Skip to content
1,348 linesCodeBlameRaw
1//! The actions service: GitHub Actions workflows, run on g1t as they are.
2//!
3//! A repository's `.g1t/workflows/*.yml`, in GitHub's format, are read
4//! from the commit an
5//! event is about (the default branch for issues, schedules and manual
6//! runs). Each workflow an event starts becomes a run; each job of the run
7//! (one per matrix combination) runs in a sandbox once the jobs it needs
8//! have finished. Jobs report their steps and logs back as they go, and a
9//! run on a pull request's head is a status on that pull request.
10//!
11//! Secrets and variables belong to a repository or to its workspace; a
12//! repository's override its workspace's of the same name. Secret values
13//! are sealed at rest and never returned.
14//!
15//! Mirrors `packages/contracts/src/actions.ts`.
16
17use serde::{Deserialize, Serialize};
18use serde_json::Value;
19
20use crate::repos::RepoPath;
21use crate::{User, Viewer};
22
23/// A note on something in a workflow that runs differently on g1t.
24#[derive(Clone, Debug, Serialize, Deserialize)]
25#[serde(rename_all = "camelCase")]
26pub struct WorkflowNote {
27 /// `info`, `warning` or `unsupported`.
28 pub severity: String,
29 pub job: Option<String>,
30 pub message: String,
31}
32
33#[derive(Clone, Debug, Serialize, Deserialize)]
34#[serde(rename_all = "camelCase")]
35pub struct Workflow {
36 pub id: String,
37 /// `.g1t/workflows/ci.yml`.
38 pub path: String,
39 pub name: String,
40 /// The events that start it, such as `push` and `pull_request`.
41 pub events: Vec<String>,
42 /// `active`, or `disabled` when a member turned it off.
43 pub state: String,
44 /// Why the file cannot be used, if it cannot.
45 pub error: Option<String>,
46 pub notes: Vec<WorkflowNote>,
47 /// `on.workflow_dispatch.inputs` as written, when it can be run by hand.
48 pub dispatch: Option<Value>,
49 pub last_run: Option<WorkflowRun>,
50}
51
52#[derive(Clone, Debug, Serialize, Deserialize)]
53#[serde(rename_all = "camelCase")]
54pub struct WorkflowRun {
55 pub id: String,
56 pub workflow_id: String,
57 pub path: String,
58 /// The workflow's name.
59 pub name: String,
60 /// `run-name`, or what started it: a commit's subject, a pull request's title.
61 pub title: String,
62 /// Counts the workflow's runs: 1, 2, 3…
63 pub number: u64,
64 pub attempt: u64,
65 /// The GitHub event: `push`, `pull_request`, `schedule`…
66 pub event: String,
67 #[serde(rename = "ref")]
68 pub git_ref: String,
69 pub sha: String,
70 /// The pull request it ran for, if any.
71 pub pull: Option<u32>,
72 /// `queued`, `in_progress` or `completed`.
73 pub status: String,
74 /// When completed: `success`, `failure`, `cancelled` or `skipped`.
75 pub conclusion: Option<String>,
76 /// Why it could not start, such as a workflow file that does not read.
77 pub error: Option<String>,
78 /// Username of whoever caused it.
79 pub actor: Option<String>,
80 pub created_at: String,
81 pub started_at: Option<String>,
82 pub finished_at: Option<String>,
83}
84
85#[derive(Clone, Debug, Default, Serialize, Deserialize)]
86#[serde(rename_all = "camelCase")]
87pub struct StepState {
88 /// From 1.
89 pub number: u32,
90 pub name: String,
91 /// `queued`, `in_progress` or `completed`.
92 pub status: String,
93 /// `success`, `failure`, `cancelled` or `skipped`.
94 pub conclusion: Option<String>,
95 pub started_at: Option<String>,
96 pub finished_at: Option<String>,
97}
98
99/// A message a step left with `::error::`, `::warning::` or `::notice::`.
100#[derive(Clone, Debug, Default, Serialize, Deserialize)]
101#[serde(rename_all = "camelCase")]
102pub struct Annotation {
103 /// `error`, `warning` or `notice`.
104 pub level: String,
105 pub message: String,
106 pub title: Option<String>,
107 pub file: Option<String>,
108 pub line: Option<u32>,
109}
110
111#[derive(Clone, Debug, Serialize, Deserialize)]
112#[serde(rename_all = "camelCase")]
113pub struct Job {
114 pub id: String,
115 pub run_id: String,
116 /// Its key under `jobs:`.
117 pub key: String,
118 /// With its matrix combination: `test (ubuntu-latest, 20)`.
119 pub name: String,
120 pub needs: Vec<String>,
121 /// `queued`, `waiting` (for the jobs it needs), `in_progress` or `completed`.
122 pub status: String,
123 pub conclusion: Option<String>,
124 pub steps: Vec<StepState>,
125 pub annotations: Vec<Annotation>,
126 /// Why it did not run, what stopped it, or what it waits for.
127 pub reason: Option<String>,
128 pub started_at: Option<String>,
129 pub finished_at: Option<String>,
130 /// The environment it names, once its needs are done (an expression
131 /// read by then). A job held by the environment's protection rules is
132 /// `pending` until they let it through.
