Skip to content

Use velero-io/velero's shared reusable workflows instead of local copies - #319

Open
kaovilai wants to merge 2 commits into
velero-io:mainfrom
kaovilai:use-shared-velero-workflows
Open

kaovilai wants to merge 2 commits into
velero-io:mainfrom
kaovilai:use-shared-velero-workflows

Conversation

@kaovilai

Copy link
Copy Markdown
Member

Thank you for contributing to Velero!

Please add a summary of your change

Points this repo at velero-io/velero's shared reusable workflows instead of maintaining drifted local copies:

  • get-go-version.yaml had already drifted from core's copy (stuck on actions/checkout@v6 vs core's @v7). pr.yaml/push.yml now call velero-io/velero/.github/workflows/get-go-version.yaml@main instead of a local file.
  • Adds backport automation (/backport <branch> / /cherrypick <branch> comments, or a backport <branch> label) via velero-io/velero/.github/workflows/backport.yml@main — this repo had none before.
  • Adds pr-filepath-check.yml (Go module zip filename validation) via the same reusable-workflow pattern — also new for this repo.
  • Adds .github/CODEOWNERS (* @velero-io/Maintainer, matching core) and switches auto_assign_prs.yml to call core's reusable version, which adds a CODEOWNERS-aware re-request-review job this repo didn't have.
  • Removes auto_request_review.yml (necojackarc/auto-request-review), which duplicated reviewer-requesting against the same auto-assignees.yml that the centralized auto_assign_prs.yml already handles — keeping both would double-request reviewers on every PR.

Known blocker: backport won't actually create PRs until "Allow GitHub Actions to create and approve pull requests" is enabled under this repo's Settings > Actions > General. Tracked in velero-io/velero#9603 — same setting is blocking on velero-io/velero itself right now too.

Companion PR on velero-io/velero: velero-io/velero#10281 (must merge first — these wrappers call @main on that repo).

Does your change fix a particular issue?

Related to velero-io/velero#9603

Please indicate you've done the following:

  • Accepted the DCO (commit is signed off)
  • Created a changelog file (make new-changelog) or comment /kind changelog-not-required on this PR. — will comment after opening; CI/infra-only, no user-facing behavior change.
  • Updated the corresponding documentation in site/content/docs/main. — N/A, no user-facing docs affected.

Note

Responses generated with Claude

get-go-version.yaml had drifted from velero core's copy (stuck on
actions/checkout@v6 vs core's @v7). Point pr.yaml/push.yml at core's
reusable version instead of a local copy that never gets updated.

Also adds backport automation (none existed here) and pr-filepath-check
(Go module zip filename validation) by calling velero-io/velero's now-
reusable versions of those workflows.

Adds .github/CODEOWNERS (* @velero-io/Maintainer, matching core) and
switches auto_assign_prs.yml to call core's reusable version, which adds
a CODEOWNERS-aware re-request-review job this repo didn't have before.
Removes auto_request_review.yml (necojackarc/auto-request-review), which
duplicated reviewer-requesting against the same auto-assignees.yml that
the centralized auto_assign_prs.yml already handles -- keeping both would
double-request reviewers on every PR.

Note: backport won't function until "Allow GitHub Actions to create and
approve pull requests" is enabled under this repo's Settings > Actions
(tracked in velero-io/velero#9603) -- same setting is also blocking on
velero-io/velero itself right now.

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
@kaovilai

Copy link
Copy Markdown
Member Author

/kind changelog-not-required

Note

Responses generated with Claude

Both called workflows (velero-io/velero's backport.yml and
auto_assign_prs.yml) only reference secrets.GITHUB_TOKEN, which is
auto-generated per-run and already flows to reusable-workflow calls
regardless of secrets: inherit. Keeping secrets: inherit granted the
called workflow every secret this repo holds (DOCKER_USER,
DOCKER_PASSWORD, CODECOV_TOKEN) for no functional benefit -- if
velero-io/velero's main branch is ever compromised, that widened the
blast radius to this repo's secrets too. Dropping it narrows the called
workflow to only what it actually uses.

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants