Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
106 commits
Select commit Hold shift + click to select a range
7a990e2
💥 feat(sdk): Support Standalone Activities (#1402)
maciejdudko Aug 14, 2026
42c7bfe
Scope docker_metrics_with_prometheus query to the test's task queue (…
mjameswh Aug 14, 2026
b97ece5
Keep the in-Docker environment check offline (#1496)
mjameswh Aug 14, 2026
c87e206
Fix integ test failure for activity cancellation against Server v1.32…
mjameswh Aug 14, 2026
84be3c1
Tolerate out-of-grammar nexus request-timeout headers (#1497)
mjameswh Aug 14, 2026
4a97144
Add Event Groups (Core) (#1308)
mjameswh Aug 14, 2026
0067717
Update API upstream (#1504)
tconley1428 Aug 17, 2026
5962c09
feat(sdk): add activity and workflow test env (#1492)
chris-olszewski Aug 17, 2026
46c50fc
chore(sdk): release 0.7.0 (#1494)
chris-olszewski Aug 17, 2026
86d5b8e
Expose cancel details on workflow cancel & propagate them in Rust SDK…
Sushisource Aug 18, 2026
74bb753
feat(client): allow setting memo on workflow start (#1443)
cgreeno Aug 19, 2026
f5d0575
Add warning on worker deployment limits (#1500)
Sushisource Aug 19, 2026
5635811
Fix CI flake detected by SDK Sentinel (rust) (#1507)
Sushisource Aug 19, 2026
c989a54
feat(sdk): add WorkflowContext::all_handlers_finished (#1505)
chris-olszewski Aug 19, 2026
d9efc49
fix(sdk): typed signal_with_start_workflow (#1508)
chris-olszewski Aug 19, 2026
5fe40e2
chore: remove some trybuild tests (#1510)
chris-olszewski Aug 20, 2026
090afd3
Add workflow for sentinel comment responses (#1514)
Sushisource Aug 21, 2026
5d63f10
Preserve Event Group Markers on cancellation commands (#1512)
mjameswh Aug 21, 2026
d913b1f
Serialize C-bridge ephemeral server tests (#1513)
sdk-sentinel-bot Aug 24, 2026
70a7bb5
[SDK Sentinel] Stabilize legacy query integration test ordering (#1511)
sdk-sentinel-bot Aug 24, 2026
04ad546
feat(metrics): emit `failure_reason` on existing activity failure met…
jmaeagle99 Aug 24, 2026
4e6f71f
Move changelog release notes helper to its own crate (#1519)
tconley1428 Aug 24, 2026
b860e3f
Update api_upstream (#1520)
tconley1428 Aug 24, 2026
096387e
chore(ci): let dependabot skip cloud tests (#1528)
chris-olszewski Aug 25, 2026
8bdcb75
Thread counters_total_suffix through prometheus exporter (#1531)
VegetarianOrc Aug 25, 2026
3037a0b
Allow including LA arguments in marker (#1532)
Sushisource Aug 26, 2026
be2be0a
Run integration tests against envconfig-backed Cloud namespaces (#1483)
THardy98 Aug 26, 2026
8598d5b
feat: workflow command pagination (#1515)
jmaeagle99 Aug 26, 2026
02f9601
build(deps): update base64 requirement from 0.22 to 0.23 (#1525)
dependabot[bot] Aug 27, 2026
feb722f
fix(sdk): mark remaining public types with `non_exhaustive` (#1536)
chris-olszewski Aug 27, 2026
35e3913
Stabilize heartbeat timeout codec test (#1539)
sdk-sentinel-bot Aug 27, 2026
3ada214
feat(client): add update-with-start support (#1438)
discosultan Aug 27, 2026
db635f0
Fix non-sticky WFT poller starvation with small workflow cache (#1534)
DABH Aug 27, 2026
97e55aa
Fix worker shutdown racing in-flight activity completions (#1538)
iw Aug 27, 2026
95b6345
feat(sdk): add `WorkflowHandle::get_update_handle` (#1540)
chris-olszewski Aug 27, 2026
3393e57
Use shared changelog workflow (#1535)
Sushisource Aug 27, 2026
ec334fa
build(deps): bump hoverkraft-tech/compose-action from 2.6.0 to 3.1.0 …
dependabot[bot] Aug 31, 2026
b16adf5
chore(docs): add missing readmes (#1551)
chris-olszewski Aug 31, 2026
f9d3d5b
fix(sdk): encode None as binary/null (#1543)
chris-olszewski Aug 31, 2026
762e2b8
fix(sdk): encode Vec<u8> as binary/plain (#1547)
chris-olszewski Aug 31, 2026
79bb0ae
chore(sdk): refactor data converter (#1549)
chris-olszewski Aug 31, 2026
48e363d
feat(sdk): make fetching workflow history lazy (#1552)
chris-olszewski Aug 31, 2026
0f605f2
feat(sdk): add encode_common_attributes to DefaultFailureConverter (#…
chris-olszewski Aug 31, 2026
857248b
Update api_upstream (#1545)
tconley1428 Aug 31, 2026
88af5c8
chore(sdk): make serialization context extensible (#1553)
chris-olszewski Aug 31, 2026
b804c0b
chore(sdk): rename include_arguments_into_marker to include_arguments…
jmaeagle99 Aug 31, 2026
a38b8b4
chore(sdk): automate crate release (#1550)
chris-olszewski Sep 1, 2026
0ee4604
Fix flaky post-cancel abandoned child test (#1555)
Sushisource Sep 1, 2026
eea75f4
Stabilize Nexus async outcome deadlines (#1556)
sdk-sentinel-bot Sep 1, 2026
8ccec71
Add named deterministic workflow random streams (#1557)
eamsden Sep 1, 2026
37d747d
feat(sdk): gate experimental APIs behind feature (#1395)
chris-olszewski Sep 1, 2026
85bf431
💥 Use context-sensitive randomness for workflow views (#1558)
eamsden Sep 2, 2026
173afc0
Make SdkWakeGuard thread-bound (#1562)
eamsden Sep 2, 2026
98bf163
Synchronize cgroup memory test refresh (#1559)
sdk-sentinel-bot Sep 2, 2026
2f7ef34
chore(sdk): make publish idempotent (#1561)
chris-olszewski Sep 2, 2026
207acc1
chore(sdk): prepare for 0.8.0 release (#1560)
chris-olszewski Sep 2, 2026
9f1acdb
chore(sdk): resolve some doc(hidden) APIs (#1563)
chris-olszewski Sep 2, 2026
f3bf104
chore(sdk): limit macro exports (#1564)
chris-olszewski Sep 3, 2026
5db7e2e
docs: update API WIT documentation (#1573)
tconley1428 Sep 3, 2026
a94ca63
chore(sdk): use correct repo in cargo toml (#1567)
chris-olszewski Sep 3, 2026
139d2e8
chore(sdk): mark remaining error enums as non exhaustive (#1568)
chris-olszewski Sep 3, 2026
078f7fe
feat(sdk): add not found variant for signal/cancel external wf (#1569)
chris-olszewski Sep 3, 2026
8cab93d
chore(sdk): mark pub test utilities as experimental (#1570)
chris-olszewski Sep 3, 2026
c855167
chore(core): remove doc hidden from runtime opts (#1572)
chris-olszewski Sep 3, 2026
e7693a2
Add workflow-scoped context storage (#1580)
eamsden Sep 3, 2026
82b24c9
fix(sdk): ensure memo/search attribute keys are determistic (#1576)
chris-olszewski Sep 4, 2026
2b8b350
chore(sdk): add SDK owned types over using core directly (#1577)
chris-olszewski Sep 4, 2026
4212ee2
chore(sdk): provide concrete types for worker tuning (#1581)
chris-olszewski Sep 4, 2026
b020c53
chore(sdk): limit reexport of core worker and worker config (#1582)
chris-olszewski Sep 4, 2026
fcac756
chore: add msrv to every crate (#1587)
chris-olszewski Sep 4, 2026
8a155a9
fix(sdk/testing): hide cancellation token from public API (#1588)
chris-olszewski Sep 4, 2026
3d2cb18
chore(sdk): keep proto/core in sync (#1583)
chris-olszewski Sep 4, 2026
e6dc63f
fix(sdk): add sdk owned wrappers for some proto types exposed in clie…
chris-olszewski Sep 4, 2026
edf4d2f
feat(client): allow usage of protox instead of system protoc (#1590)
chris-olszewski Sep 4, 2026
399cb7a
chore: release 1.0.0 (#1586)
chris-olszewski Sep 4, 2026
acac9e3
Run Cloud-eligible integration tests with filtering (#1518)
THardy98 Sep 8, 2026
26eeb2f
Allow normal polling when sticky is saturated (#1579)
yuandrew Sep 14, 2026
0c23f71
build(deps): update wit-bindgen requirement from 0.57.1 to 0.61.1 (#1…
dependabot[bot] Sep 15, 2026
24dc2d9
Fix PayloadsTooLarge errors spamming WFT failures (#1604)
Sushisource Sep 16, 2026
2713927
Merged the current Core into the external stream branch.
moedash Sep 16, 2026
ce28a0e
Fixed the seams the current Core exposed in the external stream machi…
moedash Sep 16, 2026
71c5807
Merged the WIT alignment fix into the unified branch.
moedash Sep 16, 2026
b33e76e
Preserve targets after transient errors (#1600)
yuandrew Sep 17, 2026
f0e143e
Merged the integ test timeout fix into the unified branch.
moedash Sep 17, 2026
3bc62fc
Merged the nexus request-timeout backport into the unified branch.
moedash Sep 17, 2026
7684990
Merged the nexus model WIT fix into the unified branch.
moedash Sep 17, 2026
02a02f8
Merged the current upstream Core into the unified branch.
moedash Sep 17, 2026
27073b0
Generate payload visitor implementations in a stable order (#1608)
mikek-mnx Sep 17, 2026
2deeab9
Update API definitions (#1607)
tconley1428 Sep 17, 2026
efa9e67
Standalone Activities samples (#1603)
GregoryTravis Sep 17, 2026
0eb03f2
feat: add RetryPolicy option under ChildWorkflowOptions (#1610)
xylonx Sep 18, 2026
e52a0ab
Merged the reviewed external stream repairs into the unified branch.
moedash Sep 19, 2026
a691d27
Named the leaked command in the external stream fatal message.
moedash Sep 19, 2026
eba714f
Merged the stream protos and the test lint fix from the repairs branch.
moedash Sep 22, 2026
9ce3193
Merged the external repairs review round into the unified branch.
moedash Sep 25, 2026
015f19f
Noted that pagination leaves the marker ordering rule intact.
moedash Sep 25, 2026
8de263a
Merged the current upstream Core into the unified branch.
moedash Sep 25, 2026
f62993b
Merge commit '84490148' into to-unified
moedash Oct 1, 2026
736ecc8
Merge commit '2fadc9b3' into to-unified
moedash Oct 2, 2026
741ff2b
Merge commit '757b9856' into to-unified
moedash Oct 2, 2026
1de8b92
Merge commit '0a3e3a92' into to-unified
moedash Oct 2, 2026
ba05a85
Merge commit 'cdc42602' into to-unified
moedash Oct 2, 2026
c3d0a4b
Merge commit 'c6af5175' into to-unified
moedash Oct 2, 2026
12b429e
Merge commit '4afe3e5d' into to-unified
moedash Oct 2, 2026
093c55e
Merged #2's execution addressing of linked channels into to-unified.
moedash Oct 3, 2026
2a516e1
Merged #2's execution field renumbering into to-unified.
moedash Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .cargo/config.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
[env]
# This temporarily overrides the version of the CLI used for integration tests, locally and in CI
# CLI_VERSION_OVERRIDE = "v1.6.3-serverless"
# TEMP: workflow task completion pagination requires server >=v1.32.0-162.0, for which there's no
# published stable CLI release yet.
CLI_VERSION_OVERRIDE = "v1.8.3-server-1.32.0-162.0"

[alias]
# Not sure why --all-features doesn't work
Expand All @@ -13,6 +15,8 @@ integ-test = [
"--features",
"ephemeral-server",
"--features",
"temporalio-sdk/experimental",
"--features",
"temporalio-sdk-core/otel",
"--package",
"temporalio-sdk-core",
Expand Down
14 changes: 14 additions & 0 deletions .github/workflows/changelog.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: Changelog

on:
pull_request:
types: [opened, synchronize, reopened, labeled, unlabeled]

permissions:
contents: read
pull-requests: read

jobs:
changelog-check:
name: Changelog checkpoint
uses: temporalio/.github/.github/workflows/changelog.yml@d8129c755fbd1d3f18c5a7a5420d5754acc63e3f
127 changes: 127 additions & 0 deletions .github/workflows/create-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,127 @@
name: Create Release

on:
workflow_dispatch:

concurrency:
group: publish-crates
cancel-in-progress: false

jobs:
publish:
name: Publish crates
runs-on: ubuntu-latest
timeout-minutes: 30
environment: release
permissions:
contents: write
id-token: write

steps:
- name: Require a release branch
shell: bash
run: |
if [[ "$GITHUB_REF" != "refs/heads/main" && ! "$GITHUB_REF_NAME" =~ ^releases/[0-9]+\.[0-9]+\.x$ ]]; then
echo "Publishing must be run from main or a releases/<major>.<minor>.x branch; got $GITHUB_REF."
exit 1
fi

- name: Check out repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0

# Necessary as `cargo publish` builds crates as a check before publishing
- name: Set up repository
uses: ./.github/actions/setup
with:
mise-install-args: protoc

- name: Read release metadata
id: release
shell: bash
run: |
metadata="$(cargo metadata --format-version 1 --no-deps)"
version="$(jq -er '[.packages[] | select(.name == "temporalio-sdk") | .version] | if length == 1 then .[0] else error("expected one temporalio-sdk package") end' <<<"$metadata")"
core_version="$(jq -er '[.packages[] | select(.name == "temporalio-sdk-core") | .version] | if length == 1 then .[0] else error("expected one temporalio-sdk-core package") end' <<<"$metadata")"

if [[ "$GITHUB_REF_NAME" =~ ^releases/([0-9]+)\.([0-9]+)\.x$ ]]; then
release_line="${BASH_REMATCH[1]}.${BASH_REMATCH[2]}"
if [[ "$version" != "$release_line".* ]]; then
echo "SDK version $version does not belong to release branch $GITHUB_REF_NAME."
exit 1
fi
fi

{
echo "version=$version"
echo "tag=v$version"
echo "core_tag=core-v$core_version"
} >>"$GITHUB_OUTPUT"

- name: Generate release notes
run: |
previous_tag="$(git describe --tags --match 'v[0-9]*' --abbrev=0 HEAD)"
cargo run -p changelog-release-notes -- \
--from "$previous_tag" \
--to HEAD \
--changelog rust \
>"$RUNNER_TEMP/sdk-release-notes.md"

if ! previous_core_tag="$(git describe --tags --match 'core-v[0-9]*' --abbrev=0 HEAD 2>/dev/null)"; then
previous_core_tag="$previous_tag"
fi
cargo run -p changelog-release-notes -- \
--from "$previous_core_tag" \
--to HEAD \
--changelog core \
>"$RUNNER_TEMP/core-release-notes.md"

- name: Plan crate publication
id: publish-plan
run: cargo run --quiet -p changelog-release-notes --bin plan-release-publish >>"$GITHUB_OUTPUT"

- name: Authenticate to crates.io
if: steps.publish-plan.outputs.packages != '[]'
id: auth
uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 # v1

- name: Publish crates
if: steps.publish-plan.outputs.packages != '[]'
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
PUBLISH_PACKAGES: ${{ steps.publish-plan.outputs.packages }}
shell: bash
run: |
jq -e 'type == "array" and length > 0 and all(.[]; type == "string" and length > 0)' \
<<<"$PUBLISH_PACKAGES" >/dev/null
mapfile -t packages < <(jq -r '.[]' <<<"$PUBLISH_PACKAGES")
publish_args=()
for package in "${packages[@]}"; do
publish_args+=(--package "$package")
done
cargo publish "${publish_args[@]}"

- name: Create draft SDK GitHub release
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ steps.release.outputs.tag }}
RELEASE_TITLE: temporalio-sdk ${{ steps.release.outputs.tag }}
run: |
gh release create "$RELEASE_TAG" \
--target "$GITHUB_SHA" \
--draft \
--title "$RELEASE_TITLE" \
--notes-file "$RUNNER_TEMP/sdk-release-notes.md"

- name: Create draft Core GitHub release
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ steps.release.outputs.core_tag }}
RELEASE_TITLE: temporalio-sdk-core ${{ steps.release.outputs.core_tag }}
run: |
gh release create "$RELEASE_TAG" \
--target "$GITHUB_SHA" \
--draft \
--title "$RELEASE_TITLE" \
--notes-file "$RUNNER_TEMP/core-release-notes.md"
110 changes: 96 additions & 14 deletions .github/workflows/per-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,12 @@ jobs:
- run: cargo lint
- run: cargo test-lint
- run: cargo check
- run: cargo check --features experimental
- name: Check vendored proto compilation
run: cargo check --features temporalio-client/vendored-protox
env:
PROTOC: /does/not/exist
CARGO_TARGET_DIR: /tmp/vendored-protox-target
- run: git diff --exit-code

test:
Expand Down Expand Up @@ -67,12 +73,12 @@ jobs:
with:
script: |
core.exportVariable('RUSTFLAGS', '-Csymbol-mangling-version=v0');
- run: cargo test -- --include-ignored --nocapture
- run: cargo test --features experimental -- --include-ignored --nocapture
- name: Find test executable for cgroup tests
id: find-cgroup-test
if: runner.os == 'Linux' && runner.arch == 'X64'
run: |
test_executable=$(cargo build --tests --message-format json | jq -r 'select(.profile?.test == true and .target?.name == "temporalio_sdk_core" and .executable) | .executable')
test_executable=$(cargo build --tests --features experimental --message-format json | jq -r 'select(.profile?.test == true and .target?.name == "temporalio_sdk_core" and .executable) | .executable')
cp $test_executable ./core-tests
- name: Upload cgroup test executable
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
Expand All @@ -90,17 +96,29 @@ jobs:
path: machine_coverage/

msrv:
name: "Verify MSRV"
timeout-minutes: ${{ github.ref == 'refs/heads/main' && 15 || 10 }}
name: "Verify MSRV (${{ matrix.group }})"
timeout-minutes: ${{ github.ref == 'refs/heads/main' && 20 || 15 }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- group: rust-1.88
crates: client common common-wasm macros protos sdk-core workflow
- group: rust-1.92
crates: sdk
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: ./.github/actions/setup
with:
mise-install-args: protoc cargo:cargo-msrv
rust-cache-key: msrv
- run: cargo msrv verify
working-directory: ./crates/sdk-core
rust-cache-key: msrv-${{ matrix.group }}
- name: Verify crate MSRVs
run: |
read -ra crates <<< "${{ matrix.crates }}"
for crate in "${crates[@]}"; do
cargo msrv verify --all-features --path "crates/$crate"
done

cgroup-tests:
name: cgroup tests
Expand Down Expand Up @@ -171,21 +189,73 @@ jobs:
- run: cargo integ-test -t wasm_workflow_tests -- --test-threads 1