133 #[serde(default)]
134 pub environment: Option<String>,
135 /// Its `runs-on` names self-hosted runners (see `runners`).
136 #[serde(default)]
137 pub self_hosted: bool,
138 /// The self-hosted runner that took it, by name.
139 #[serde(default)]
140 pub runner: Option<String>,
141 /// It was cancelled and is running its `if: always()` and `cancelled()`
142 /// steps and its post steps before it ends.
143 #[serde(default)]
144 pub cancelling: bool,
145 /// Where its deployment is (`environment.url`), for a job that deploys
146 /// and says; the current attempt's only.
147 #[serde(default, skip_serializing_if = "Option::is_none")]
148 pub environment_url: Option<String>,
149 /// For a job that calls a reusable workflow: that workflow's file. Its
150 /// jobs' keys start with this job's key and a `/`.
151 #[serde(default, skip_serializing_if = "Option::is_none")]
152 pub uses: Option<String>,
153}
154
155#[derive(Clone, Debug, Serialize, Deserialize)]
156#[serde(rename_all = "camelCase")]
157pub struct RunDetail {
158 pub run: WorkflowRun,
159 pub jobs: Vec<Job>,
160 /// The workflow's notes, as of the run's commit.
161 pub notes: Vec<WorkflowNote>,
162 /// For a run of a pull request from outside: whether it waits for, or
163 /// had, someone's approval (`status` is `action_required` while it waits).
164 #[serde(default)]
165 pub approval: Option<RunApproval>,
166 /// The environments whose protection rules hold its jobs, this attempt.
167 #[serde(default)]
168 pub pending_deployments: Vec<PendingDeployment>,
169 /// Every attempt of the run, oldest first, the one shown included.
170 /// `run.attempt` says which one `jobs` belong to.
171 #[serde(default)]
172 pub attempts: Vec<RunAttempt>,
173}
174
175/// One attempt of a run: the first, or a re-run.
176#[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
177#[serde(rename_all = "camelCase")]
178pub struct RunAttempt {
179 /// From 1.
180 pub attempt: u64,
181 /// `queued`, `in_progress` or `completed`; earlier attempts are completed.
182 pub status: String,
183 pub conclusion: Option<String>,
184 /// Who started it: whoever caused the run for the first, whoever re-ran
185 /// it for the rest.
186 pub actor: Option<String>,
187 /// It ran with debug logging (`RUNNER_DEBUG=1`).
188 pub debug: bool,
189 pub started_at: Option<String>,
190 pub finished_at: Option<String>,
191}
192
193/// One job's summary: what its steps wrote to `$GITHUB_STEP_SUMMARY`, in
194/// Markdown, masked.
195#[derive(Clone, Debug, Serialize, Deserialize)]
196#[serde(rename_all = "camelCase")]
197pub struct JobSummary {
198 /// The job's id, as `RunDetail.jobs` gives it for the attempt.
199 pub job_id: String,
200 pub name: String,
201 pub steps: Vec<StepSummary>,
202}
203
204#[derive(Clone, Debug, Serialize, Deserialize)]
205#[serde(rename_all = "camelCase")]
206pub struct StepSummary {
207 /// The step, from 1 (post steps follow the job's own).
208 pub step: u32,
209 pub markdown: String,
210}
211
212/// A job's whole log, for downloading: its steps, to split the text by.
213#[derive(Clone, Debug, Serialize, Deserialize)]
214#[serde(rename_all = "camelCase")]
215pub struct JobLogText {
216 pub job_id: String,
217 pub name: String,
218 pub steps: Vec<StepState>,
219 pub chunks: Vec<LogChunk>,
220 /// Whether the job has finished.
221 pub done: bool,
222 /// Its log was left out: the run's logs reached `MAX_RUN_LOG_BYTES`.
223 #[serde(default)]
224 pub omitted: bool,
225}
226
227/// A run that needed approval before it started.
228#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
229#[serde(rename_all = "camelCase")]
230pub struct RunApproval {
231 /// `required` while it waits, then `approved`.
232 pub state: String,
233 /// Why it waits, in words.
234 pub reason: String,
235 /// Who approved it.
236 pub approved_by: Option<String>,
237}
238
239/// One person or team who may approve a job's deployment to an
240/// environment.
241#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
242pub struct EnvironmentReviewer {
243 /// `user` or `team`.
244 #[serde(rename = "type")]
245 pub kind: String,
246 /// A username, or a team's slug in the repository's workspace.
247 pub name: String,
248}
249
250/// A branch or tag pattern an environment lets deploy.
251#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
252pub struct BranchPattern {
253 /// fnmatch-style, as branch filters are: `main`, `release/*`, `v*`.
254 pub name: String,
255 /// `branch` or `tag`.
256 #[serde(rename = "type", default = "branch_kind")]
257 pub kind: String,
258}
259
260fn branch_kind() -> String {
261 "branch".to_owned()
262}
263
264/// The most reviewers an environment may have, as on GitHub.
265pub const MAX_ENVIRONMENT_REVIEWERS: usize = 6;
266/// The longest wait timer, in minutes: 30 days.
267pub const MAX_WAIT_MINUTES: u32 = 43_200;
268
269/// An environment and its protection rules. Jobs that name it with
270/// `environment:` wait until the rules let them through; only then does the
271/// job get the environment's secrets.
