Skip to content

ci: require shared installer confirmation through PR comments - #108

Closed
karthikbekalp wants to merge 1 commit into
aws-deadline:mainlinefrom
karthikbekalp:ci/installer-coordination-comments
Closed

karthikbekalp wants to merge 1 commit into
aws-deadline:mainlinefrom
karthikbekalp:ci/installer-coordination-comments

Conversation

@karthikbekalp

@karthikbekalp karthikbekalp commented Oct 7, 2026 •

Copy link
Copy Markdown

Installer definition changes can require a corresponding update to the shared Deadline Cloud submitter installer. Add a static confirmation check that asks the PR author or a maintainer through one public PR comment.

The checker watches XML definitions under installer/ and install_builder/, including additions, deletions, nested files, and both sides of renames. It creates or updates one bot comment and accepts exactly one of these commands in a new PR conversation comment:

  • /installer-followup done
  • /installer-followup in-review
  • /installer-followup not-needed

Accepted commands update the same comment and make the Installer coordination status pass. Missing confirmation keeps it failing; editing or deleting the only valid response makes it fail again. Unrelated PRs pass without a question. Maintainer replies require current write, maintain, or admin permission. The checker uses fixed public wording and never echoes reply text, review identifiers, or tracking links.

The reusable workflow supports trusted pull_request_target and issue_comment callers, including fork PRs. It checks out only central tooling and never executes PR code. It explicitly publishes the status on the current PR head because comment events run on the default branch. Incomplete or stale API data and posting failures produce an error instead of a successful result.

Validation: all 88 Python 3.13 unit tests pass, including 30 new tests for detection, command permissions, comment reuse, response edits/deletions, fork-head status updates, and error handling. Actionlint and zizmor validation passes for the reusable workflow and all 10 callers. The trusted-trigger annotation documents why pull_request_target is safe here: only central tooling is checked out and PR data is never executed.

Merge this central workflow before the caller PRs. After a caller runs, configure the Installer coordination commit status as required in the repository's mainline branch protection rule or ruleset to enforce confirmation before merge. The setup guide documents the commands, permissions, caller workflow, and rollout.

Caller rollout drafts (each contains only the new caller workflow):

Repository Draft PR
Houdini aws-deadline/deadline-cloud-for-houdini#402
Maya aws-deadline/deadline-cloud-for-maya#486
Blender aws-deadline/deadline-cloud-for-blender#399
Unreal Engine aws-deadline/deadline-cloud-for-unreal-engine#417
3ds Max aws-deadline/deadline-cloud-for-3ds-max#300
After Effects aws-deadline/deadline-cloud-for-after-effects#347
Cinema 4D aws-deadline/deadline-cloud-for-cinema-4d#583
Nuke aws-deadline/deadline-cloud-for-nuke#367
KeyShot aws-deadline/deadline-cloud-for-keyshot#287
VRED aws-deadline/deadline-cloud-for-vred#164

Signed-off-by: Karthik BekalPattathana <133984042+karthikbekalp@users.noreply.github.com>
if isinstance(sha, str) and re.fullmatch(r"[0-9a-f]{40}", sha):
try:
set_status(repo, sha, "error", DATA_ERROR, run_url)
except (OSError, subprocess.CalledProcessError, json.JSONDecodeError, TypeError, ValueError):
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants