ci: stop running the whole suite twice on every pull-request push

The header of this file argues that release.yml must not be repeated here,
because a private repository is billed twice for one answer. The push trigger
it shipped with then did exactly that: `branches: ['**']` plus `pull_request`
means a branch with an open PR runs everything once for refs/heads/<branch>
and once for refs/pull/N/merge. The concurrency group is keyed on github.ref,
which differs between the two, so neither cancels the other. Visible on this
branch's own checks: go 3m14s and go 3m3s, shell 7s and 7s, panel 25s and 24s.

Limiting the push trigger to main keeps both gates that matter -- a PR is
still checked before merge, main is still checked after -- and drops only the
duplicate. The one case that loses coverage is a branch pushed with no PR
open, where nothing has asked for the answer yet.

Verified by parsing the result with the repository's own sigs.k8s.io/yaml:
triggers are {"pull_request":null,"push":{"branches":["main"]}} and the three
jobs go/panel/shell are intact. Worth recording for the next person who
parses a workflow: YAML 1.1 reads the bare key `on` as the boolean true, so
it arrives as the string "true" after the YAML-to-JSON conversion, and a
struct tag of `json:"on"` silently matches nothing. GitHub's own parser does
not have this problem; a local check of the triggers does.

Refs #7
This commit is contained in:
flyemoji committed 2026-07-28 18:20:40 +09:00
1 parent 584d31fc49
commit 503240db7b
1 file changed
+8 -5
+8 -5
View File
@@ -1,4 +1,4 @@
# Runs the checks on every push and pull request.
# Runs the checks on pull requests and on main.
#
# release.yml already runs `go vet` and `go test`, but only once a vX.Y.Z tag exists — by then
# a red change is on the release path and the only remedy is a new tag. This is the same gate
@@ -6,14 +6,17 @@
# the release goes through the Dockerfile, and the Dockerfile runs `npm run build`, never
# `npm test`.
#
# Tags are excluded from the push trigger. A vX.Y.Z push fires release.yml, which repeats the
# Go job itself; running both would spend a private repository's Actions minutes twice for one
# answer.
# The push trigger is limited to main rather than every branch, for the reason release.yml is
# not repeated here: a branch with an open PR would otherwise run the whole suite twice per
# push, once for refs/heads/<branch> and once for refs/pull/N/merge. Those are different
# concurrency groups, so neither cancels the other, and this repository is private and billed
# for both. A branch with no PR open yet is the one case that loses coverage, and opening the
# PR is what asks for the answer.
name: ci
on:
push:
branches: ['**']
branches: [main]
pull_request:
permissions: