Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Switch to GitHub actions #332

Merged
merged 7 commits into from
Mar 16, 2021
Merged

Conversation

p37ruh4
Copy link
Contributor

@p37ruh4 p37ruh4 commented Feb 12, 2021

Switch from Travis CI to GitHub actions, I will highlight some of the changes:

  1. build will automatically determine if interactive shell is available, it is required for GitLab actions to work
  2. YUM and DNF cache will be reused between containers to avoid it being downloaded again for each RPM package, should significantly improve performance

Travis CI is slow, not being maintained too much lately and will only get worse over time, so I suggest switching to GitHub actions. Also, it's nice to have one external dependency less.

@p37ruh4
Copy link
Contributor Author

p37ruh4 commented Feb 12, 2021

@lest, I will want to hear your opinion on this. One thing to note, currently publish tasks will not work, as they might require slight adjustment, I've added echo in front of them so that they do not actually run.

@karlism
Copy link
Collaborator

karlism commented Feb 15, 2021

@lest, can you please look into this and #335? I'm currently affected by couple of exporter issues where update to more recent versions could potentially resolve issues, but would like these two PRs to be merge first so that we can test them out.

Comment on lines 71 to 75
- if: env.RPM_GPG_KEY_SECRET != ''
run: echo openssl aes-256-cbc -k ${RPM_GPG_KEY_SECRET} -in secret.asc.enc -out secret.asc -d

- if: env.RPM_GPG_KEY_PASSPHRASE != ''
run: echo ${RPM_GPG_KEY_PASSPHRASE} > .passphrase
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lest, are these steps actually required? I can see sign target in Makefile but it appears that it was not used in .travis.ci.

Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sign is not used on its own. sign7 and sign8 are used as they are specified as dependencies for publish7 and publish8.

Comment on lines +55 to +59
strategy:
matrix:
version:
- 8
- 7
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lest, is there any point in separating publish jobs and run make publish7 & make publish8 separately instead of doing that in single step that includes both of them? (make publish)

Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can have a single step that includes both with the new approach for caching RPMs between jobs.

@karlism
Copy link
Collaborator

karlism commented Mar 16, 2021

@lest, any updates on this? Travis CI has been PITA lately with most of the jobs failing:
image

@lest
Copy link
Owner

lest commented Mar 16, 2021

@karlism everything looks alright. I've added all required secrets to the repository, so we can merge it and see it in action.

@lest lest merged commit f663a37 into lest:master Mar 16, 2021
@karlism
Copy link
Collaborator

karlism commented Mar 16, 2021

Thanks, will try to update some packages to see if everything works as expected.

@lest
Copy link
Owner

lest commented Mar 16, 2021

@karlism Looks like there are a few issues with getting it fully running. I'm testing and making required adjustments now.

@karlism
Copy link
Collaborator

karlism commented Mar 16, 2021

@lest, what issues did you see? Tests in this PR were successful, I've just merged it in master to see if publish jobs will succeed: #350

@karlism
Copy link
Collaborator

karlism commented Mar 16, 2021

Looks like publish packages Create GPG key secret job failed:
https://github.com/lest/prometheus-rpm/runs/2120554172

Run openssl aes-256-cbc -k ${RPM_GPG_KEY_SECRET} -in secret.asc.enc -out secret.asc -d
*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
140037249672512:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:615:

@lest
Copy link
Owner

lest commented Mar 16, 2021

@karlism I got it fixed.

@karlism
Copy link
Collaborator

karlism commented Mar 16, 2021

@lest, thanks! Why did you remove this check? 19b4f67#diff-5c3fa597431eda03ac3339ae6bf7f05e1a50d6fc7333679ec38e21b337cb6721L98
This might be an issue if someone attempts to run actions on forked repositories

@lest
Copy link
Owner

lest commented Mar 16, 2021

@karlism this check resulted in the step being skipped for some reason during my testing. I think we can have it applied to the whole publish_packages job instead of a single step.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants