Skip to content

DEB package build

DEB package build #236

Workflow file for this run

name: DEB package build
on:
pull_request:
merge_group:
push:
branches:
- stackstate-7.78.2
schedule:
- cron: "17 20 * * 1-5"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name }}
cancel-in-progress: true
defaults:
run:
shell: bash
env:
CONDA_ENV: ddpy3
MAJOR_VERSION: '3'
jobs:
godeps-cache-amd64:
name: Go dependency cache image (amd64)
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
uses: ./.github/workflows/godeps-cache.yml
with:
arch: amd64
build_delay_seconds: 0
secrets:
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
QUAY_PASSWORD: ${{ secrets.QUAY_PASSWORD }}
godeps-cache-arm64:
name: Go dependency cache image (arm64)
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
uses: ./.github/workflows/godeps-cache.yml
with:
arch: arm64
build_delay_seconds: 900
secrets:
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
QUAY_PASSWORD: ${{ secrets.QUAY_PASSWORD }}
build-deb:
name: Build DEB package (omnibus, branded / StackState, ${{ matrix.arch }})
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
needs:
- godeps-cache-amd64
- godeps-cache-arm64
strategy:
fail-fast: false
matrix:
include:
- arch: amd64
runner: xlarge-public
cache_image: ${{ needs.godeps-cache-amd64.outputs.ci_image }}
- arch: arm64
runner: arm64-xlarge-public
cache_image: ${{ needs.godeps-cache-arm64.outputs.ci_image }}
runs-on: ${{ matrix.runner }}
timeout-minutes: 300
container:
image: ${{ matrix.cache_image }} # zizmor: ignore[unpinned-images]
credentials:
username: ${{ vars.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}
env:
OMNIBUS_BASE_DIR: /omnibus
OMNIBUS_GIT_CACHE_DIR: ${{ github.workspace }}/.omnibus-git-cache
BAZEL_CACHE_ROOT: ${{ github.workspace }}/.cache
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
fetch-depth: 0
- name: Configure git identity for the omnibus cache
run: |
# omnibus runs with replace_env=True, so a job-level env identity and
# $HOME/.gitconfig are both invisible to its `git commit`. /etc/gitconfig
# is read regardless of environment.
git config --system user.name 'github-actions[bot]'
git config --system user.email 'github-actions[bot]@users.noreply.github.com'
- name: Restore omnibus git cache (${{ matrix.arch }})
id: omnibus-git-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ env.OMNIBUS_GIT_CACHE_DIR }}
key: omnibus-git-${{ matrix.arch }}-${{ hashFiles('omnibus/**', 'release.json') }}
restore-keys: |
omnibus-git-${{ matrix.arch }}-
- name: Restore bazel caches (${{ matrix.arch }})
id: bazel-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
${{ env.BAZEL_CACHE_ROOT }}/bazelisk
${{ env.BAZEL_CACHE_ROOT }}/bazel/install
${{ env.BAZEL_CACHE_ROOT }}/bazel-repo
key: bazel-${{ matrix.arch }}-${{ hashFiles('.bazelversion', 'MODULE.bazel.lock', 'omnibus/config/software/datadog-agent-dependencies.rb') }}
restore-keys: |
bazel-${{ matrix.arch }}-
- name: Build DEB package with omnibus
run: |
set -eo pipefail
export PATH="$PATH:/usr/local/go/bin"
. /root/miniforge3/etc/profile.d/conda.sh
conda activate "${CONDA_ENV}"
# omnibus is Ruby; the build image ships it under rvm.
. /usr/local/rvm/scripts/rvm
# Work volume is owned by the ARC runner uid but the job container runs as
# root, so git rejects the repo as "dubious ownership"; mark it safe.
git config --global --add safe.directory '*'
# omnibus resolves the agent source through GOPATH rather than the
# workspace path; GitLab's before_script created this symlink.
mkdir -p /go/src/github.com/StackVista
rm -rf /go/src/github.com/StackVista/stackstate-agent
ln -s "${GITHUB_WORKSPACE}" /go/src/github.com/StackVista/stackstate-agent
# DD 7.78 builds some dependencies through bazelisk from
# omnibus/config/software/datadog-agent-dependencies.rb. bazelisk aborts
# with "XDG_CACHE_HOME () must denote a directory in CI!" unless these
# point at real directories. BAZEL_CACHE_ROOT is what the cache steps
# restore and save, so the two must stay in agreement.
export XDG_CACHE_HOME="${BAZEL_CACHE_ROOT}"
export BAZELISK_HOME="${XDG_CACHE_HOME}/bazelisk"
mkdir -p "${XDG_CACHE_HOME}/bazel" "${XDG_CACHE_HOME}/bazel-repo" "${BAZELISK_HOME}"
# .bazelrc:75 `try-import %workspace%/user.bazelrc` is the upstream-blessed
# extension point; it applies to every bazelisk shell-out omnibus makes.
# user.bazelrc is gitignored.
cat > "${GITHUB_WORKSPACE}/user.bazelrc" <<EOF
startup --output_user_root=${XDG_CACHE_HOME}/bazel
common --repository_cache=${XDG_CACHE_HOME}/bazel-repo
EOF
export AGENT_GITHUB_ORG=DataDog
export GITHUB_ORG=DataDog
export BRANDED=true
export AGENT_REPO_NAME=datadog-agent
export OMNIBUS_FORCE_PACKAGES=true
# Rebrand DataDog -> StackState BEFORE vendoring: branding rewrites import
# paths, so vendor/ must be materialised against the rewritten tree.
# fix_branding.sh defaults its target dir to $CI_PROJECT_DIR (a GitLab
# built-in that is unset here); pass the checkout root explicitly.
./fix_branding.sh "${GITHUB_WORKSPACE}"
# GOMODCACHE is pre-warmed by the godeps-cache image (STAC-25429), keyed
# to the module-graph hash, so there is no `go clean -modcache` and no
# per-job `inv deps` (go mod download + tidy) reconcile. Materialise
# vendor/ for this checkout against the warm cache (offline; no download).
# omnibus.build is handed this vendor/ as its --go-mod-cache below.
go work sync
go work vendor
# version.txt is consumed by the packaging/image phases. deps_deb produced
# it on GitLab; generate it in-job instead. No `-e`: stdout must be only
# the version string.
inv agent.version -u > version.txt
cat version.txt
export LD_LIBRARY_PATH="/opt/stackstate-agent/embedded/lib/python3.12/site-packages/psycopg2_binary.libs:/opt/stackstate-agent/embedded/lib"
# --install-directory pins the omnibus paths to the BRANDED install dir.
# Without it tasks/omnibus.py derives them from the unbranded
# /opt/datadog-agent while the branded build uses /opt/stackstate-agent,
# and the post-build step then targets a nonexistent directory.
inv -e omnibus.build \
--gem-path "${GITHUB_WORKSPACE}/.gems" \
--base-dir "${OMNIBUS_BASE_DIR}" \
--go-mod-cache "${GITHUB_WORKSPACE}/vendor" \
--skip-deps \
--skip-sign \
--install-directory /opt/stackstate-agent
- name: Save omnibus git cache (${{ matrix.arch }})
if: github.event_name != 'pull_request' && github.event_name != 'merge_group' && steps.omnibus-git-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ env.OMNIBUS_GIT_CACHE_DIR }}
key: omnibus-git-${{ matrix.arch }}-${{ hashFiles('omnibus/**', 'release.json') }}
- name: Save bazel caches (${{ matrix.arch }})
if: github.event_name != 'pull_request' && github.event_name != 'merge_group' && steps.bazel-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
${{ env.BAZEL_CACHE_ROOT }}/bazelisk
${{ env.BAZEL_CACHE_ROOT }}/bazel/install
${{ env.BAZEL_CACHE_ROOT }}/bazel-repo
key: bazel-${{ matrix.arch }}-${{ hashFiles('.bazelversion', 'MODULE.bazel.lock', 'omnibus/config/software/datadog-agent-dependencies.rb') }}
- name: Collect package outputs
run: |
set -eo pipefail
mkdir -p outcomes
cp -r "${OMNIBUS_BASE_DIR}/pkg" outcomes/
cp -r Dockerfiles outcomes/
ls -la outcomes/pkg outcomes/Dockerfiles
- name: Upload DEB package and image manifests
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: deb-package-${{ matrix.arch }}
path: |
outcomes/pkg/*.deb
outcomes/pkg/*.json
outcomes/Dockerfiles/agent
outcomes/Dockerfiles/cluster-agent
outcomes/Dockerfiles/dogstatsd
outcomes/Dockerfiles/manifests
version.txt
retention-days: 5
if-no-files-found: error
test-deb-renaming:
name: DEB branding verification (no DataDog references, ${{ matrix.arch }})
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
needs: build-deb
strategy:
fail-fast: false
matrix:
arch: [amd64, arm64]
runs-on: docker-public
timeout-minutes: 30
container:
image: ${{ vars.REGISTRY_HOST }}/quay/stackstate/datadog_build_linux_x64:7af9194f
credentials:
username: ${{ vars.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Download DEB package
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: deb-package-${{ matrix.arch }}
- name: Verify package carries no DataDog branding
run: |
set -eo pipefail
git config --global --add safe.directory '*'
