0 with Go.golangimage and a Go compile, so it builds faster.plantbuildalready downloads v0.22.0 for vendored projects. Now the image uses the same version.ci: Move CI/CD from Prow to GitHub Actionspull-plantbuild-test,post-plantbuild-testtest.yamlmasterpull-plantbuild-jsonnet-verify,post-plantbuild-jsonnet-verifyjsonnet-verify.yamlmasterthat changes a.jsonnetfilepost-plantbuild-image-buildimage.yamlmasterthat changes the image files, or a push of av*tagtest.shrunsjsonnet -J jsonnetlibdirectly, with the same arguments thatentry.shgives in the image. The tests need onlyjsonnet, not Docker.test.shno longer formats the.jsonnetfiles.jsonnet-verify.yamlchecks the format.image.yamluses the Docker actions withGITHUB_TOKEN. It builds the image one time, pushes the same tags as before (short commit hash,latest, git tag name), and keeps the layer cache in the GitHub Actions cache.build.shand the rootbuild.jsonnet, because nothing else uses them.Before you merge
ghcr.io/theplant/plantbuildpackage. Give this repository the Write role under "Manage Actions access". If you do not, the push fromimage.yamlfails.post-plantbuild-image-buildin Prow fails, becausebuild.shis gone.After you merge
Imageworkflow pushed the short commit hash tag andlatest.docker run --rm --entrypoint jsonnet ghcr.io/theplant/plantbuild --versionshows v0.22.0.Caution
Projects that run
plantbuild fmt-checkgetjsonnetfmtv0.22.0 from the new image. They can see new format errors until they runplantbuild fmt-update.