272#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
273#[serde(rename_all = "camelCase")]
274pub struct Environment {
275 /// Lowercase.
276 pub name: String,
277 /// Who may approve its jobs; none means no review is needed.
278 pub reviewers: Vec<EnvironmentReviewer>,
279 /// Whoever started a run may not approve its jobs, even as a reviewer.
280 pub prevent_self_review: bool,
281 /// Minutes each job waits before it may start.
282 pub wait_minutes: u32,
283 /// Which refs may deploy: `all`, `protected` (branches the rules
284 /// protect, the default branch included) or `selected` (`branch_patterns`).
285 pub branch_policy: String,
286 pub branch_patterns: Vec<BranchPattern>,
287 /// Admins may approve without being reviewers, which also skips the wait.
288 pub admins_bypass: bool,
289 /// Whether it has rules saved; false for one only named by a workflow,
290 /// a secret or a deployment.
291 pub protected: bool,
292 pub updated_at: Option<String>,
293 pub updated_by: Option<String>,
294}
295
296/// An environment holding a run's jobs, and where its rules stand.
297#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
298#[serde(rename_all = "camelCase")]
299pub struct PendingDeployment {
300 pub environment: String,
301 /// `waiting`, `approved` or `rejected`.
302 pub state: String,
303 /// Whether a reviewer must approve it before its jobs start.
304 pub needs_review: bool,
305 /// When its wait timer lets its jobs start, if it has one.
306 pub wait_until: Option<String>,
307 pub reviewers: Vec<EnvironmentReviewer>,
308 /// The jobs it holds, by name.
309 pub jobs: Vec<String>,
310 /// Whether the viewer may approve or reject it now.
311 #[serde(default)]
312 pub can_review: bool,
313 pub reviewed_by: Option<String>,
314 pub comment: Option<String>,
315 pub reviewed_at: Option<String>,
316}
317
318/// A repository's choices for its workflows.
319#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
320#[serde(rename_all = "camelCase")]
321pub struct ActionsSettings {
322 /// What a workflow without `permissions:` gets: `read` (contents and
323 /// packages read) or `write` (every permission). Unchosen, a repository
324 /// made before restricted tokens keeps `write`; a newer one takes its
325 /// workspace's default. Never more than the workspace's maximum.
326 pub default_permissions: String,
327 /// Whether the repository chose it, rather than taking it as above.
328 #[serde(default)]
329 pub default_chosen: bool,
330 /// The most the workspace lets a repository's default be.
331 #[serde(default = "write")]
332 pub max_permissions: String,
333 /// Which pull requests' runs wait for approval: `first_time_contributors`,
334 /// `outside_contributors` (the default) or `all_external_contributors`.
335 pub approval_policy: String,
336 /// Whether a job's token may open pull requests and approve them. Off
337 /// unless the repository turns it on, and only where the workspace
338 /// allows it.
339 #[serde(default)]
340 pub can_approve_pull_requests: bool,
341 /// Whether the workspace lets its repositories turn that on.
342 #[serde(default)]
343 pub workspace_allows_pull_requests: bool,
344 /// Who may use this repository's actions and reusable workflows from
345 /// their workflows, when it is private: `none` (only itself, the
346 /// default) or `organization` (private repositories of its workspace).
347 /// A public repository's are anyone's. See [`ACCESS_LEVELS`].
348 #[serde(default = "no_access")]
349 pub access_level: String,
350}
351
352fn no_access() -> String {
353 "none".to_owned()
354}
355
356/// The values of `access_level`. `user` is read as `organization`: a
357/// personal account's repositories are its own workspace's.
358pub const ACCESS_LEVELS: [&str; 2] = ["none", "organization"];
359
360/// `access_level` as given, as one of [`ACCESS_LEVELS`]; None when it is
361/// not one.
362pub fn access_level(given: &str) -> Option<&'static str> {
363 match given.trim().to_ascii_lowercase().as_str() {
364 "none" | "" => Some("none"),
365 "organization" | "user" | "workspace" => Some("organization"),
366 _ => None,
367 }
368}
369
370fn write() -> String {
371 "write".to_owned()
372}
373
374/// A workspace's policy for its repositories' tokens.
375#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
376#[serde(rename_all = "camelCase")]
377pub struct WorkspaceActionsSettings {
378 /// What a repository made from now on gets by default: `read` (the
379 /// default) or `write`.
380 pub default_permissions: String,
381 /// The most any repository's default may be: `write` (the default) or
382 /// `read`, which holds every repository to read-only.
383 pub max_permissions: String,
384 /// Whether its repositories may let jobs open and approve pull
385 /// requests. Off by default.
386 pub can_approve_pull_requests: bool,
387}
388
389/// `workspace_actions_settings`: members only. Returns
390/// `Outcome<WorkspaceActionsSettings>`.
391#[derive(Debug, Serialize, Deserialize)]
392pub struct WorkspaceActionsSettingsArgs {
393 pub viewer: Viewer,
394 pub workspace: String,
395}
396
397/// `set_workspace_actions_settings`: owners only. Fields left out stay as
398/// they are. Returns `Outcome<WorkspaceActionsSettings>`.
399#[derive(Debug, Serialize, Deserialize)]
400#[serde(rename_all = "camelCase")]
401pub struct SetWorkspaceActionsSettingsArgs {
402 pub actor: User,
403 pub workspace: String,
404 #[serde(default)]
405 pub default_permissions: Option<String>,
406 #[serde(default)]
407 pub max_permissions: Option<String>,
408 #[serde(default)]
409 pub can_approve_pull_requests: Option<bool>,
410}
411
412/// The approval policies, least strict first.
413pub const APPROVAL_POLICIES: [&str; 3] = ["first_time_contributors", "outside_contributors", "all_external_contributors"];
414
415/// `actions_settings`. Returns `Outcome<ActionsSettings>`; anyone who can
416/// read the repository may see them.
417#[derive(Debug, Serialize, Deserialize)]
418pub struct ActionsSettingsArgs {
419 pub viewer: Viewer,
420 pub repo: RepoPath,
421}
422
423/// `set_actions_settings`: Admins only. Fields left out stay as they are.
424/// Returns `Outcome<ActionsSettings>`.
425#[derive(Debug, Serialize, Deserialize)]
426#[serde(rename_all = "camelCase")]
427pub struct SetActionsSettingsArgs {
428 pub actor: User,
429 pub repo: RepoPath,
430 /// `read` or `write`; `inherit` goes back to the workspace's (or, for a
431 /// repository made before restricted tokens, `write`).
432 #[serde(default)]
433 pub default_permissions: Option<String>,
434 #[serde(default)]
435 pub approval_policy: Option<String>,
436 #[serde(default)]
437 pub can_approve_pull_requests: Option<bool>,
438 /// `none`, or `organization` (`user` reads the same). See
439 /// [`ActionsSettings::access_level`].
440 #[serde(default)]
441 pub access_level: Option<String>,
442}
443
444/// `environments`: every environment a repository's workflows, secrets,
445/// deployments or rules name, with its rules. `environment`: one, by
446/// `name`. Returns `Outcome<Vec<Environment>>` and `Outcome<Environment>`.
447#[derive(Debug, Serialize, Deserialize)]
448pub struct EnvironmentsArgs {
449 pub viewer: Viewer,
450 pub repo: RepoPath,
451 #[serde(default)]
452 pub name: Option<String>,
453}
454
455/// `set_environment`: create an environment's rules or change them. Fields
456/// left out stay as they are (none, for a new one). Admins only. Returns
457/// `Outcome<Environment>`.
458#[derive(Debug, Serialize, Deserialize)]
459#[serde(rename_all = "camelCase")]
460pub struct SetEnvironmentArgs {
461 pub actor: User,
462 pub repo: RepoPath,
463 pub name: String,
464 #[serde(default)]
465 pub reviewers: Option<Vec<EnvironmentReviewer>>,
466 #[serde(default)]
467 pub prevent_self_review: Option<bool>,
468 #[serde(default)]
469 pub wait_minutes: Option<u32>,
470 #[serde(default)]
471 pub branch_policy: Option<String>,
472 #[serde(default)]
473 pub branch_patterns: Option<Vec<BranchPattern>>,
474 #[serde(default)]
475 pub admins_bypass: Option<bool>,
476}
477
478/// `delete_environment`: its rules go; jobs naming it run without them.
479/// Its secrets' rows stay. Admins only. Returns `Outcome<bool>`.
480#[derive(Debug, Serialize, Deserialize)]
481pub struct DeleteEnvironmentArgs {
482 pub actor: User,
483 pub repo: RepoPath,
484 pub name: String,
485}
486
487/// `pending_deployments`: the environments holding a run's jobs. Returns
488/// `Outcome<Vec<PendingDeployment>>`.
489#[derive(Debug, Serialize, Deserialize)]
490pub struct PendingDeploymentsArgs {
491 pub viewer: Viewer,
492 pub repo: RepoPath,
493 pub id: String,
494}
495
496/// `review_deployments`: approve or reject a run's jobs for `environments`
497/// (every one waiting, if empty). Returns `Outcome<Vec<PendingDeployment>>`.
498#[derive(Debug, Serialize, Deserialize)]
499pub struct ReviewDeploymentsArgs {
500 pub actor: User,
501 pub repo: RepoPath,
502 pub id: String,
503 #[serde(default)]
504 pub environments: Vec<String>,
505 /// `approved` or `rejected`.
506 pub state: String,
507 #[serde(default)]
508 pub comment: Option<String>,
509}
510
511/// `repository_dispatch`: start the default branch's workflows that run
512/// `on: repository_dispatch` for `event_type`. Needs the Write role (a
513/// token's `code:write`). Returns `Outcome<u32>`: how many started.
514#[derive(Debug, Serialize, Deserialize)]
515#[serde(rename_all = "camelCase")]
516pub struct RepositoryDispatchArgs {
517 pub actor: User,
518 pub repo: RepoPath,
519 pub event_type: String,
520 #[serde(default)]
521 pub client_payload: Value,
522}
523
524#[derive(Clone, Debug, Serialize, Deserialize)]
525#[serde(rename_all = "camelCase")]
526pub struct LogChunk {
527 pub seq: u64,
528 /// The step it belongs to, from 1; 0 for the job's setup.
529 pub step: u32,
530 pub text: String,
531}
532
533#[derive(Clone, Debug, Serialize, Deserialize)]
534#[serde(rename_all = "camelCase")]
535pub struct JobLog {
536 pub chunks: Vec<LogChunk>,
537 /// Whether the job has finished, so no more will come.
538 pub done: bool,
539}
540
541/// Who may read a secret or variable: workflows (`secrets.*` and `vars.*`
542/// in GitHub Actions) and deployments (a deploy build's environment and the
543/// running app's bindings). Agents, checks and the merge queue read none.
544pub const CONSUMERS: [&str; 2] = ["workflows", "deployments"];
545
546/// One row of a repository's or workspace's secrets and variables, as
547/// Vercel lists environment variables: a key, its type, the environments
548/// it applies to and who reads it. A key may have one row per environment.
549/// Secrets' values are never returned.
550#[derive(Clone, Debug, Serialize, Deserialize)]
551#[serde(rename_all = "camelCase")]
552pub struct Setting {
553 #[serde(default)]
554 pub id: String,
555 pub name: String,
556 /// `secret`, or `variable` (shown as Config).
557 #[serde(default)]
558 pub kind: String,
559 /// A variable's value; secrets' are never returned.
560 pub value: Option<String>,
561 /// `project` (a repository's, which belong to its project) or
562 /// `workspace`.
563 pub scope: String,
564 pub updated_at: String,
565 /// `workflows` and/or `deployments`.
566 #[serde(default)]
567 pub available_to: Vec<String>,
568 /// The environments it applies to; empty is every environment.
569 #[serde(default)]
570 pub environments: Vec<String>,
571 /// A workspace's row: the projects it reaches, by slug; empty is every
572 /// project.
573 #[serde(default)]
574 pub projects: Vec<String>,
575 #[serde(default)]
576 pub note: Option<String>,
577 #[serde(default)]
578 pub updated_by: Option<String>,
579}
580
581// --- Methods ---------------------------------------------------------------
582
583/// `workflows`. Returns `Outcome<Vec<Workflow>>`.
584#[derive(Debug, Serialize, Deserialize)]
585pub struct WorkflowsArgs {
586 pub repo: RepoPath,
587 pub viewer: Viewer,
588}
589
590/// `runs`: newest first. Returns `Outcome<Vec<WorkflowRun>>`.
591#[derive(Debug, Serialize, Deserialize)]
592pub struct RunsArgs {
593 pub repo: RepoPath,
594 pub viewer: Viewer,
595 /// A workflow's id or file name.
596 #[serde(default)]
597 pub workflow: Option<String>,
598 #[serde(default)]
599 pub branch: Option<String>,
600 #[serde(default)]
601 pub event: Option<String>,
602 /// The pull request's number.
603 #[serde(default)]
604 pub pull: Option<u32>,
605 #[serde(default)]
606 pub sha: Option<String>,
607 #[serde(default)]
608 pub limit: Option<u32>,
609}
610
611/// `run`. Returns `Outcome<RunDetail>`.
612#[derive(Debug, Serialize, Deserialize)]
613pub struct RunArgs {
614 pub repo: RepoPath,
615 pub viewer: Viewer,
616 pub id: String,
617 /// An earlier attempt; the latest when absent.
618 #[serde(default)]
619 pub attempt: Option<u64>,
620}
621
622/// `summaries`: the job summaries of a run's attempt (the latest when
623/// `attempt` is absent), jobs in the run's order, those with none left
624/// out. Returns `Outcome<Vec<JobSummary>>`.
625#[derive(Debug, Serialize, Deserialize)]
626pub struct SummariesArgs {
627 pub repo: RepoPath,
628 pub viewer: Viewer,
629 pub id: String,
630 #[serde(default)]
631 pub attempt: Option<u64>,
632}
633
634/// `job_log_text`: one job's whole log, any attempt's (by the id the run
635/// gave the job). Returns `Outcome<JobLogText>`.
636#[derive(Debug, Serialize, Deserialize)]
637pub struct JobLogTextArgs {
638 pub repo: RepoPath,
639 pub viewer: Viewer,
640 pub job: String,
641}
642
643/// `run_logs`: every job's whole log for an attempt of a run (the latest
644/// when `attempt` is absent), until they add up to `MAX_RUN_LOG_BYTES`;
645/// jobs past it come `omitted`, with no chunks. Returns
646/// `Outcome<Vec<JobLogText>>`.
647#[derive(Debug, Serialize, Deserialize)]
648pub struct RunLogsArgs {
649 pub repo: RepoPath,
650 pub viewer: Viewer,
651 pub id: String,
652 #[serde(default)]
653 pub attempt: Option<u64>,
654}
655
656/// The most log `run_logs` returns at once, in bytes.
657pub const MAX_RUN_LOG_BYTES: usize = 24 * 1024 * 1024;
658
659/// `logs`: a job's log after `after`. Returns `Outcome<JobLog>`.
660#[derive(Debug, Serialize, Deserialize)]
661pub struct LogsArgs {
662 pub repo: RepoPath,
663 pub viewer: Viewer,
664 pub job: String,
665 #[serde(default)]
666 pub after: u64,
667}
668
669/// `dispatch`: run a workflow that has `workflow_dispatch`. Members only.