# test_deb.sh takes exactly one package and rejects anything else, so
# resolve the glob here and fail loudly rather than passing it through
# (the GitLab job relied on the glob expanding to exactly one file).
shopt -s nullglob
debs=(outcomes/pkg/stackstate-agent_"${MAJOR_VERSION}"*.deb)
if [ "${#debs[@]}" -ne 1 ]; then
echo "Expected exactly one stackstate-agent_${MAJOR_VERSION}*.deb, found ${#debs[@]}: ${debs[*]}" >&2
exit 1
fi
./test/renaming/test_deb.sh "${debs[0]}"
build-agent-image:
name: Build agent container image (docker build, no push on PR, ${{ matrix.arch }})
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
needs: build-deb
strategy:
fail-fast: false
matrix:
include:
- arch: amd64
runner: docker-public
- arch: arm64
runner: arm64-xlarge-public
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
env:
ARCH: ${{ matrix.arch }}
LOCAL_IMAGE: quay.io/stackstate/stackstate-k8s-agent:ci-${{ matrix.arch }}
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Download DEB package
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: deb-package-${{ matrix.arch }}
- name: Log in to the registry proxy
env:
REGISTRY_HOST: ${{ vars.REGISTRY_HOST }}
REGISTRY_USER: ${{ vars.REGISTRY_USER }}
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
run: |
set -eo pipefail
printf '%s' "${REGISTRY_PASSWORD}" | docker login -u "${REGISTRY_USER}" --password-stdin "${REGISTRY_HOST}"
- name: Build agent image
run: |
set -eo pipefail
shopt -s nullglob
debs=(outcomes/pkg/stackstate-agent_*_"${ARCH}".deb)
if [ "${#debs[@]}" -ne 1 ]; then
echo "Expected exactly one stackstate-agent_*_${ARCH}.deb, found ${#debs[@]}: ${debs[*]}" >&2
exit 1
fi
cp "${debs[0]}" Dockerfiles/agent/
# publish_image.sh also passes --build-arg S6_ARCH; the agent Dockerfile
# declares no such ARG, so it is dropped here rather than kept as a warning.
docker build --pull --build-arg ARCH="${ARCH}" -t "${LOCAL_IMAGE}" Dockerfiles/agent
- name: Smoke test agent image
run: |
set -eo pipefail
docker run --rm --entrypoint /opt/stackstate-agent/bin/agent/agent "${LOCAL_IMAGE}" version
- name: Verify embedded Python security fixes
run: |
set -eo pipefail
docker run --rm -i --entrypoint /opt/stackstate-agent/embedded/bin/python3 "${LOCAL_IMAGE}" - < scripts/test_embedded_python_security.py
- name: Scan agent image, report-only (Trivy and Grype vulnerabilities, VEX-aware, plus Trivy secrets)
uses: StackVista/image-pipeline/.github/actions/scan-image@ab8ac3d608530ee0a295483c973d720230174348
env:
GRYPE_NAME: stackstate-k8s-agent
with:
image: ${{ env.LOCAL_IMAGE }}
mode: inform
severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL
with-grype: true
exceptions-path: exceptions
upload-sarif: false
sarif-category: stackstate-k8s-agent-${{ matrix.arch }}
await-verification:
name: Await lint and unit test verification
if: github.event_name == 'push'
permissions:
checks: read
uses: ./.github/workflows/await-checks.yml
with:
checks: CI success (lint and unit tests)
publish-agent-image:
name: Publish and sign agent image (${{ matrix.arch }})
if: github.event_name == 'push'
needs:
- await-verification
- build-agent-image
- test-deb-renaming
strategy:
fail-fast: false
matrix:
include:
- arch: amd64
runner: docker-public
- arch: arm64
runner: arm64-xlarge-public
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
permissions:
contents: read
id-token: write
env:
ARCH: ${{ matrix.arch }}
IMAGE: quay.io/stackstate/stackstate-k8s-agent
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Download DEB package
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: deb-package-${{ matrix.arch }}
- name: Stage the DEB in the image build context
run: |
set -eo pipefail
shopt -s nullglob
debs=(outcomes/pkg/stackstate-agent_*_"${ARCH}".deb)
if [ "${#debs[@]}" -ne 1 ]; then
echo "Expected exactly one stackstate-agent_*_${ARCH}.deb, found ${#debs[@]}: ${debs[*]}" >&2
exit 1
fi
cp "${debs[0]}" Dockerfiles/agent/
- name: Resolve image tag
id: image
env:
SOURCE_SHA: ${{ github.sha }}
run: |
set -euo pipefail
echo "tag=$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" >> "${GITHUB_OUTPUT}"
- name: Resolve canonical OCI labels
id: oci
uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@ab8ac3d608530ee0a295483c973d720230174348
with:
image-name: stackstate-k8s-agent
tag: ${{ steps.image.outputs.tag }}
title: SUSE Observability Agent
description: Node agent collecting metrics, logs, traces and topology for SUSE Observability.
