fix: route realtime, inference and errors through the gateway; wave-sdk 2.3.0 #67
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ga evidence | |
| # Producer for the WAVE GA readiness gate — VER-001 and SUPPLY-001 — computed against what the | |
| # PUBLIC PyPI registry and GitHub actually serve, never the checkout under test. See | |
| # scripts/ga/ga_evidence.py for what each criterion verifies and what it leaves `unknown`. | |
| # | |
| # wave-av/sdks is the only other repo in the WAVE org that ships a GA-evidence producer today | |
| # (its `registry clean-room acceptance` workflow). This mirrors that repo's fail-loud posture: | |
| # every trigger reports its true state, no `|| true`, no continue-on-error, and the final | |
| # Enforce step turns a non-zero producer exit into a red job. | |
| # | |
| # `pull_request` legitimately sees VER-001 as `unknown` on a release PR whose tag/version is | |
| # ahead of what PyPI has published — the producer reports that as `unknown`, not `fail`; see the | |
| # HEAD-ahead-of-published branch in scripts/ga/check_ver_001.py. | |
| # | |
| # PR CONTRACT: on `pull_request`, exit 1 (a live criterion failed) is a `::warning`, not a job | |
| # failure — that is a property of the live registry, not of the PR's diff. Exit 2 (the producer | |
| # could not run) always fails the job, and on schedule/workflow_dispatch/push exit 1 fails it too. | |
| on: | |
| pull_request: | |
| workflow_dispatch: | |
| inputs: | |
| expect_version: | |
| description: 'Assert PyPI now serves exactly this version (e.g. a release job verifying its own publish)' | |
| type: string | |
| required: false | |
| schedule: | |
| # 09:43 UTC — offset from a round hour so a registry rate-limit window shared across the org's | |
| # scheduled jobs does not land on this one every day. | |
| - cron: "43 9 * * *" | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| ga-evidence: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Run GA evidence producer against the public registries | |
| id: evidence | |
| env: | |
| GA_EXPECT_VERSION: ${{ inputs.expect_version }} | |
| # Read-only, job-scoped default token — raises the GitHub REST API's | |
| # unauthenticated 60/hour-per-IP cap (shared across CI runners' NAT'd | |
| # pools, and easy to exhaust) to 1000/hour. No new secret: this is | |
| # `github.token`, already governed by the `permissions:` block above | |
| # (contents: read), expires with the job, and is never logged. | |
| # scripts/ga/ga_common.py attaches it ONLY to api.github.com requests. | |
| GITHUB_TOKEN: ${{ github.token }} | |
| run: | | |
| set -uo pipefail | |
| args=(--out-dir "$GITHUB_WORKSPACE/ga-out") | |
| [ -n "${GA_EXPECT_VERSION:-}" ] && args+=(--expect-version "$GA_EXPECT_VERSION") | |
| set +e | |
| python3 scripts/ga/ga_evidence.py "${args[@]}" 2>&1 | tee "$RUNNER_TEMP/ga-evidence.log" | |
| code=${PIPESTATUS[0]} | |
| set -e | |
| echo "exit_code=$code" >> "$GITHUB_OUTPUT" | |
| { | |
| echo "## GA evidence — VER-001 / SUPPLY-001" | |
| echo | |
| echo "Exit code \`$code\` (0 = pass/unknown, 1 = a criterion failed, 2 = the producer could not run)." | |
| echo | |
| echo '```' | |
| cat "$RUNNER_TEMP/ga-evidence.log" | |
| echo '```' | |
| } >> "$GITHUB_STEP_SUMMARY" | |
| exit 0 | |
| - name: Upload GA evidence | |
| if: always() | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: ga-evidence-sdk-python | |
| path: ga-out/ | |
| if-no-files-found: warn | |
| retention-days: 90 | |
| - name: Enforce | |
| # A gate that cannot fail is not a gate (wave-av/sdks#79 is the org's own cautionary | |
| # tale — see registry-cleanroom.yml). This step fails loud on every trigger except one: | |
| # see the PR CONTRACT note in the header — a live-criterion failure (exit 1) on | |
| # `pull_request` logs a `::warning` and exits 0 instead of failing the job, because that | |
| # failure is a property of the live registry, not of this PR's diff. Whether the job is a | |
| # *required* branch-protection check is a separate branch-ruleset decision. | |
| env: | |
| CODE: ${{ steps.evidence.outputs.exit_code }} | |
| EVENT: ${{ github.event_name }} | |
| run: | | |
| if [ "$CODE" = "0" ]; then | |
| echo "ga-evidence: no criterion failed (pass or unknown only) — see the job summary for detail" | |
| exit 0 | |
| fi | |
| if [ "$CODE" = "1" ] && [ "$EVENT" = "pull_request" ]; then | |
| echo "::warning title=ga-evidence::sdk-python GA evidence producer reports a failing live criterion (exit 1); evidence is in the job summary and artifact; this does not fail the PR because the criterion is a property of the live surface, not of this change" | |
| exit 0 | |
| fi | |
| if [ "$CODE" = "1" ]; then | |
| echo "::error title=ga-evidence::a GA criterion failed verification (exit 1) — see the job summary" | |
| exit 1 | |
| fi | |
| echo "::error title=ga-evidence::the producer could not run (exit $CODE) — never read as a pass" | |
| exit 1 |