670/// Returns `Outcome<WorkflowRun>`.
671#[derive(Debug, Serialize, Deserialize)]
672pub struct DispatchArgs {
673 pub actor: User,
674 pub repo: RepoPath,
675 /// A workflow's id or file name.
676 pub workflow: String,
677 /// A branch or tag; the default branch when absent.
678 #[serde(default, rename = "ref")]
679 pub git_ref: Option<String>,
680 #[serde(default)]
681 pub inputs: serde_json::Map<String, Value>,
682}
683
684/// `cancel` and `rerun`: every job, with `failed_only` the ones that did
685/// not succeed, or with `job` that one job (by its id in the run's latest
686/// attempt); each with the jobs that need them. `debug` runs the new
687/// attempt with debug logging. Members only. Returns `Outcome<WorkflowRun>`.
688#[derive(Debug, Serialize, Deserialize)]
689pub struct RunActionArgs {
690 pub actor: User,
691 pub repo: RepoPath,
692 pub id: String,
693 #[serde(default)]
694 pub failed_only: bool,
695 #[serde(default)]
696 pub job: Option<String>,
697 #[serde(default)]
698 pub debug: bool,
699 /// `cancel`: stop running jobs outright, without their cleanup steps.
700 #[serde(default)]
701 pub force: bool,
702}
703
704/// `set_workflow_enabled`. Members only. Returns `Outcome<Workflow>`.
705#[derive(Debug, Serialize, Deserialize)]
706pub struct SetWorkflowEnabledArgs {
707 pub actor: User,
708 pub repo: RepoPath,
709 pub workflow: String,
710 pub enabled: bool,
711}
712
713/// Whose secrets or variables: a repository's, or with only `workspace`,
714/// a workspace's.
715#[derive(Clone, Debug, Serialize, Deserialize)]
716pub struct SettingsOwner {
717 #[serde(default)]
718 pub repo: Option<RepoPath>,
719 #[serde(default)]
720 pub workspace: Option<String>,
721}
722
723/// `settings`: the secrets (`kind: secret`) or variables (`kind: variable`)
724/// of a repository, with its workspace's, or of a workspace. Members only.
725/// Returns `Outcome<Vec<Setting>>`.
726#[derive(Debug, Serialize, Deserialize)]
727pub struct SettingsArgs {
728 pub actor: User,
729 #[serde(flatten)]
730 pub owner: SettingsOwner,
731 pub kind: String,
732}
733
734/// `set_setting`: add or replace one. A repository's need a member; a
735/// workspace's an owner. Returns `Outcome<Setting>`.
736#[derive(Debug, Serialize, Deserialize)]
737pub struct SetSettingArgs {
738 pub actor: User,
739 #[serde(flatten)]
740 pub owner: SettingsOwner,
741 /// `secret` or `variable`. Changing a variable's row to `secret` seals
742 /// it; a secret cannot become a variable.
743 pub kind: String,
744 pub name: String,
745 /// The row to change. Left out, the key's row for every environment, as
746 /// GitHub's API addresses a secret by name alone.
747 #[serde(default)]
748 pub id: Option<String>,
749 /// Needed for a new row; left out, an existing row keeps its value.
750 #[serde(default)]
751 pub value: Option<String>,
752 /// `workflows` and/or `deployments`; left out, unchanged (both, for a
753 /// new row).
754 // Named as callers send it: an `alias` is not honoured beside the
755 // flattened owner in the Worker's build.
756 #[serde(default, rename = "availableTo")]
757 pub available_to: Option<Vec<String>>,
758 /// The environments it applies to; empty is every one. Left out,
759 /// unchanged.
760 #[serde(default)]
761 pub environments: Option<Vec<String>>,
762 /// A workspace's row: project slugs; empty for every one.
763 #[serde(default)]
764 pub projects: Option<Vec<String>>,
765 #[serde(default)]
766 pub note: Option<String>,
767}
768
769/// `resolve_settings`: the secrets and variables one reader gets, for the
770/// services that hand them out (the deployments service). Returns
771/// `ResolvedSettings`.
772#[derive(Debug, Serialize, Deserialize)]
773#[serde(rename_all = "camelCase")]
774pub struct ResolveSettingsArgs {
775 pub repo_id: String,
776 pub repo: RepoPath,
777 /// The project being read for; its repository's primary project if left
778 /// out.
779 #[serde(default)]
780 pub project_id: Option<String>,
781 #[serde(default)]
782 pub project_slug: Option<String>,
783 /// `workflows` or `deployments`.
784 pub consumer: String,
785 /// The environment being read for, such as `production` or `preview`.
786 #[serde(default)]
787 pub environment: Option<String>,
788 /// Whether the run is trusted; an untrusted one gets no secrets.
789 pub trusted: bool,
790}
791
792#[derive(Debug, Default, Serialize, Deserialize)]
793pub struct ResolvedSettings {
794 pub secrets: serde_json::Map<String, serde_json::Value>,
795 pub variables: serde_json::Map<String, serde_json::Value>,
796}
797
798/// `delete_setting`. Returns `Outcome<bool>`.
