From c3a038e6532ebddc38783bcab924ac6c56289b45 Mon Sep 17 00:00:00 2001 From: "wayne@stellar.tech" Date: Tue, 29 Sep 2026 09:40:25 -0700 Subject: [PATCH] ci: move public workflows to GitHub-hosted runners --- .github/workflows/ci.yml | 23 +++-------------------- .github/workflows/publish.yml | 23 +++-------------------- 2 files changed, 6 insertions(+), 40 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4996ae2..d21f8e3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -14,7 +14,7 @@ on: jobs: test: name: Node.js v22 - runs-on: codebuild-stellaraf-actions-public-${{ github.run_id }}-${{ github.run_attempt }} + runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 @@ -31,29 +31,12 @@ jobs: run: | echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT" echo "node=$(node --version)" >> "$GITHUB_OUTPUT" - - name: Export temporary AWS cache credentials - shell: bash - run: | - python3 - <<'PYTHON' - import json, os, subprocess - credentials = json.loads(subprocess.check_output(['aws', 'configure', 'export-credentials', '--format', 'process'])) - with open(os.environ['GITHUB_ENV'], 'a') as output: - for source, target in [('AccessKeyId', 'AWS_ACCESS_KEY_ID'), ('SecretAccessKey', 'AWS_SECRET_ACCESS_KEY'), ('SessionToken', 'AWS_SESSION_TOKEN')]: - value = credentials[source] - if not value or '\n' in value or '\r' in value: - raise RuntimeError('Invalid temporary credential value') - print('::add-mask::' + value) - output.write(target + '=' + value + '\n') - PYTHON - - name: Restore pnpm download store from S3 - uses: tespkg/actions-cache@e07e2d4953dc8c020d447363e5064e36d04f3cf9 + - name: Restore pnpm download store + uses: actions/cache@v4 with: - region: us-west-1 - bucket: stellaraf-public-ci-961341522852-us-west-1 path: ${{ steps.ci-pnpm-cache.outputs.path }} key: cache/${{ github.repository }}/${{ github.ref }}/pnpm-7.33.7/${{ runner.os }}/${{ runner.arch }}/${{ steps.ci-pnpm-cache.outputs.node }}/${{ hashFiles('pnpm-lock.yaml') }} - use-fallback: false - name: Install run: pnpm install --frozen-lockfile diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 63d73da..75c0a74 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -6,7 +6,7 @@ on: jobs: publish: name: Node.js v22 - runs-on: codebuild-stellaraf-actions-public-${{ github.run_id }}-${{ github.run_attempt }} + runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 @@ -23,29 +23,12 @@ jobs: run: | echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT" echo "node=$(node --version)" >> "$GITHUB_OUTPUT" - - name: Export temporary AWS cache credentials - shell: bash - run: | - python3 - <<'PYTHON' - import json, os, subprocess - credentials = json.loads(subprocess.check_output(['aws', 'configure', 'export-credentials', '--format', 'process'])) - with open(os.environ['GITHUB_ENV'], 'a') as output: - for source, target in [('AccessKeyId', 'AWS_ACCESS_KEY_ID'), ('SecretAccessKey', 'AWS_SECRET_ACCESS_KEY'), ('SessionToken', 'AWS_SESSION_TOKEN')]: - value = credentials[source] - if not value or '\n' in value or '\r' in value: - raise RuntimeError('Invalid temporary credential value') - print('::add-mask::' + value) - output.write(target + '=' + value + '\n') - PYTHON - - name: Restore pnpm download store from S3 - uses: tespkg/actions-cache@e07e2d4953dc8c020d447363e5064e36d04f3cf9 + - name: Restore pnpm download store + uses: actions/cache@v4 with: - region: us-west-1 - bucket: stellaraf-public-ci-961341522852-us-west-1 path: ${{ steps.ci-pnpm-cache.outputs.path }} key: cache/${{ github.repository }}/${{ github.ref }}/pnpm-7.33.7/${{ runner.os }}/${{ runner.arch }}/${{ steps.ci-pnpm-cache.outputs.node }}/${{ hashFiles('pnpm-lock.yaml') }} - use-fallback: false - name: Install run: pnpm install --frozen-lockfile