Skip to content

ci: Move CI/CD from Prow to GitHub Actions - #101

Merged
geckofu merged 2 commits into
masterfrom
sre-6507-github-actions
Sep 23, 2026
Merged

geckofu merged 2 commits into
masterfrom
sre-6507-github-actions

Conversation

@dzvon

@dzvon dzvon commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Provide context or links (Jira ticket, Slack thread) for both the reviewer and your future self:

What this PR does

This PR moves the CI/CD of plantbuild from Prow to GitHub Actions. It has two commits.

Dockerfile: Download jsonnet v0.22.0 from the release

  • The image downloads the go-jsonnet v0.22.0 release binaries, and checks them against checksums.txt. Before, it compiled v0.18.0 with Go.
  • The image no longer needs the golang image and a Go compile, so it builds faster.
  • plantbuild already downloads v0.22.0 for vendored projects. Now the image uses the same version.

ci: Move CI/CD from Prow to GitHub Actions

Prow job Workflow When it runs
pull-plantbuild-test, post-plantbuild-test test.yaml Each PR and each push to master
pull-plantbuild-jsonnet-verify, post-plantbuild-jsonnet-verify jsonnet-verify.yaml A PR or a push to master that changes a .jsonnet file
post-plantbuild-image-build image.yaml A push to master that changes the image files, or a push of a v* tag
  • test.sh runs jsonnet -J jsonnetlib directly, with the same arguments that entry.sh gives in the image. The tests need only jsonnet, not Docker.
  • test.sh no longer formats the .jsonnet files. jsonnet-verify.yaml checks the format.
  • image.yaml uses the Docker actions with GITHUB_TOKEN. It builds the image one time, pushes the same tags as before (short commit hash, latest, git tag name), and keeps the layer cache in the GitHub Actions cache.
  • This PR removes build.sh and the root build.jsonnet, because nothing else uses them.

Before you merge

  1. Open the settings of the ghcr.io/theplant/plantbuild package. Give this repository the Write role under "Manage Actions access". If you do not, the push from image.yaml fails.
  2. Merge theplant/test-infra#673 at the same time. After this PR, post-plantbuild-image-build in Prow fails, because build.sh is gone.

After you merge

  1. Make sure that the Image workflow pushed the short commit hash tag and latest.
  2. Make sure that docker run --rm --entrypoint jsonnet ghcr.io/theplant/plantbuild --version shows v0.22.0.

Caution

Projects that run plantbuild fmt-check get jsonnetfmt v0.22.0 from the new image. They can see new format errors until they run plantbuild fmt-update.

The image compiled jsonnet and jsonnetfmt v0.18.0 with Go in a builder
stage. plantbuild already downloads v0.22.0 for vendored projects, so a
project got a different jsonnet version with and without
jsonnetfile.json.

This change makes the image download the go-jsonnet v0.22.0 release
binaries, and checks them against checksums.txt of the release. The
binaries are statically linked, so they run on Alpine. The image no
longer needs the golang image and a Go compile, so it builds faster.

Alpine has no good package for this. The community jsonnet package is
the C++ implementation, and go-jsonnet is only in edge/testing. Both
have v0.21.0.

The jsonnet files in this repository pass the v0.22.0 format check
without change. Projects that use plantbuild fmt-check can see new
format errors if v0.22.0 formats their code differently.

Jira: SRE-6507
@dzvon
dzvon force-pushed the sre-6507-github-actions branch from eb744f7 to 6e3ca3c Compare September 23, 2026 03:55
Prow runs the plantbuild tests, the jsonnet format check and the image
push today. This change adds GitHub Actions workflows that do the same
jobs, so that the Prow jobs in theplant/test-infra can be removed.

- test.yaml downloads jsonnet from the go-jsonnet release and runs
  test.sh on each pull request and each push to master.
- jsonnet-verify.yaml downloads jsonnetfmt from the go-jsonnet release
  and runs hack/verify-jsonnet.sh when a .jsonnet file changes.
- image.yaml builds and pushes the image to ghcr.io on a push to master
  or a push of a v* tag.

The image workflow uses the Docker actions in place of build.sh and
`plantbuild push`. That command ran the published image to make the
compose file, and built the image again for each tag. build-push-action
builds once, pushes all tags, and keeps the layer cache in the GitHub
Actions cache. The image tags stay the same: the short commit hash,
latest, and the git tag name.

test.sh no longer builds the image and runs `plantbuild show`. It runs
jsonnet against ./jsonnetlib directly, with the same arguments that
entry.sh gives in the image. Thus, the tests need only jsonnet, not
Docker. test.sh also no longer formats the jsonnet files, because a test
must not change the source, and jsonnet-verify.yaml checks the format.
This change removes build.sh and the root build.jsonnet, because nothing
else uses them.

The image workflow uses GITHUB_TOKEN in place of the classic PAT of the
theplant-ci user. It watches Dockerfile and the fmt scripts, because
they change the image. It does not watch plantbuild, because the script
is not in the image. The Prow job mounted AWS credentials, but the push
does not use AWS, so the workflow does not have them.

The hack/ scripts now use bash. On the Ubuntu runner, /bin/sh is dash,
and dash has no pipefail option. Prow ran them in Alpine, where the
BusyBox sh has it.

Jira: SRE-6507
@dzvon
dzvon force-pushed the sre-6507-github-actions branch from 6e3ca3c to b580a60 Compare September 23, 2026 04:08
@geckofu
geckofu merged commit 829d935 into master Sep 23, 2026
2 checks passed
@geckofu
geckofu deleted the sre-6507-github-actions branch September 23, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants