Skip to content

refactor(ci): consolidate validation into four check buckets - #1072

Merged
iamgp merged 1 commit into
mainfrom
refactor/ci-check-buckets
Oct 7, 2026
Merged

iamgp merged 1 commit into
mainfrom
refactor/ci-check-buckets

Conversation

@iamgp

@iamgp iamgp commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Change

Organise merge validation into quality/contracts, behaviour, integration/portability, and artifact/dependency safety. The expanded full graph drops from 39 jobs to 24 without dropping suites or weakening required gates.

  • Share checkout/setup for file hooks and Python quality; Observatory, writer and plugin; Linux service contracts; and native Windows contracts.
  • Run container waiver, Dockerfile and generated Compose checks in one job instead of tiny jobs and a lint matrix.
  • Build provider wheels once and reuse them for Windows. Collect combined coverage in pr / required instead of a separate runner.
  • Retain affected selection, Python/provider shards, fail-closed aggregation, exact-SHA main reuse, scheduled scans and approved release publication.
  • Update support-manifest evidence references to the workflows that own the moved checks.

Verification

  • make setup, make check and make docs-build passed on the committed tree.
  • 265 focused workflow/evidence/selector tests passed, including executable negative cases for combined Node selection and container lint failure propagation. Final Windows reuse assertions also passed.
  • actionlint, zizmor and committed suppression inventory passed.
  • GitHub run https://github.com/phlohouse/phlo/actions/runs/37611270604 completed successfully: all 24 validation jobs passed. The PR has 25 passing checks including its external review, with no failed or pending checks.
  • Actual moved storage, PostgreSQL, quickstart, recovery, Node and Windows steps succeeded. Downloaded JUnit evidence confirms PostgreSQL 3 tests, quickstart 1 and plugin 6, all without skips or failures. Combined coverage was produced successfully.

Timing limits

Recent file hooks took 16 seconds after a 191-second full-history checkout that Python quality repeated. Consolidation removes that duplicate setup. One full-queue baseline used 39 jobs, 68.8 minutes of summed job time and 10m25s elapsed; this all-lanes PR used 24 jobs, 64.7 minutes of summed job time and 12m05s elapsed. These are individual runs, not a controlled benchmark. This PR proves fewer jobs and preserved checks, not a wall-time gain. The current critical path includes a 5m06s checkout in an unchanged core shard.

No repository settings, required check identity, deployments or release permissions changed. Native platforms, service environments and slower shards remain separate; four buckets do not mean four literal jobs. Not merged.

@coldtea-pr-lens

coldtea-pr-lens Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Nothing flagged · reviewed d432520


Architecture

Architecture diagram for phlohouse/phlo at d432520

Play the walkthrough


Inside the changed components — 3 views

Component view — Integration and Service Contracts

Consolidation of storage behavioral suites, PostgreSQL lock contention gates, quickstart smoke, and recovery drills into a single Linux runner.

Architecture view of Component view — Integration and Service Contracts in phlohouse/phlo

Component view — Quality and Behaviour Check Buckets

Consolidation of file hooks, linting, zizmor audit, type checks, and JavaScript/TypeScript test runners into unified jobs.

Architecture view of Component view — Quality and Behaviour Check Buckets in phlohouse/phlo

Component view — Artifact Safety and Coverage Collection

Single-pass wheel compilation, unified container security checks, and combined coverage aggregation in the final PR gate.

Architecture view of Component view — Artifact Safety and Coverage Collection in phlohouse/phlo

Data flow

Data flow diagram for phlohouse/phlo at d432520

Follow each request


The other flows — 1 sequence

Shared-Runner Integration and Recovery Execution

Sequence diagram of Shared-Runner Integration and Recovery Execution in phlohouse/phlo

View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change
  • Open a diagram on the canvas, then press W or click play to walk through the change one step at a time
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs as before
  • Set github.draw: on-demand in .github/pr-lens.yml and PR Lens stops drawing pull requests on its own. Comment @pr-lens draw on a pull request when you want that one drawn
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works
  • Push a commit and the drawing stays, with a note that it is out of date. Tick Redraw in the note to draw the new head
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@phlo-agent

phlo-agent Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Reviewed the full diff at d432520fca58ac5167ca6a12d08f712d4ff3ab17 and the live check runs for that SHA. No actionable correctness, security, compatibility, or maintainability defects found.

Surfaces checked

  • Aggregation logic. ci / status and pr / required are internally consistent with the workflows they gate: python-quality is now unconditional and asserted success; installed-provider-artifacts/python-core-tests/windows-portability are asserted against expected_python; python-package-tests against expected_groups; the merged behaviour / JavaScript job's if (frontend‖writer‖plugin) matches the expected_node derivation. Every job the aggregates need is asserted, and the moved lanes (postgres/quickstart/recovery → integration.yml; release contract → windows-compose-portability.yml; coverage → pr / required; writer/plugin → ci.yml) stay required.
  • Artifact wiring. The provider-wheelhouse artifact is produced by ci-config under the same python gate that guards its two consumers (installed-provider-artifacts, windows-portability via reuse-wheelhouse: true); coverage inputs (core-tests-*, package-results-*, quickstart-smoke) are all produced when python is selected. python == true implies a non-empty package group in scripts/select_ci.py, so the groups[0] != null guard on the package download cannot skip a needed artifact.
  • Evidence/manifest references. registry/support/v1.json, src/phlo/support_data/v1.json, and scripts/validate_support_manifest.py were updated together to point recovery evidence at integration.yml and golden-path evidence at windows-compose-portability.yml, both of which contain the referenced commands.
  • Test coverage. The renamed/removed job identities are reflected in the updated tests/scripts and tests/tooling suites, and the new conditional paths (combined Node gate, multi-file container lint, shared integration setup) have executable failure-case tests.
  • Live CI. Observed check runs for this SHA are green, including ci / ci / status, ci / quality / source and file contracts (zizmor + file hooks), containers / safety / container contracts, integration / integration / required suites, ci / behaviour / JavaScript, and ci / windows / compose portability / ….

Validation that remains

  • The PR run is a pull_request run, so the merge-queue-only path (scripts/ci_evidence.py emit / reuse, pr / required job needs + fail-closed aggregation) is not exercised here; it should be confirmed on the first queue run. At inspection time pr / required was still finishing its coverage-combine step; all other lanes had completed.
  • Native Windows acceptance and the scheduled scans still need a real queue/scheduled run; an x64 review cannot prove them.

@iamgp
iamgp added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit daf7e74 Oct 7, 2026
25 checks passed
@iamgp
iamgp deleted the refactor/ci-check-buckets branch October 7, 2026 14:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant