Skip to content

Commit e050b5e

Browse files
committed
Unify CI, benchmark site publication and dated database releases
1 parent 660b608 commit e050b5e

47 files changed

Lines changed: 2672 additions & 642 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/AGENTS.md‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
## Purpose and entry points
44
- Owns repository CI qualification and GitHub Pages publication workflows.
55
- Canonical workflows: `ci.yml` (restore, Release build, TUnit unit/integration/recovery suites and comparison artifact production) and `pages.yml` (verified artifact download, site checks/build and Pages deployment).
6-
- Owner clarification 2026-10-03 supersedes the historical placement above: `ci.yml` (`CI`) always includes repository rules and PR checks; `tests.yml` (`Tests`) owns project qualification; `benchmarks.yml` (`Benchmarks`) owns all performance comparisons and TimeSeries image checks; `release.yml` (`Release`) builds NuGet package artifacts; `pages.yml` (`Website`) publishes the qualified site. Do not create standalone governance or per-feature comparison workflows. Preserve exact historical KeyLoad CI main-push identity separately from its current CI metadata name under ADR-062.
6+
- Latest owner correction 2026-10-03 supersedes the historical placements above and ADR-062's five-workflow scope: exactly `ci.yml` (`CI`) combines build/rules/unit/scalar/recovery/RF3 for PR/push/manual checks; `benchmarks.yml` (`Benchmarks`) owns all load/comparison/TimeSeries checks followed by aggregate-gated website qualification and publication; `release.yml` (`Release`) builds all packages and actual database images/distribution and creates the release/tag `v<major>.<minor>.<yyMMdd>.<daily-build>`. Remove standalone Tests/Website/governance/per-feature benchmark workflows. Preserve authentic historical KeyLoad CI report bytes and run identity independently of the current CI name; newer CI build/test runs are not historical measurement producers.
77

88
## Ownership and boundaries
99
- Workflow changes belong to the feature or infrastructure contract they implement and must preserve the repository's single-repository, canonical-slice architecture. Workflow YAML is delivery infrastructure, not a place to hide missing product behavior.
@@ -43,3 +43,7 @@
4343
- ADR056 adds authenticated successful comparison-aggregate selection and the complete270-cell/native-image proof, independently of the retained legacy comparison evidence. Qualify both original archives and all277 isolated inputs through BCL before-session preparation and preserve their byte hashes after tests and around the final builder.
4444
- Capture actual Pages executor context; never impersonate the CI-only job environment. Historical pins are validation-only. Hash and compare the complete closed executed49-file dependency closure between trusted control and website source; separately inspect the isolated measured source.
4545
- Retain full site/TUnit/browser/native coverage/no-skip gates. Qualification timeout180min and deployment freshness90min accommodate the bounded same-route provider rate protocol. Both native evidence freshness checks and current website SHA must pass immediately before needs-gated least-privilege Pages deployment.
46+
47+
## Owner-directed integrated publication and release, 2026-10-03
48+
- The latest three-pipeline instruction explicitly supersedes the separate pages.yml placement above. Move its complete qualification/deploy stages behind the successful Benchmarks aggregate, bind current producer run/attempt/SHA directly from GitHub's executor context, and recheck that tuple before deployment. Historical validation pins cannot impersonate this current producer.
49+
- Release uses UTC daily version reservation, immutable source-bound tags, actual database image/package/distribution hashes and an idempotent GitHub Release. Limit contents/packages write permissions to the publication job; reservation/build/test jobs remain read-only. Do not publish a failed build, overwrite an existing tag/image/release asset, bypass required checks or claim runtime qualification from packaging.

‎.github/workflows/Features/BenchmarkComparisons/BuildIsolatedSite/AGENTS.md‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,3 +19,6 @@
1919
- No applicable workflow skill is installed; installing skills or tools is prohibited.
2020
- Preserve least privilege and the actual inherited GitHub context. Never log secrets, forge a CI environment, add a provider fallback, weaken gates or rewrite measured inputs.
2121
- Require the isolated receipt to be a regular non-link file of at most4MiB before parsing; preserve original receipt bytes and hashes across the builder. Do not use generic archive extraction or replace original authority with a rewritten receipt.
22+
23+
## Owner-directed three-pipeline join, 2026-10-03
24+
- The latest explicit owner layout moves this full qualification into Benchmarks/benchmarks.yml behind its own successful aggregate and TimeSeries image jobs, superseding pages.yml placement above. Retain the exact qualify job name, actual inherited executor, every archive/hash/TUnit/browser/coverage check, and downstream least-privilege deployment. Only the exact current benchmark run/attempt/source may refresh native metrics; historical archive validation remains separately authentic.
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# DeploySite
2+
3+
## Purpose and entry points
4+
- Owns the BenchmarkComparisons DeploySite composite action under ADR-064/AC-PIPE-002..003. Read root/workflow policy, ReleaseDelivery and BenchmarkComparisons specs before edits. Entry: action.yml.
5+
6+
## Boundaries and protected risks
7+
- Preserve every original archive/hash/native/browser/TUnit/coverage/freshness gate. Use actual inherited Benchmarks qualify/deploy context and the exact current run/attempt/source; no historical publication fallback or forged executor.
8+
- Lead alone owns workflows, permissions, source closure, docs and delivery. Three persistent RF3 owners and all isolated measurement jobs remain unchanged.
9+
- The qualification compares both new actions' source/policy with trusted control and the current website checkout. Deployment writes remain confined to the needs-gated deploy job.
10+
11+
## Commands and verification
12+
- Execute only in Linux GitHub Actions under the exact qualify/deploy job name. Static YAML/shell/source checks are not runtime or provider qualification. No local tests or providers.
13+
14+
## Applicable skills
15+
- No installed skill is required for this bounded workflow composition; install none.
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
name: Publish the current benchmark website
2+
description: Recheck exact source and current producer tuple before least-privilege Pages delivery.
3+
outputs:
4+
page_url:
5+
value: ${{ steps.deployment.outputs.page_url }}
6+
runs:
7+
using: composite
8+
steps:
9+
- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
10+
with:
11+
name: site-qualification-${{ env.QUALIFIED_REVISION }}-${{ github.run_attempt }}
12+
path: qualification
13+
- name: Recheck current website and immutable comparison evidence
14+
shell: bash
15+
run: |
16+
revision=$(timeout 120s gh api "repos/$GH_REPO/git/ref/heads/main" --jq .object.sha)
17+
[[ "$revision" == "$QUALIFIED_REVISION" ]]
18+
capture="$GITHUB_WORKSPACE/predeploy-capture"
19+
bash control/scripts/Features/BenchmarkComparisons/collect-github-evidence.sh --input="$capture" --mode=publish --site-revision="$revision" --workflow-revision="$CONTROL_REVISION"
20+
node control/scripts/Features/BenchmarkComparisons/github-evidence.mjs fresh --before="$GITHUB_WORKSPACE/qualification/artifacts/site-evidence/archive-receipt.json" --after="$capture/metadata-proof.json" > predeploy-proof.json
21+
isolated_capture="$GITHUB_WORKSPACE/predeploy-isolated-capture"
22+
node control/scripts/Features/BenchmarkComparisons/site-isolated-github-cli.mjs capture-metadata --input="$isolated_capture" --mode=publish --site-revision="$revision" --workflow-revision="$CONTROL_REVISION" > predeploy-isolated-capture-envelope.json
23+
jq -e '.ok == true' predeploy-isolated-capture-envelope.json > /dev/null
24+
node control/scripts/Features/BenchmarkComparisons/site-isolated-github-cli.mjs fresh --before="$GITHUB_WORKSPACE/qualification/artifacts/site-evidence/isolated-capture/archive-receipt.json" --after="$isolated_capture/metadata-proof.json" > predeploy-isolated-proof.json
25+
jq -e '.ok == true' predeploy-isolated-proof.json > /dev/null
26+
date --utc --iso-8601=seconds > predeploy-checked-at.txt
27+
- uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5
28+
- name: Publish qualified website
29+
id: deployment
30+
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
31+
- name: Record actual Pages deployment result
32+
if: always()
33+
env:
34+
DEPLOYMENT_OUTCOME: ${{ steps.deployment.outcome }}
35+
DEPLOYMENT_URL: ${{ steps.deployment.outputs.page_url }}
36+
SITE_REVISION: ${{ env.QUALIFIED_REVISION }}
37+
shell: bash
38+
run: |
39+
jq -n --arg outcome "$DEPLOYMENT_OUTCOME" --arg url "$DEPLOYMENT_URL" --arg revision "$SITE_REVISION" --arg run_url "https://github.com/$GH_REPO/actions/runs/$GITHUB_RUN_ID" --argjson attempt "$GITHUB_RUN_ATTEMPT" '{schemaVersion:1,siteSourceRevision:$revision,qualification:{runUrl:$run_url,attempt:$attempt},provider:{outcome:$outcome,pageUrl:$url}}' > deployment-receipt.json
40+
- name: Retain freshness and deployment receipt
41+
if: always()
42+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
43+
with:
44+
name: site-publication-${{ github.run_id }}-${{ github.run_attempt }}
45+
path: |
46+
predeploy-capture
47+
predeploy-proof.json
48+
predeploy-isolated-capture
49+
predeploy-isolated-capture-envelope.json
50+
predeploy-isolated-proof.json
51+
predeploy-checked-at.txt
52+
deployment-receipt.json
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# QualifySite
2+
3+
## Purpose and entry points
4+
- Owns the BenchmarkComparisons QualifySite composite action under ADR-064/AC-PIPE-002..003. Read root/workflow policy, ReleaseDelivery and BenchmarkComparisons specs before edits. Entry: action.yml.
5+
6+
## Boundaries and protected risks
7+
- Preserve every original archive/hash/native/browser/TUnit/coverage/freshness gate. Use actual inherited Benchmarks qualify/deploy context and the exact current run/attempt/source; no historical publication fallback or forged executor.
8+
- Lead alone owns workflows, permissions, source closure, docs and delivery. Three persistent RF3 owners and all isolated measurement jobs remain unchanged.
9+
- The qualification compares both new actions' source/policy with trusted control and the current website checkout. Deployment writes remain confined to the needs-gated deploy job.
10+
11+
## Commands and verification
12+
- Execute only in Linux GitHub Actions under the exact qualify/deploy job name. Static YAML/shell/source checks are not runtime or provider qualification. No local tests or providers.
13+
14+
## Applicable skills
15+
- No installed skill is required for this bounded workflow composition; install none.

0 commit comments

Comments
 (0)