799#[derive(Debug, Serialize, Deserialize)]
800pub struct DeleteSettingArgs {
801 pub actor: User,
802 #[serde(flatten)]
803 pub owner: SettingsOwner,
804 pub kind: String,
805 pub name: String,
806 /// One row; left out, every row of the key.
807 #[serde(default)]
808 pub id: Option<String>,
809}
810
811/// `job_spec` and `job_report`: the sandbox running a job, with the job's
812/// own token. `report` is one of:
813/// `{"kind": "step", "number", "status", "conclusion"}`,
814/// `{"kind": "log", "step", "text"}`,
815/// `{"kind": "annotation", "level", "message", "title", "file", "line"}`,
816/// `{"kind": "done", "conclusion", "outputs", "reason"}`.
817#[derive(Debug, Serialize, Deserialize)]
818pub struct JobCallArgs {
819 pub job: String,
820 pub token: String,
821 #[serde(default)]
822 pub report: Value,
823}
824
825/// What the runner needs to start a job's sandbox.
826#[derive(Debug, Serialize, Deserialize)]
827#[serde(rename_all = "camelCase")]
828pub struct StartJobArgs {
829 pub job: String,
830 pub token: String,
831 pub repo: RepoPath,
832 /// Minutes before the job is stopped.
833 pub timeout_minutes: u32,
834 /// The workflow file the job is in (`.g1t/workflows/deploy.yml`), for
835 /// the guardrails' workflow-only domains.
836 #[serde(default)]
837 pub workflow: Option<String>,
838 /// The environment the job names with `environment:`, when it names
839 /// one plainly (not with an expression).
840 #[serde(default)]
841 pub environment: Option<String>,
842 /// Whether its run is trusted: not a pull request from a fork. Only a
843 /// trusted run's jobs reach workflow-only domains.
844 #[serde(default)]
845 pub trusted: bool,
846 /// The machine its `runs-on` asked for, by label (`instance_for`):
847 /// `g1t-2core` or `g1t-4core`; absent, the standard one.
848 #[serde(default)]
849 pub instance: Option<String>,
850}
851
852/// A size of machine g1t runs workflow jobs on, asked for by a label in
853/// `runs-on`. Each is a Cloudflare Containers instance type; it costs what
854/// that instance costs g1t, plus the margin, like any sandbox time.
855#[derive(Clone, Copy, Debug, PartialEq)]
856pub struct InstanceType {
857 /// The `runs-on` label, or `standard` for the default.
858 pub label: &'static str,
859 /// The Containers instance type.
860 pub container: &'static str,
861 pub vcpu: f64,
862 pub memory_gib: f64,
863 pub disk_gb: f64,
864 /// What a second of it costs g1t as a multiple of the standard
865 /// machine's, with its vCPUs as busy (Cloudflare's list prices:
866 /// memory $0.0000025 a GiB-second, disk $0.00000007 a GB-second, vCPU
867 /// $0.00002 a second). Used to reserve before a job starts, and to
868 /// price a job that did not report its own CPU.
869 pub price_scale: f64,
870}
871
872/// The default: what `ubuntu-latest` and every other hosted label get.
873pub const STANDARD_INSTANCE: InstanceType =
874 InstanceType { label: "standard", container: "standard-1", vcpu: 0.5, memory_gib: 4.0, disk_gb: 8.0, price_scale: 1.0 };
875
876/// Every machine a workflow job can ask for, the default first.
877pub const INSTANCE_TYPES: [InstanceType; 3] = [
878 STANDARD_INSTANCE,
879 InstanceType { label: "g1t-2core", container: "standard-3", vcpu: 2.0, memory_gib: 8.0, disk_gb: 16.0, price_scale: 2.8 },
880 InstanceType { label: "g1t-4core", container: "standard-4", vcpu: 4.0, memory_gib: 12.0, disk_gb: 20.0, price_scale: 5.1 },
881];
882
883/// The machine a job's `runs-on` labels ask for: the largest named, or the
884/// standard one. Labels compare without regard to case.
885pub fn instance_for(labels: &[String]) -> InstanceType {
886 INSTANCE_TYPES
887 .iter()
888 .rev()
889 .find(|instance| instance.label != STANDARD_INSTANCE.label && labels.iter().any(|label| label.trim().eq_ignore_ascii_case(instance.label)))
890 .copied()
891 .unwrap_or(STANDARD_INSTANCE)
892}
893
894/// An instance type by its label, if it is one.
895pub fn instance_named(label: &str) -> Option<InstanceType> {
896 INSTANCE_TYPES.iter().find(|instance| instance.label.eq_ignore_ascii_case(label.trim())).copied()
897}
898
899// ── The cache (actions/cache) ─────────────────────────────────────────────
900//
901// Entries are kept in R2 by the API (the ACTIONS_CACHE bucket) and listed
902// here, by the actions service, which decides what is found, what fits and
903// what is evicted. A sandbox reaches these through the API with its job's
904// token: `/actions/jobs/{job}/cache` (see apps/api/src/blobs.rs).
905
906/// The largest one cache entry may be, compressed.
907pub const CACHE_MAX_ENTRY_BYTES: u64 = 2 * 1024 * 1024 * 1024;
908/// What one repository's entries may hold together. Saving past it evicts
909/// the entries restored longest ago.