cloud-tests:
if: github.event.pull_request.head.repo.full_name == '' || github.event.pull_request.head.repo.full_name == 'temporalio/sdk-rust'
if: github.actor != 'dependabot[bot]' && (github.event.pull_request.head.repo.full_name == '' || github.event.pull_request.head.repo.full_name == 'temporalio/sdk-rust')
name: Cloud tests
env:
TEMPORAL_CLOUD_ADDRESS: https://${{ vars.TEMPORAL_CLIENT_NAMESPACE }}.tmprl.cloud:7233
TEMPORAL_NAMESPACE: ${{ vars.TEMPORAL_CLIENT_NAMESPACE }}
TEMPORAL_CLIENT_CERT: ${{ secrets.TEMPORAL_CLIENT_CERT }}
TEMPORAL_CLIENT_KEY: ${{ secrets.TEMPORAL_CLIENT_KEY }}
TEMPORAL_CLIENT_CLOUD_API_VERSION: v0.19.1
timeout-minutes: ${{ github.ref == 'refs/heads/main' && 25 || 20 }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: ./.github/actions/setup
with:
mise-install-args: protoc
- run: cargo test --features=test-utilities --test cloud_tests
- env:
TEMPORAL_CLOUD_ADDRESS: https://${{ vars.TEMPORAL_CLIENT_NAMESPACE }}.tmprl.cloud:7233
TEMPORAL_NAMESPACE: ${{ vars.TEMPORAL_CLIENT_NAMESPACE }}
TEMPORAL_CLIENT_CERT: ${{ secrets.TEMPORAL_CLIENT_CERT }}
TEMPORAL_CLIENT_KEY: ${{ secrets.TEMPORAL_CLIENT_KEY }}
run: cargo test --features=test-utilities,temporalio-sdk/experimental --test cloud_tests
- name: Generate Cloud test certificates
run: |
umask 077
cert_dir="$RUNNER_TEMP/cloud-test-certs"
mkdir "$cert_dir"
openssl req -x509 -newkey rsa:2048 -nodes -days 1 \
-keyout "$cert_dir/ca.key" -out "$cert_dir/ca.pem" \
-subj '/CN=Temporal Rust SDK Cloud CI CA'
openssl req -newkey rsa:2048 -nodes \
-keyout "$cert_dir/client.key" -out "$cert_dir/client.csr" \
-subj '/CN=Temporal Rust SDK Cloud CI'
openssl x509 -req -days 1 -in "$cert_dir/client.csr" \
-CA "$cert_dir/ca.pem" -CAkey "$cert_dir/ca.key" -CAcreateserial \
-out "$cert_dir/client.pem" -extfile <(printf 'extendedKeyUsage=clientAuth')
{
echo "TEMPORAL_CLOUD_CLIENT_CA_PATH=$cert_dir/ca.pem"
echo "TEMPORAL_TLS_CLIENT_CERT_PATH=$cert_dir/client.pem"
echo "TEMPORAL_TLS_CLIENT_KEY_PATH=$cert_dir/client.key"
} >> "$GITHUB_ENV"
- name: Create Cloud namespace
id: create-cloud-namespace
env:
TEMPORAL_CLIENT_CLOUD_API_KEY: ${{ secrets.TEMPORAL_CLIENT_CLOUD_API_KEY }}
run: cargo integ-test cloud-namespace create
- name: Run Cloud-eligible integration tests
timeout-minutes: 20
env:
TEMPORAL_ADDRESS: ${{ steps.create-cloud-namespace.outputs.namespace }}.tmprl.cloud:7233
TEMPORAL_NAMESPACE: ${{ steps.create-cloud-namespace.outputs.namespace }}
run: |
set -o pipefail
cargo integ-test -s envconfig --cloud 2>&1 | tee cloud-integration.log
- name: Delete Cloud namespace
id: delete-cloud-namespace
if: ${{ always() && steps.create-cloud-namespace.outputs.namespace != '' }}
continue-on-error: true
env:
TEMPORAL_CLIENT_CLOUD_API_KEY: ${{ secrets.TEMPORAL_CLIENT_CLOUD_API_KEY }}
run: cargo integ-test cloud-namespace delete "${{ steps.create-cloud-namespace.outputs.namespace }}"
- name: Report Cloud namespace cleanup failure
if: ${{ always() && steps.delete-cloud-namespace.outcome == 'failure' }}
run: echo "::warning title=Cloud namespace cleanup failed::Failed to delete Cloud namespace ${{ steps.create-cloud-namespace.outputs.namespace }}"
- name: Upload Cloud test output
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: cloud-integration-tests-output
path: cloud-integration.log
if-no-files-found: ignore
retention-days: 14

docker-integ-tests:
name: Docker integ tests
Expand All @@ -203,7 +273,7 @@ jobs:
with:
mise-install-args: protoc
- name: Start container for otel-collector and prometheus
uses: hoverkraft-tech/compose-action@d2bee4f07e8ca410d6b196d00f90c12e7d48c33a # v2.6.0
uses: hoverkraft-tech/compose-action@ee6af68587292d72db67743171809c19787df4c9 # v3.1.0
with:
compose-file: ./etc/docker/docker-compose-ci.yaml
- run: cargo integ-test docker_
Expand All @@ -223,11 +293,23 @@ jobs:
)"
test -x "$integ_test_binary"
test -x "$integ_runner_binary"
# The CLI is cached under a version-derived name, so the container only finds the one
# the previous step downloaded if it asks for the same version. Cargo's `[env]` does not
# reach a directly invoked binary, hence passing the pin, if any, explicitly.
cli_version_override="$(
sed -n 's/^CLI_VERSION_OVERRIDE = "\(.*\)"$/\1/p' .cargo/config.toml
)"
cli_version_env=()
if [ -n "$cli_version_override" ]; then
cli_version_env=(--env "CLI_VERSION_OVERRIDE=$cli_version_override")
fi
docker run --rm \
--env TMPDIR="$RUNNER_TEMP" \
--env TEMPORAL_TEST_EXPECT_DOCKER=true \
"${cli_version_env[@]}" \
--volume "$RUNNER_TEMP:$RUNNER_TEMP" \
--volume "$GITHUB_WORKSPACE:$GITHUB_WORKSPACE" \
--volume /etc/ssl/certs/ca-certificates.crt:/etc/ssl/certs/ca-certificates.crt:ro \
--workdir "$GITHUB_WORKSPACE" \
ubuntu:24.04 \
"$integ_runner_binary" --test-executable "$integ_test_binary" \
Expand Down
57 changes: 57 additions & 0 deletions .github/workflows/sdk-sentinel-pr-responder.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
name: SDK Sentinel PR responder relay

on:
issue_comment:
types: [created]

permissions: {}

jobs:
relay:
if: >-
github.event.issue.pull_request &&
github.event.comment.user.login != 'sdk-sentinel-bot' &&
contains(github.event.comment.body, '@sdk-sentinel-bot') &&
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Mint a Sentinel-only dispatch token from the Relay App
id: dispatch-token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2
with:
app-id: ${{ vars.SDK_SENTINEL_RELAY_APP_ID }}
private-key: ${{ secrets.SDK_SENTINEL_RELAY_PRIVATE_KEY }}
owner: temporalio
repositories: sdk-sentinel
permission-actions: write
permission-metadata: read
- name: Verify the Sentinel Relay installation
env:
ACTUAL_APP_SLUG: ${{ steps.dispatch-token.outputs.app-slug }}
ACTUAL_INSTALLATION_ID: ${{ steps.dispatch-token.outputs.installation-id }}
EXPECTED_INSTALLATION_ID: ${{ vars.SDK_SENTINEL_RELAY_INSTALLATION_ID }}
run: |
test "$ACTUAL_APP_SLUG" = sdk-sentinel-relay
test "$ACTUAL_INSTALLATION_ID" = "$EXPECTED_INSTALLATION_ID"
- name: Dispatch the trusted central responder
env:
COMMENT_ID: ${{ github.event.comment.id }}
DISPATCH_TOKEN: ${{ steps.dispatch-token.outputs.token }}
PR_NUMBER: ${{ github.event.issue.number }}
TARGET_ID: rust
run: |
payload="$(
jq -cn \
--arg target "$TARGET_ID" \
--arg pr_number "$PR_NUMBER" \
--arg comment_id "$COMMENT_ID" \
'{ref:"main",inputs:{target:$target,pr_number:$pr_number,comment_id:$comment_id}}'
)"
curl --fail --silent --show-error \
--request POST \
--header "Accept: application/vnd.github+json" \
--header "Authorization: Bearer $DISPATCH_TOKEN" \
--header "X-GitHub-Api-Version: 2022-11-28" \
--data "$payload" \
https://api.github.com/repos/temporalio/sdk-sentinel/actions/workflows/sdk-pr-responder.yml/dispatches
Loading
Loading