component: stackstate-k8s-agent
dockerfile: Dockerfiles/agent/Dockerfile
base-name: registry.suse.com/bci/bci-micro:latest
registry-credentials: |
[{"registry": "${{ vars.REGISTRY_HOST }}", "username": "${{ vars.REGISTRY_USER }}", "password": "${{ secrets.REGISTRY_PASSWORD }}"}]
- name: Build, publish, and sign architecture image
uses: StackVista/image-pipeline/.github/actions/push-single-arch@ab8ac3d608530ee0a295483c973d720230174348
with:
image: ${{ env.IMAGE }}
tag: ${{ steps.image.outputs.tag }}
arch: ${{ matrix.arch }}
docker-context: Dockerfiles/agent
dockerfile: Dockerfiles/agent/Dockerfile
build-args: ARCH=${{ matrix.arch }}
labels: |
${{ steps.oci.outputs.labels }}
org.opencontainers.image.revision=${{ github.sha }}
source-registry-credentials: |
[{"registry": "${{ vars.REGISTRY_HOST }}", "username": "${{ vars.REGISTRY_USER }}", "password": "${{ secrets.REGISTRY_PASSWORD }}"}]
target-registry: quay.io
target-registry-user: ${{ vars.QUAY_USER }}
target-registry-password: ${{ secrets.QUAY_PASSWORD }}
merge-agent-manifest:
name: Publish and sign multi-architecture agent image
if: github.event_name == 'push'
needs:
- publish-agent-image
- sign-and-publish-deb
runs-on: docker-public
timeout-minutes: 30
permissions:
contents: read
id-token: write
steps:
- name: Resolve image tag
id: image
env:
SOURCE_SHA: ${{ github.sha }}
run: |
set -euo pipefail
echo "tag=$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" >> "${GITHUB_OUTPUT}"
- name: Merge and sign multi-architecture manifest
uses: StackVista/image-pipeline/.github/actions/merge-multiarch@ab8ac3d608530ee0a295483c973d720230174348
with:
image: quay.io/stackstate/stackstate-k8s-agent
tag: ${{ steps.image.outputs.tag }}
arches: amd64,arm64
target-registry: quay.io
target-registry-user: ${{ vars.QUAY_USER }}
target-registry-password: ${{ secrets.QUAY_PASSWORD }}
sign-and-publish-deb:
name: Sign DEB packages (GPG) and publish to the pre-release apt repository
needs:
- await-verification
- build-deb
- test-deb-renaming
if: github.event_name == 'push'
runs-on: ubuntu-24.04
environment: agent-pre-release
timeout-minutes: 30
permissions:
contents: read
id-token: write
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Download amd64 DEB package
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: deb-package-amd64
- name: Download arm64 DEB package
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: deb-package-arm64
- name: Install debsigs and GnuPG
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install -y --no-install-recommends debsigs gnupg gpg-agent ruby
- name: Install deb-s3 from the pinned, checksum-verified manifest
run: ./.github/scripts/install-deb-s3.sh .github/deb-s3-gems.sha256
- name: Assume the pre-release publishing role
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with:
role-to-assume: ${{ vars.AGENT_PRERELEASE_ROLE_ARN }}
aws-region: eu-west-1
- name: Sign the DEB packages with debsigs
env:
SIGNING_PUBLIC_KEY: ${{ secrets.SIGNING_PUBLIC_KEY }}
SIGNING_PRIVATE_KEY: ${{ secrets.SIGNING_PRIVATE_KEY }}
SIGNING_PRIVATE_PASSPHRASE: ${{ secrets.SIGNING_PRIVATE_PASSPHRASE }}
SIGNING_KEY_ID: ${{ secrets.SIGNING_KEY_ID }}
run: ./omnibus/package-scripts/sign_debian_package.sh
- name: Publish the DEB packages to the pre-release apt repository
env:
SIGNING_PUBLIC_KEY: ${{ secrets.SIGNING_PUBLIC_KEY }}
SIGNING_PRIVATE_KEY: ${{ secrets.SIGNING_PRIVATE_KEY }}
SIGNING_PRIVATE_PASSPHRASE: ${{ secrets.SIGNING_PRIVATE_PASSPHRASE }}
SIGNING_KEY_ID: ${{ secrets.SIGNING_KEY_ID }}
run: ./omnibus/package-scripts/publish_package.sh sts-agent-prerelease
generate-install-script:
name: Generate the pre-release agent install script
needs: godeps-cache-amd64
