Skip to content

Add praktika workflow with review job - #357

Draft
maxknv wants to merge 4 commits into
mainfrom
ci/migrate-docs-lint-to-praktika
Draft

maxknv wants to merge 4 commits into
mainfrom
ci/migrate-docs-lint-to-praktika

Conversation

@maxknv

@maxknv maxknv commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Why

Add code review job

What

  • Migrate the doc's pipeline from GHActions to praktika
  • Define and deploy infra for praktika CI
  • Add praktika's code review job

Migrate .github/workflows/docs-lint.yaml (both pull_request and push
triggers) to praktika workflows:

- Add shared Job.Config registry ci/workflows/job_configs.py (JobConfigs)
  with the vale, doc-links and api-reference-generated jobs, reused by
  both Pull Request CI (pull_request.py) and Main CI (main_ci.py).
- Bake the lint toolchain (Go, pre-warmed crd-ref-docs, Vale, Node +
  linkspector) into the runner AMIs via an arch-aware build component in
  ci/infrastructure/projects.py, so jobs run the existing Makefile
  targets with no per-job installs.
- Drop .github/workflows/docs-lint.yaml; the ci-success-check aggregator
  is handled natively by praktika.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@maxknv
maxknv marked this pull request as draft October 2, 2026 16:09
@maxknv
maxknv force-pushed the ci/migrate-docs-lint-to-praktika branch from 6a95ab5 to 8cb11d2 Compare October 2, 2026 16:16
@clickhouse-operator

clickhouse-operator Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Workflow [PR], commit [1f4e5d6]

Summary: ⏳

job_name test_name status info comment
Lint FAIL
Helm Test FAIL

Code Review

Result: ⚠️ Issues found

What changed: Migrates documentation linting and several operator CI checks from GitHub Actions to Praktika, adds AWS runner/image infrastructure, and introduces an AI-assisted pull-request review job. The remaining GitHub Actions workflow is adjusted to remove the migrated jobs.

The three existing unresolved findings remain valid in the current head: pushes to main are still disallowed, the GitHub token still has unnecessary contents: write access, and the change-filter digest still omits Go packages exercised by the migrated checks. No additional findings were identified.

Investigation: 4/13 rounds, 30 tool calls.

volume_size_gb=100,
capacity_reserve=1,
image_builder=_IMAGE_BUILDERS_BY_NAME["ci-arm64-image"],
ext={"allowed_push_branches": ['NA'], "allowed_pr_base_branches": ['main'], "allowed_users": ['maxknv']},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

main_ci.py defines a push workflow for main, but this orchestrator explicitly allows pushes only from the nonexistent NA branch. Consequently, the documentation checks that previously ran after every push to main will never be dispatched. Please include main in allowed_push_branches.

_GH_TOKEN_MINTER = Components.GitHubTokenMinter(
permissions={
"checks": "write",
"contents": "write",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

None of the configured jobs updates repository contents, so granting contents: write gives the minted CI token unnecessary authority to modify code or refs. This token is used by PR automation, making that extra privilege especially risky if the job or its dependencies are compromised. Please reduce this to contents: read; the separate checks, issues, pull-request, status, and Pages permissions cover the operations configured here.

Add the two Go-only ci.yaml jobs to the praktika PR and Main workflows via
shared JobConfigs, and remove them from .github/workflows/ci.yaml:

- Build and Unit Tests: "go build cmd/main.go && make test-ci" (arm-medium;
  envtest runs in-process, no Docker). controller-gen/setup-envtest
  self-install via go-install-tool against the baked Go toolchain.
- Fuzz Specs: "make fuzz" (arm-small).

Both are change-filtered on Go source paths (the praktika equivalent of
ci.yaml's changes non-docs gate). The dorny/test-reporter step is dropped;
pass/fail comes from the job exit code. Dropped both jobs from ci.yaml's
ci-success-check needs list.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Comment on lines +70 to +71
_GO_CODE_DIGEST = Job.CacheDigestConfig(
include_paths=[

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

enable_job_filtering_by_changes uses this digest to decide whether these jobs run, but the list omits test/testutil (and other Go-bearing directories such as tools). For example, a PR that changes test/testutil/dialer_test.go matches none of these paths, so both build_and_test and fuzz_specs are skipped even though make test-ci normally runs those unit tests and vets/formats all Go packages. Please include every Go source/test directory processed by these commands, or use a broad Go-file/non-docs digest equivalent to the removed Actions changes filter.

…tika

Add three more ci.yaml jobs to the praktika PR/Main workflows via shared
JobConfigs, bake their tooling into the runner image, and remove them from
.github/workflows/ci.yaml:

- Lint: `make lint` (+ go mod tidy / generate / manifests diff checks).
- Helm Test: `make generate-helmchart-ci` + chart diff + helm lint, using the
  baked helm and kubebuilder.
- Check CRD Compatibility: PR-only, advisory (allow_failure). ci/jobs/
  check_crd_compat.py fetches the base branch (praktika's ephemeral merge
  checkout has no base history) and runs `make check-crd-compat`. The
  crd-breaking-change label gate is a workflow filter hook
  (ci/jobs/filter_job_hook.py) using praktika.info.Info — no gh calls.

Image (ci/infrastructure/projects.py, recipe 1.0.1 -> 1.0.2): new
_go_ci_tools_component bakes helm + kubebuilder and pre-warms the Go
build/module and pip caches for controller-gen, kustomize, setup-envtest,
golangci-lint, actionlint, crd-schema-checker and codespell (versions kept in
sync with the Makefile), replacing ci.yaml's marketplace actions + actions/cache.

Dropped lint from e2e-test's needs and all three jobs from ci-success-check.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@maxknv
maxknv force-pushed the ci/migrate-docs-lint-to-praktika branch from 498d14a to 1f4e5d6 Compare October 3, 2026 18:44

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant