Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -93,6 +93,17 @@ jobs:
assert.ok(snapshot.coverage.aic.total === null || typeof snapshot.coverage.aic.total === 'number');
NODE

install-labels:
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- name: Checkout repository
uses: actions/checkout@v7

- name: Test label installer
run: node --test tests/install-labels.test.js

history-immutability:
if: github.event_name == 'pull_request'
runs-on: ubuntu-24.04
Expand Down
71 changes: 71 additions & 0 deletions .github/workflows/install-labels-org.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
name: Install labels on pipeline repositories

# This is a plain (non-gh-aw) workflow: installs the pipeline's labels
# (scripts/install-labels.js LABELS) on every repository in the organization
# that runs the pipeline, i.e. contains any of drafter.lock.yml,
# review.lock.yml or fix.lock.yml in .github/workflows, so they pick up new or
# renamed labels without waiting for their own copy of install-labels.yml to
# be updated. It only creates labels and fixes their color, description and
# name case; it never deletes one.
#
# Labels every repository should have regardless of the pipeline are synced by
# bootc-dev/infra (labels.toml) instead; this workflow owns only the agent/*
# labels. It is not part of the gh-aw package (aw.yml): it's specific to the
# organization hosting this repository.

on:
# Every push to main syncs, not only those changing the label set: a run
# that finds nothing to change costs one label listing per pipeline
# repository, and it repairs labels changed by hand or reverted by a
# repository's outdated install-labels.yml without polling for drift.
push:
branches: [main]
workflow_dispatch:
inputs:
dry-run:
description: "Only print the planned label changes (uncheck to apply them)"
type: boolean
default: true

permissions:
contents: read

concurrency:
group: install-labels-org
cancel-in-progress: false

jobs:
install-labels:
# Forks have neither the App credentials nor any business editing the
# organization's labels.
if: github.repository == 'bootc-dev/gh-agentic-workflows'
runs-on: ubuntu-24.04
steps:
- name: Checkout repository
uses: actions/checkout@v7
with:
persist-credentials: false

# The pipeline's own App: it is installed wherever the pipeline runs,
# and --installation below only considers repositories it can access.
- name: Generate label token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ vars.GH_AW_APP_CLIENT_ID }}
private-key: ${{ secrets.GH_AW_APP_PRIVATE_KEY }}
owner: ${{ github.repository_owner }}
# Labels are managed through the Issues API; contents: read is for
# detecting the pipeline marker file.
permission-issues: write
permission-contents: read

- name: Install labels
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
ORG: ${{ github.repository_owner }}
DRY_RUN: ${{ inputs.dry-run && '--dry-run' || '' }}
run: |
set -euo pipefail
# shellcheck disable=SC2086 # DRY_RUN is empty or a single flag.
node scripts/install-labels.js --org "$ORG" --installation $DRY_RUN
34 changes: 32 additions & 2 deletions scripts/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,8 @@ The script creates or updates the following labels:

- **`agent/workflow-edits-allowed`** (purple) — Pre-authorizes an agent run to edit protected files (workflows, README, etc.) without triggering the request_review gate. Apply this to an issue before labeling it `agent/code`, or to a PR before applying `agent/fixme`.

- **`agent/flake-tracker`** (blue) — Marks the CI flake tracker issue that the merge queue analyzer (`queue-triage.md`) maintains.

### Usage

#### Via GitHub Actions
Expand All @@ -85,6 +87,33 @@ Alternatively, you can copy `.github/workflows/install-labels.yml` to your own r
workflow inlines the LABELS array and install loop directly in its `actions/github-script` step, so it has no
dependency on this file being checked out.

#### On every pipeline repository in bootc-dev

`.github/workflows/install-labels-org.yml` runs this script on every push to `main` and on
dispatch. It installs the labels on every non-archived
bootc-dev repository that runs the pipeline, i.e. contains any of `drafter.lock.yml`,
`review.lock.yml` or `fix.lock.yml` in `.github/workflows`, and that the `GH_AW_APP_*` App
is installed on. Other repositories are left alone. It creates missing labels and fixes the color,
description and name case of existing ones, but never deletes a label. It is not part of the gh-aw
package and runs only from `bootc-dev/gh-agentic-workflows`.

Each pipeline repository also keeps running its own weekly copy of `install-labels.yml`,
which only picks up label changes when that repository runs `gh aw update`. So after a
label's color or description changes here, that copy reverts it to the old value (and
recreates a renamed label's old name) every week until the repository updates it, and
the next push to `main` here applies the new value again.

Only the `agent/*` labels are managed here. Labels every bootc-dev and composefs
repository should have regardless of the pipeline (e.g. `triaged`) are synced by
[bootc-dev/infra](https://github.com/bootc-dev/infra)'s `labels.toml`.

To see what it would change without writing anything, run it with any authenticated
`gh` (read access is enough), or dispatch the workflow, which does a dry run unless `dry-run` is unchecked:

```bash
node scripts/install-labels.js --org bootc-dev --dry-run
```

#### Via github-script action

If you want to integrate label installation into your own workflow, `install-labels.js` is a plain CommonJS module
Expand Down Expand Up @@ -137,5 +166,6 @@ gh api repos/:owner/:repo/labels/agent/code -X PATCH \
### Customizing Labels

To customize the labels (change colors, descriptions, or add new ones), edit the `LABELS` array in
`install-labels.js` **and** the matching copy in `.github/workflows/install-labels.yml`, then rerun the
installation workflow to update the labels on your repository.
`install-labels.js` **and** the matching copy in `.github/workflows/install-labels.yml`
(`tests/install-labels.test.js` fails if they differ), then rerun the installation workflow to update
the labels on your repository.
Loading