From 9086feb49ae761f2844fb183c2ef9f11097ad842 Mon Sep 17 00:00:00 2001 From: Erica Portnoy Date: Fri, 17 Apr 2026 14:26:26 -0700 Subject: [PATCH 1/5] modify .gitignore to ignore files created during the migration process --- .gitignore | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.gitignore b/.gitignore index dcd20b9bd..49fcff369 100644 --- a/.gitignore +++ b/.gitignore @@ -68,3 +68,7 @@ snapcraft.cfg # macOS files .DS_Store + +# azure workflow migration +.env.local +tmp From d2c39a3980eda3cce604e57bfeb9b6be7bb1a2cd Mon Sep 17 00:00:00 2001 From: Erica Portnoy Date: Fri, 17 Apr 2026 14:39:01 -0700 Subject: [PATCH 2/5] add sphinx tests; compare to .azure-pipelines/templates/steps/sphinx-steps.yml which is still needed for other pipelines on azure --- .github/workflows/sphinx_steps.yml | 37 ++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 .github/workflows/sphinx_steps.yml diff --git a/.github/workflows/sphinx_steps.yml b/.github/workflows/sphinx_steps.yml new file mode 100644 index 000000000..c65ee78d6 --- /dev/null +++ b/.github/workflows/sphinx_steps.yml @@ -0,0 +1,37 @@ +name: Sphinx steps +on: + workflow_call: +permissions: + contents: read + +jobs: + test_sphinx_builds: + name: Build Sphinx Documentation + runs-on: ubuntu-latest + steps: + - name: checkout + uses: actions/checkout@v6.0.2 + - name: Build Sphinx Documentation + run: |- + set -e + sudo apt-get update + sudo apt-get install -y --no-install-recommends libaugeas-dev + FINAL_STATUS=0 + declare -a FAILED_BUILDS + tools/venv.py + source venv/bin/activate + for doc_path in */docs + do + echo "" + echo "##[group]Building $doc_path" + if ! sphinx-build -W --keep-going -b html $doc_path $doc_path/_build/html; then + FINAL_STATUS=1 + FAILED_BUILDS[${#FAILED_BUILDS[@]}]="${doc_path%/docs}" + fi + echo "##[endgroup]" + done + if [[ $FINAL_STATUS -ne 0 ]]; then + echo "##[error]The following builds failed: ${FAILED_BUILDS[*]}" + exit 1 + fi + shell: bash From 7690b4c0190fd26f1206187e0e9e72e94e6a0bd3 Mon Sep 17 00:00:00 2001 From: Erica Portnoy Date: Fri, 17 Apr 2026 14:39:39 -0700 Subject: [PATCH 3/5] add tox steps; compare to .azure-pipelines/templates/steps/tox-steps.yml which is still needed for other pipelines on azure --- .github/workflows/tox_steps.yml | 124 ++++++++++++++++++++++++++++++++ 1 file changed, 124 insertions(+) create mode 100644 .github/workflows/tox_steps.yml diff --git a/.github/workflows/tox_steps.yml b/.github/workflows/tox_steps.yml new file mode 100644 index 000000000..38dff477f --- /dev/null +++ b/.github/workflows/tox_steps.yml @@ -0,0 +1,124 @@ +name: Tox steps +on: + workflow_call: + inputs: + PYTHON_VERSION: + type: string + IMAGE_NAME: + type: string + TOXENV: + type: string + PIP_USE_PEP517: + type: string + uploadCoverage: + description: 'Upload coverage to Codecov' + type: boolean + default: false + AWS_ACCESS_KEY_ID: + description: 'access key ID for AWS' + type: string + AWS_SECRET_ACCESS_KEY: + description: 'access key for AWS' + type: string + AWS_TEST_FARM_PEM: + description: 'contents of AWS PEM file to be placed in $AWS_EC2_PEM_FILE from environment' + type: string + test_name: + type: string +permissions: + contents: read + +env: + uploadCoverage: ${{ inputs.uploadCoverage }} + +jobs: + tox_all: + name: ${{ inputs.test_name }} ${{ inputs.IMAGE_NAME }}-${{ inputs.TOXENV }} + runs-on: + - "${{ inputs.IMAGE_NAME }}" + steps: + - name: Checkout + uses: actions/checkout@v6.0.2 + # We run brew update because we've seen attempts to install an older version + # of a package fail. See + # https://github.com/actions/virtual-environments/issues/3165. + # + # We untap homebrew/core and homebrew/cask and unset HOMEBREW_NO_INSTALL_FROM_API (which + # is maybe set by the CI macOS env) because GitHub has been having issues, making these jobs + # fail on git clones: https://github.com/orgs/Homebrew/discussions/4612. + - name: Install MacOS dependencies + if: runner.os == 'macOS' + id: mac_install + run: |- + set -e + unset HOMEBREW_NO_INSTALL_FROM_API + brew untap homebrew/core homebrew/cask + brew update + brew install augeas + BREW_PREFIX=$(brew --prefix) + CFLAGS="$CFLAGS -I$BREW_PREFIX/include -L$BREW_PREFIX/lib" + echo "CFLAGS=$CFLAGS" >> $GITHUB_ENV + shell: bash + - name: Install Linux dependencies + if: runner.os == 'Linux' + run: |- + set -e + sudo apt-get update + sudo apt-get install -y --no-install-recommends \ + libaugeas-dev \ + nginx-light + sudo systemctl stop nginx + sudo sysctl net.ipv4.ip_unprivileged_port_start=0 + shell: bash + - uses: actions/setup-python@v6.2.0 + with: + python-version: "${{ inputs.PYTHON_VERSION }}" + - name: Install runtime dependencies + run: |- + set -e + python3 tools/pip_install.py tox + shell: bash + - name: Create test farm pem file + if: contains(inputs.TOXENV, 'test-farm') + env: + PEM_CONTENTS: "${{ inputs.AWS_TEST_FARM_PEM }}" + run: |- + set -e + echo "${PEM_CONTENTS}" >> $AWS_EC2_PEM_FILE + shell: bash + - name: Run tox + env: + AWS_ACCESS_KEY_ID: "${{ inputs.AWS_ACCESS_KEY_ID }}" + AWS_SECRET_ACCESS_KEY: "${{ inputs.AWS_SECRET_ACCESS_KEY }}" + PIP_USE_PEP517: "${{ inputs.PIP_USE_PEP517 }}" + TOXENV: "${{ inputs.TOXENV }}" + run: |- + set -e + export TARGET_BRANCH="`echo "${BUILD_SOURCEBRANCH}" | sed -E 's!refs/(heads|tags)/!!g'`" + [ -z "${SYSTEM_PULLREQUEST_TARGETBRANCH}" ] || export TARGET_BRANCH="${SYSTEM_PULLREQUEST_TARGETBRANCH}" + env + python3 -m tox run + shell: bash + - name: Upload coverage data + if: env.uploadCoverage == true && (startsWith(matrix.TOXENV, 'cover') || startsWith(matrix.TOXENV, 'integration')) + run: |- + python3 tools/pip_install.py -I coverage + case "${{ runner.os }}" in + Darwin) + CODECOV_URL="https://uploader.codecov.io/latest/macos/codecov" + ;; + Linux) + CODECOV_URL="https://uploader.codecov.io/latest/linux/codecov" + ;; + Windows_NT) + CODECOV_URL="https://uploader.codecov.io/latest/windows/codecov.exe" + ;; + *) + echo "Unexpected OS" + exit 0 + esac + curl --retry 3 -o codecov "$CODECOV_URL" + chmod +x codecov + coverage xml + ./codecov || echo "Uploading coverage data failed" + shell: bash From dd436786b0ab676c7f98c9d80b3c483102c71e12 Mon Sep 17 00:00:00 2001 From: Erica Portnoy Date: Fri, 17 Apr 2026 14:40:54 -0700 Subject: [PATCH 4/5] add standard tests jobs; compare to .azure-pipelines/templates/jobs/standard-tests-jobs.yml which is still needed for other pipelines on azure --- .github/workflows/standard_tests_jobs.yml | 49 +++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/workflows/standard_tests_jobs.yml diff --git a/.github/workflows/standard_tests_jobs.yml b/.github/workflows/standard_tests_jobs.yml new file mode 100644 index 000000000..c2238d0cd --- /dev/null +++ b/.github/workflows/standard_tests_jobs.yml @@ -0,0 +1,49 @@ +# Environment variables defined in a calling workflow are not accessible to this reusable workflow. Refer to the documentation for further details on this limitation. +name: Standard tests jobs +on: + workflow_call: + inputs: + uploadCoverage: + description: 'Upload coverage to Codecov' + type: boolean + default: false +permissions: + contents: read + +jobs: + test: + strategy: + fail-fast: false + matrix: + PYTHON_VERSION: ['3.14'] + IMAGE_NAME: ['ubuntu-22.04'] + TOXENV: + - 'cover' + - 'lint-posix' + - 'mypy' + - 'integration' + - 'apache_compat' + - 'apacheconftest-with-pebble' + - 'nginxroundtrip' + - 'validate-changelog' + include: + - IMAGE_NAME: macOS-15 + PYTHON_VERSION: '3.14' + TOXENV: cover + PIP_USE_PEP517: 'true' + - IMAGE_NAME: ubuntu-22.04 + PYTHON_VERSION: '3.10' + TOXENV: oldest + - IMAGE_NAME: ubuntu-22.04 + PYTHON_VERSION: '3.10' + TOXENV: py310 + uses: "./.github/workflows/tox_steps.yml" + with: + PYTHON_VERSION: "${{ matrix.PYTHON_VERSION }}" + PIP_USE_PEP517: "${{ matrix.PIP_USE_PEP517 }}" + TOXENV: "${{ matrix.TOXENV }}" + uploadCoverage: "${{ inputs.uploadCoverage }}" + IMAGE_NAME: "${{ matrix.IMAGE_NAME }}" + test_name: "test" + test_sphinx_builds: + uses: "./.github/workflows/sphinx_steps.yml" From 3c8b6dbbcb9177a07c886282cf44fb4110fd316c Mon Sep 17 00:00:00 2001 From: Erica Portnoy Date: Fri, 17 Apr 2026 14:41:34 -0700 Subject: [PATCH 5/5] convert .azure-pipelines/main.yml to .github/workflows/pr-test-suite.yml to run PR test suite --- .azure-pipelines/main.yml | 18 ----------------- .github/workflows/pr-test-suite.yml | 31 +++++++++++++++++++++++++++++ 2 files changed, 31 insertions(+), 18 deletions(-) delete mode 100644 .azure-pipelines/main.yml create mode 100644 .github/workflows/pr-test-suite.yml diff --git a/.azure-pipelines/main.yml b/.azure-pipelines/main.yml deleted file mode 100644 index 315b0d47f..000000000 --- a/.azure-pipelines/main.yml +++ /dev/null @@ -1,18 +0,0 @@ -# We run the test suite on commits to main so codecov gets coverage data -# about the main branch and can use it to track coverage changes. -trigger: - - main -pr: - - main - - '*.x' - -variables: - # We set this here to avoid coverage data being uploaded from things like our - # nightly pipeline. This is done because codecov (helpfully) keeps track of - # the number of coverage uploads for a commit and displays a warning when - # comparing two commits with an unequal number of uploads. Only uploading - # coverage here should keep the number of uploads it sees consistent. - uploadCoverage: true - -jobs: - - template: templates/jobs/standard-tests-jobs.yml diff --git a/.github/workflows/pr-test-suite.yml b/.github/workflows/pr-test-suite.yml new file mode 100644 index 000000000..e3808f757 --- /dev/null +++ b/.github/workflows/pr-test-suite.yml @@ -0,0 +1,31 @@ +# We run the test suite on commits to main so codecov gets coverage data +# about the main branch and can use it to track coverage changes. +name: PR test suite +on: + push: + branches: + - main + pull_request: + branches: + - main + - "*.x" + workflow_dispatch: +permissions: + contents: read +concurrency: + # https://stackoverflow.com/questions/74117321/if-condition-in-concurrency-in-gha + group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }} + cancel-in-progress: true + +jobs: + standard_tests_jobs: + name: standard_tests_jobs + uses: "./.github/workflows/standard_tests_jobs.yml" + + with: + # We set this here to avoid coverage data being uploaded from things like our + # nightly pipeline. This is done because codecov (helpfully) keeps track of + # the number of coverage uploads for a commit and displays a warning when + # comparing two commits with an unequal number of uploads. Only uploading + # coverage here should keep the number of uploads it sees consistent. + uploadCoverage: true