-
Notifications
You must be signed in to change notification settings - Fork 166
38 lines (35 loc) · 2 KB
/
Copy pathnightly.yml
File metadata and controls
38 lines (35 loc) · 2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
name: "nightly"
on:
schedule:
- cron: "0 0 * * *"
workflow_dispatch:
jobs:
Spec:
uses: "puppetlabs/cat-github-actions/.github/workflows/module_ci.yml@main"
with:
# voxpupuli-puppet-lint-plugins 7.0 (needed for Puppet 9 support) requires
# ruby >= 3.2; the default (3.1) can no longer resolve the :development group.
ruby_version: "3.2"
# puppet_litmus -> bolt 4.x -> faraday-patron -> patron builds a libcurl native extension;
# the runner has no libcurl headers, so install them before bundle (Puppet 9 lane, Ruby 4).
additional_packages: "libcurl4-openssl-dev"
secrets: "inherit"
Acceptance:
needs: Spec
uses: "puppetlabs/cat-github-actions/.github/workflows/module_acceptance.yml@main"
with:
# redhat-7/debian-10/ubuntu-18.04/ubuntu-20.04 have no Puppet 9 agent build (nightly
# install 404s); collection-platform-exclude drops just their Puppet 9 acceptance run
# while keeping Puppet 8 acceptance for them.
flags: "--nightly --platform-exclude centos-7 --platform-exclude oraclelinux-7 --platform-exclude scientific-7 --collection-platform-exclude 9:redhat-7 --collection-platform-exclude 9:debian-10 --collection-platform-exclude 9:ubuntu-18.04 --collection-platform-exclude 9:ubuntu-20.04"
# voxpupuli-puppet-lint-plugins 7.0 (needed for Puppet 9 support) requires
# ruby >= 3.2; the default (3.1) can no longer resolve the :development group.
ruby_version: "3.2"
# AppArmor's unix-chkpwd profile denies the PAM password-check helper the
# dac_read_search/dac_override capabilities it needs to read /etc/shadow inside a
# container, causing intermittent "Authentication failed for user root@localhost"
# errors on Rocky-8 even with correct credentials (confirmed live via tmate
# debugging: `apparmor="DENIED" ... profile="unix-chkpwd"` in the container's
# journal at the exact moment of failure, 3/3 clean runs after disabling).
disable_apparmor: true
secrets: "inherit"