From f453a807e7fb2542557c7c8d7362adce439ec986 Mon Sep 17 00:00:00 2001 From: Jeremy White Date: Thu, 6 Jul 2023 09:41:42 -0400 Subject: [PATCH 1/2] ref(gha/runs-on): restrict to org runner --- .github/workflows/feature-branch.yml | 1 + .github/workflows/main-branch.yaml | 1 + .github/workflows/release.yaml | 1 + 3 files changed, 3 insertions(+) diff --git a/.github/workflows/feature-branch.yml b/.github/workflows/feature-branch.yml index 32faedb..f927ef7 100644 --- a/.github/workflows/feature-branch.yml +++ b/.github/workflows/feature-branch.yml @@ -12,6 +12,7 @@ permissions: jobs: do: + runs-on: [self-hosted, amd64-public] uses: cloudposse/github-actions-workflows-docker-ecr-eks-helmfile/.github/workflows/feature-branch.yml@main with: organization: "${{ github.event.repository.owner.login }}" diff --git a/.github/workflows/main-branch.yaml b/.github/workflows/main-branch.yaml index f5fc96a..f4bd877 100644 --- a/.github/workflows/main-branch.yaml +++ b/.github/workflows/main-branch.yaml @@ -9,6 +9,7 @@ permissions: jobs: do: + runs-on: [self-hosted, amd64-public] uses: cloudposse/github-actions-workflows-docker-ecr-eks-helmfile/.github/workflows/main-branch.yml@main with: organization: "${{ github.event.repository.owner.login }}" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index b99e94e..985933c 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -9,6 +9,7 @@ permissions: jobs: perform: + runs-on: [self-hosted, amd64-public] uses: cloudposse/github-actions-workflows-docker-ecr-eks-helmfile/.github/workflows/release.yml@main with: organization: "${{ github.event.repository.owner.login }}" From 260195a05720df3534fcca263e4ae8b51b5d7d65 Mon Sep 17 00:00:00 2001 From: Jeremy White Date: Thu, 6 Jul 2023 09:44:50 -0400 Subject: [PATCH 2/2] ref(gha/feature-branch): reformat for runs-on --- .github/workflows/feature-branch.yml | 27 ++++++++++++++------------- 1 file changed, 14 insertions(+), 13 deletions(-) diff --git a/.github/workflows/feature-branch.yml b/.github/workflows/feature-branch.yml index f927ef7..18f5bff 100644 --- a/.github/workflows/feature-branch.yml +++ b/.github/workflows/feature-branch.yml @@ -13,16 +13,17 @@ permissions: jobs: do: runs-on: [self-hosted, amd64-public] - uses: cloudposse/github-actions-workflows-docker-ecr-eks-helmfile/.github/workflows/feature-branch.yml@main - with: - organization: "${{ github.event.repository.owner.login }}" - repository: "${{ github.event.repository.name }}" - open: ${{ github.event.pull_request.state == 'open' }} - labels: ${{ toJSON(github.event.pull_request.labels.*.name) }} - ref: ${{ github.event.pull_request.head.ref }} - secrets: - github-private-actions-pat: "${{ secrets.PUBLIC_AND_PRIVATE_REPO_ACCESS_TOKEN }}" - registry: "${{ secrets.ECR_REGISTRY }}" - secret-outputs-passphrase: "${{ secrets.GHA_SECRET_OUTPUT_PASSPHRASE }}" - ecr-region: "${{ secrets.ECR_REGION }}" - ecr-iam-role: "${{ secrets.ECR_IAM_ROLE }}" + steps: + - uses: cloudposse/github-actions-workflows-docker-ecr-eks-helmfile/.github/workflows/feature-branch.yml@main + with: + organization: "${{ github.event.repository.owner.login }}" + repository: "${{ github.event.repository.name }}" + open: ${{ github.event.pull_request.state == 'open' }} + labels: ${{ toJSON(github.event.pull_request.labels.*.name) }} + ref: ${{ github.event.pull_request.head.ref }} + secrets: + github-private-actions-pat: "${{ secrets.PUBLIC_AND_PRIVATE_REPO_ACCESS_TOKEN }}" + registry: "${{ secrets.ECR_REGISTRY }}" + secret-outputs-passphrase: "${{ secrets.GHA_SECRET_OUTPUT_PASSPHRASE }}" + ecr-region: "${{ secrets.ECR_REGION }}" + ecr-iam-role: "${{ secrets.ECR_IAM_ROLE }}"