From 503240db7be29afcab44bc97be5e5940b052f65b Mon Sep 17 00:00:00 2001 From: Minseong Choi Date: Tue, 28 Jul 2026 18:20:40 +0900 Subject: [PATCH] ci: stop running the whole suite twice on every pull-request push The header of this file argues that release.yml must not be repeated here, because a private repository is billed twice for one answer. The push trigger it shipped with then did exactly that: `branches: ['**']` plus `pull_request` means a branch with an open PR runs everything once for refs/heads/ and once for refs/pull/N/merge. The concurrency group is keyed on github.ref, which differs between the two, so neither cancels the other. Visible on this branch's own checks: go 3m14s and go 3m3s, shell 7s and 7s, panel 25s and 24s. Limiting the push trigger to main keeps both gates that matter -- a PR is still checked before merge, main is still checked after -- and drops only the duplicate. The one case that loses coverage is a branch pushed with no PR open, where nothing has asked for the answer yet. Verified by parsing the result with the repository's own sigs.k8s.io/yaml: triggers are {"pull_request":null,"push":{"branches":["main"]}} and the three jobs go/panel/shell are intact. Worth recording for the next person who parses a workflow: YAML 1.1 reads the bare key `on` as the boolean true, so it arrives as the string "true" after the YAML-to-JSON conversion, and a struct tag of `json:"on"` silently matches nothing. GitHub's own parser does not have this problem; a local check of the triggers does. Refs #7 --- .github/workflows/ci.yml | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2a718ff..e2ddc1f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,4 +1,4 @@ -# Runs the checks on every push and pull request. +# Runs the checks on pull requests and on main. # # release.yml already runs `go vet` and `go test`, but only once a vX.Y.Z tag exists — by then # a red change is on the release path and the only remedy is a new tag. This is the same gate @@ -6,14 +6,17 @@ # the release goes through the Dockerfile, and the Dockerfile runs `npm run build`, never # `npm test`. # -# Tags are excluded from the push trigger. A vX.Y.Z push fires release.yml, which repeats the -# Go job itself; running both would spend a private repository's Actions minutes twice for one -# answer. +# The push trigger is limited to main rather than every branch, for the reason release.yml is +# not repeated here: a branch with an open PR would otherwise run the whole suite twice per +# push, once for refs/heads/ and once for refs/pull/N/merge. Those are different +# concurrency groups, so neither cancels the other, and this repository is private and billed +# for both. A branch with no PR open yet is the one case that loses coverage, and opening the +# PR is what asks for the answer. name: ci on: push: - branches: ['**'] + branches: [main] pull_request: permissions: