Automate Taskcluster reports and optional Pages publishing with GitHub Actions - #14
Merged
lotas merged 2 commits intoSep 16, 2026
Conversation
lotas
approved these changes
Sep 16, 2026
lotas
left a comment
Contributor
There was a problem hiding this comment.
let's see how it works, thanks!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add GitHub Actions workflows to replace the NAS-based report automation, with optional GitHub Pages publishing.
The report workflow snapshots configuration, creates worker probes, waits 90 minutes, collects results, commits snapshots, and rebuilds history. Manual runs default to dry-run mode: they create real probes and upload a reviewable patch, but do not push or deploy.
Scheduled runs are opt-in and run every Monday at 07:23 UTC (12:23 a.m. PDT / Sunday 11:23 p.m. PST). GitHub may delay scheduled starts.
Setup and rollout
TASKCLUSTER_CLIENT_IDandTASKCLUSTER_ACCESS_TOKEN.GITHUB_TOKEN.dry_run=true. Verify that the restricted client works, and review the task group, logs, andreport-changespatch artifact.dry_run=falseand verify the published reports and history. This creates another set of probes.ENABLE_SCHEDULED_REPORTS=trueto enable weekly runs, and retire the NAS job after successful verification.Maintainers should enable Actions failure notifications. Remove or disable
ENABLE_SCHEDULED_REPORTSto stop scheduled scans; manual runs remain available.Taskcluster client scopes
Proposed explicit scopes for the dedicated automation client:
auth:list-clientsqueue:create-task:lowest:*queue:scheduler-id:smoketestqueue:seal-task-group:smoketest/*These allow client enumeration, lowest-priority probes across the discovered worker pools, and task-group sealing under scheduler
smoketest. Other required read permissions are currently provided by Firefox CI's anonymous role. The tools do not require worker-quarantine or secret-reading permissions.This scope set was derived from the reporting code and live API definitions; validate it with the initial manual dry run before enabling scheduling.
Runtime and cost
Each report run includes a 90-minute wait for worker probes and has a 150-minute timeout. Scheduling is weekly and opt-in, with report runs serialized to prevent overlap.
The workflow uses standard GitHub-hosted Ubuntu runners, which are free for public repositories under GitHub's current billing policy.
Optional GitHub Pages publishing
PUBLISH_REPORT_PAGES=trueto deploy automatically after successful non-dry report runs. Leave unset to retain the existing publishing setup.Validation
Rebased onto the merged reporting improvements without conflicts or changes to either commit. Zizmor passes; local actionlint flags the
$/reusable-workflow syntax recommended by zizmor. End-to-end report generation and deployment have not been run.