if: github.event_name == 'push'
runs-on: xlarge-public
timeout-minutes: 30
permissions:
contents: read
container:
image: ${{ needs.godeps-cache-amd64.outputs.ci_image }} # zizmor: ignore[unpinned-images]
credentials:
username: ${{ vars.REGISTRY_USER }}
password: ${{ secrets.REGISTRY_PASSWORD }}
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Render install.sh against the pre-release repositories
env:
STS_AWS_TEST_BUCKET: sts-agent-prerelease
STS_AWS_TEST_BUCKET_YUM: stackstate-agent-3-rpm-test
STS_AWS_TEST_BUCKET_WIN: stackstate-agent-3-test
run: |
set -eo pipefail
. /root/miniforge3/etc/profile.d/conda.sh
conda activate "${CONDA_ENV}"
git config --global --add safe.directory '*'
inv release.generate-install -t
grep -q 's3.amazonaws.com' ./cmd/agent/install.sh
if grep -q 'None.s3.amazonaws.com' ./cmd/agent/install.sh; then
echo "install.sh references an unset bucket variable" >&2
exit 1
fi
- name: Upload the rendered install script
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: agent-install-script
path: cmd/agent/install.sh
retention-days: 5
if-no-files-found: error
publish-install-script:
name: Publish the pre-release agent install script to S3
needs:
- generate-install-script
- sign-and-publish-deb
if: github.event_name == 'push'
runs-on: ubuntu-24.04
environment: agent-pre-release
timeout-minutes: 15
permissions:
contents: read
id-token: write
steps:
- name: Download the rendered install script
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: agent-install-script
- name: Assume the pre-release publishing role
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6.2.3
with:
role-to-assume: ${{ vars.AGENT_PRERELEASE_ROLE_ARN }}
aws-region: eu-west-1
- name: Upload install.sh
run: |
set -euo pipefail
aws s3 cp ./install.sh s3://sts-agent-prerelease/install.sh --acl public-read
aws s3 ls s3://sts-agent-prerelease/
cerberus-notify:
name: Report failure to Slack (Cerberus)
needs:
- godeps-cache-amd64
- godeps-cache-arm64
- build-deb
- test-deb-renaming
- build-agent-image
- publish-agent-image
- merge-agent-manifest
- sign-and-publish-deb
- generate-install-script
- publish-install-script
if: >-
always()
&& (github.event_name == 'push' || github.event_name == 'schedule')
&& contains(needs.*.result, 'failure')
uses: ./.github/workflows/cerberus-notify.yml
with:
suite: deb-package
secrets:
CERBERUS_LAMBDA_URL: ${{ secrets.CERBERUS_LAMBDA_URL }}
CERBERUS_API_TOKEN: ${{ secrets.CERBERUS_API_TOKEN }}
ci-success:
name: CI success (DEB package build)
needs:
- godeps-cache-amd64
- godeps-cache-arm64
- build-deb
- test-deb-renaming
- build-agent-image
if: always()
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: Evaluate upstream job results
env:
GODEPS_CACHE_AMD64: ${{ needs.godeps-cache-amd64.result }}
GODEPS_CACHE_ARM64: ${{ needs.godeps-cache-arm64.result }}
BUILD_DEB: ${{ needs.build-deb.result }}
TEST_DEB_RENAMING: ${{ needs.test-deb-renaming.result }}
BUILD_AGENT_IMAGE: ${{ needs.build-agent-image.result }}
run: |
set -euo pipefail
status=0
# Every job below is skipped on a fork pull request, so "skipped" must not
# satisfy the gate -- otherwise the merge check goes green having built nothing.
# The signing, publishing and manifest jobs are excluded on purpose: they only
# run on push, so they can never report on a pull request.
require_success() {
printf ' %-30s %s\n' "$1" "$2"
[ "$2" = "success" ] || status=1
}
require_success "Go dependency cache (amd64)" "${GODEPS_CACHE_AMD64}"
require_success "Go dependency cache (arm64)" "${GODEPS_CACHE_ARM64}"
require_success "DEB package" "${BUILD_DEB}"
require_success "DEB branding verification" "${TEST_DEB_RENAMING}"
require_success "Agent image" "${BUILD_AGENT_IMAGE}"
exit "${status}"