diff --git a/.github/workflows/incluster-comp-pr-merged.yaml b/.github/workflows/incluster-comp-pr-merged.yaml index 9ab51c7..ca26788 100644 --- a/.github/workflows/incluster-comp-pr-merged.yaml +++ b/.github/workflows/incluster-comp-pr-merged.yaml @@ -251,6 +251,10 @@ jobs: GH_TOKEN: ${{ steps.app-token.outputs.token }} CORRELATION_ID: ${{ steps.dispatch-info.outputs.correlation_id }} REQUIRED_TESTS: ${{ needs.docker-build.outputs.TEST_NAMES }} + COMPONENT_NAME: ${{ inputs.COMPONENT_NAME }} + IMAGE_TAG_PRERELEASE: ${{ needs.docker-build.outputs.IMAGE_TAG_PRERELEASE }} + SYSTEM_TESTS_BRANCH: ${{ inputs.SYSTEM_TESTS_BRANCH }} + HELM_BRANCH: ${{ inputs.HELM_BRANCH }} run: | ADDITIONAL_TESTS=$(python3 - <<'PY' import json, os @@ -262,7 +266,7 @@ jobs: print(" ".join(tests)) PY ) - case "${{ inputs.COMPONENT_NAME }}" in + case "${COMPONENT_NAME}" in operator) TESTS_GROUP="OPERATOR_E2E" ;; @@ -291,12 +295,12 @@ jobs: # (e.g. http-request, prometheus-exporter) makes armosec/system-tests reject # the dispatch as an unrecognised override. COMPONENT_TAG_ARGS=() - case "${{ inputs.COMPONENT_NAME }}" in + case "${COMPONENT_NAME}" in kubescape|operator|kubevuln|kollector|gateway|storage|nodeAgent) - COMPONENT_TAG_ARGS=(-f "inputs[component_image_tags]=${{ inputs.COMPONENT_NAME }}-tag=${{ needs.docker-build.outputs.IMAGE_TAG_PRERELEASE }}") + COMPONENT_TAG_ARGS=(-f "inputs[component_image_tags]=${COMPONENT_NAME}-tag=${IMAGE_TAG_PRERELEASE}") ;; *) - echo "Component '${{ inputs.COMPONENT_NAME }}' is not part of the kubescape-operator chart; skipping component_image_tags override" + echo "Component '${COMPONENT_NAME}' is not part of the kubescape-operator chart; skipping component_image_tags override" ;; esac @@ -308,8 +312,8 @@ jobs: -f "inputs[environment]=production" \ -f "inputs[tests_groups]=${TESTS_GROUP}" \ -f "inputs[additional_tests]=${ADDITIONAL_TESTS}" \ - -f "inputs[systests_branch]=${{ inputs.SYSTEM_TESTS_BRANCH }}" \ - -f "inputs[in_cluster_chart_branch]=${{ inputs.HELM_BRANCH }}" \ + -f "inputs[systests_branch]=${SYSTEM_TESTS_BRANCH}" \ + -f "inputs[in_cluster_chart_branch]=${HELM_BRANCH}" \ -f "inputs[ks_branch]=release" \ -f "inputs[charts_repo]=kubescape/helm-charts" \ "${COMPONENT_TAG_ARGS[@]}") @@ -340,9 +344,14 @@ jobs: fi # Re-run: the dispatch step is skipped, so find the run the first attempt started. - # It is minutes old by now, so the run list already shows it. - run_id=$(gh api "repos/armosec/shared-workflows/actions/workflows/helm-e2e-receiver.yaml/runs?per_page=100" \ - --jq '.workflow_runs | map(select(.name | contains("'"$CORRELATION_ID"'"))) | first | .id // empty') + # The App token can see a new run minutes late, so retry for a while. + for i in {1..15}; do + run_id=$(gh api "repos/armosec/shared-workflows/actions/workflows/helm-e2e-receiver.yaml/runs?per_page=100" \ + --jq '.workflow_runs | map(select(.name | contains("'"$CORRELATION_ID"'"))) | first | .id // empty') + [ -n "$run_id" ] && break + echo "Attempt $i: waiting for the first attempt's run to show up..." + sleep 30 + done if [ -z "$run_id" ]; then echo "::error::Could not find the E2E run started by the first attempt (${CORRELATION_ID})" exit 1 diff --git a/.github/workflows/kubescape-cli-e2e-tests.yaml b/.github/workflows/kubescape-cli-e2e-tests.yaml index 22912db..f488826 100644 --- a/.github/workflows/kubescape-cli-e2e-tests.yaml +++ b/.github/workflows/kubescape-cli-e2e-tests.yaml @@ -114,6 +114,11 @@ jobs: GH_TOKEN: ${{ steps.app-token.outputs.token }} CORRELATION_ID: ${{ steps.dispatch-info.outputs.correlation_id }} REQUIRED_TESTS: ${{ needs.wf-preparation.outputs.TEST_NAMES }} + SOURCE_RUN_ID: ${{ github.run_id }} + ARTIFACT_KEY_NAME: ${{ inputs.DOWNLOAD_ARTIFACT_KEY_NAME }} + ARTIFACT_PATH: ${{ inputs.DOWNLOAD_ARTIFACT_PATH }} + USE_ARTIFACTS_FILE: ${{ inputs.USE_ARTIFACTS_FILE }} + SYSTEM_TESTS_BRANCH: ${{ inputs.SYSTEM_TESTS_BRANCH }} run: | ADDITIONAL_TESTS=$(python3 - <<'PY' import json, os @@ -132,10 +137,10 @@ jobs: SOURCE_ARTIFACT=$(jq -cn \ --arg repo "${GITHUB_REPOSITORY}" \ - --arg run_id "${{ github.run_id }}" \ - --arg name "${{ inputs.DOWNLOAD_ARTIFACT_KEY_NAME }}" \ - --arg path "${{ inputs.DOWNLOAD_ARTIFACT_PATH }}" \ - --arg use_file "${{ inputs.USE_ARTIFACTS_FILE }}" \ + --arg run_id "${SOURCE_RUN_ID}" \ + --arg name "${ARTIFACT_KEY_NAME}" \ + --arg path "${ARTIFACT_PATH}" \ + --arg use_file "${USE_ARTIFACTS_FILE}" \ '{repo: $repo, run_id: $run_id, name: $name, path: $path, use_file: $use_file}') RESPONSE=$(gh api --method POST "repos/armosec/shared-workflows/actions/workflows/helm-e2e-receiver.yaml/dispatches" \ @@ -146,7 +151,7 @@ jobs: -f "inputs[environment]=production" \ -f "inputs[tests_groups]=${TESTS_GROUP}" \ -f "inputs[additional_tests]=${ADDITIONAL_TESTS}" \ - -f "inputs[systests_branch]=${{ inputs.SYSTEM_TESTS_BRANCH }}" \ + -f "inputs[systests_branch]=${SYSTEM_TESTS_BRANCH}" \ -f "inputs[ks_branch]=release" \ --raw-field "inputs[source_artifact]=${SOURCE_ARTIFACT}") @@ -176,9 +181,14 @@ jobs: fi # Re-run: the dispatch step is skipped, so find the run the first attempt started. - # It is minutes old by now, so the run list already shows it. - run_id=$(gh api "repos/armosec/shared-workflows/actions/workflows/helm-e2e-receiver.yaml/runs?per_page=100" \ - --jq '.workflow_runs | map(select(.name | contains("'"$CORRELATION_ID"'"))) | first | .id // empty') + # The App token can see a new run minutes late, so retry for a while. + for i in {1..15}; do + run_id=$(gh api "repos/armosec/shared-workflows/actions/workflows/helm-e2e-receiver.yaml/runs?per_page=100" \ + --jq '.workflow_runs | map(select(.name | contains("'"$CORRELATION_ID"'"))) | first | .id // empty') + [ -n "$run_id" ] && break + echo "Attempt $i: waiting for the first attempt's run to show up..." + sleep 30 + done if [ -z "$run_id" ]; then echo "::error::Could not find the E2E run started by the first attempt (${CORRELATION_ID})" exit 1