910pub const CACHE_REPO_QUOTA_BYTES: u64 = 10 * 1024 * 1024 * 1024;
911/// An entry not restored for this long is deleted.
912pub const CACHE_UNUSED_DAYS: u64 = 7;
913/// An entry is deleted this long after it was saved, however often it is
914/// restored (the bucket's own lifecycle rule deletes objects at 30 days).
915pub const CACHE_MAX_AGE_DAYS: u64 = 28;
916/// An upload is sent in parts of this size (the last may be smaller).
917pub const CACHE_PART_BYTES: u64 = 32 * 1024 * 1024;
918/// What R2 charges g1t to store a GB for a month, in millionths of a
919/// dollar ($0.015): what the cache's storage is charged at, plus the margin.
920pub const CACHE_MICROS_PER_GB_MONTH: i64 = 15_000;
921
922/// `cache_lookup`: the entry a job restores: its key exactly, else the
923/// newest whose key starts with one of `restore`, in order.
924/// Returns `Outcome<Option<CacheHit>>`.
925#[derive(Debug, Serialize, Deserialize)]
926pub struct CacheLookupArgs {
927 pub job: String,
928 pub token: String,
929 pub key: String,
930 #[serde(default)]
931 pub restore: Vec<String>,
932 /// The entry's version, a hash of its paths and compression, as the
933 /// toolkit's client and g1t's runner both send it: only an entry of the
934 /// same version is found. `None` from runners that send none, whose
935 /// entries have none.
936 #[serde(default)]
937 pub version: Option<String>,
938}
939
940#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
941pub struct CacheHit {
942 pub key: String,
943 pub object: String,
944 pub size: u64,
945 /// When it was saved, RFC 3339.
946 #[serde(default)]
947 pub created_at: String,
948 /// A signed token for downloading it through the toolkit's blob
949 /// endpoint, when the lookup came with a version.
950 #[serde(default)]
951 pub blob: Option<String>,
952}
953
954/// `cache_reserve`: a job about to save `size` bytes under `key`. Refused
955/// when the key is taken (`conflict`: keys are written once) or the entry
956/// is too large. Returns `Outcome<CacheReservation>`.
957#[derive(Debug, Serialize, Deserialize)]
958pub struct CacheReserveArgs {
959 pub job: String,
960 pub token: String,
961 pub key: String,
962 /// Its size, when known before it is sent (the toolkit's newer client
963 /// says only when it finishes: 0 then).
964 pub size: u64,
965 /// As in `CacheLookupArgs`.
966 #[serde(default)]
967 pub version: Option<String>,
968}
969
970#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
971pub struct CacheReservation {
972 pub id: String,
973 /// Where the API puts it in R2.
974 pub object: String,
975 /// The entry's number, which the toolkit's older protocol names it by.
976 #[serde(default)]
977 pub number: u64,
978 /// Its R2 upload, once one is started.
979 #[serde(default)]
980 pub upload: Option<String>,
981 /// A signed token for sending its parts through the toolkit's blob
982 /// endpoint, once its upload is started.
983 #[serde(default)]
984 pub blob: Option<String>,
985}
986
987/// `cache_upload`: an entry a job is still uploading, by its number or by
988/// key and version. Returns `Outcome<CacheReservation>`, with `upload` and
989/// `blob` set once its upload has been started.
990#[derive(Debug, Serialize, Deserialize)]
991pub struct CacheUploadArgs {
992 pub job: String,
993 pub token: String,
994 #[serde(default)]
995 pub number: Option<u64>,
996 #[serde(default)]
997 pub key: Option<String>,
998 #[serde(default)]
999 pub version: Option<String>,
1000}
1001
1002/// `cache_commit`: the upload of `id` is complete, at `size` bytes. Returns
1003/// `Outcome<CacheCommitted>`: the objects of entries it evicted, which the
1004/// API deletes from R2.
1005#[derive(Debug, Serialize, Deserialize)]
1006pub struct CacheCommitArgs {
1007 pub job: String,
1008 pub token: String,
1009 pub id: String,
1010 pub size: u64,
1011}
1012
1013#[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
1014pub struct CacheCommitted {
1015 pub evicted: Vec<String>,
1016}
1017
1018/// `cache_abort`: an upload that will not finish; its reservation goes.
1019/// Returns `Outcome<bool>`.
1020#[derive(Debug, Serialize, Deserialize)]
1021pub struct CacheAbortArgs {
1022 pub job: String,
1023 pub token: String,
1024 pub id: String,
1025}
1026
1027// ── Artifacts (actions/upload-artifact) ───────────────────────────────────
1028//
1029// Kept in R2 by the API (the ACTIONS_CACHE bucket, under `a/`) and listed
1030// here, by the actions service, which decides names, sizes and how long
1031// each is kept. A sandbox reaches them with its job's token
1032// (`/actions/jobs/{job}/artifacts…`) or, through the toolkit's protocol,
1033// with its runtime token (`ACTIONS_RUNTIME_TOKEN`); people through the
1034// REST API and the run's page.
1035
1036/// The largest one artifact may be.
1037pub const ARTIFACT_MAX_BYTES: u64 = 5 * 1024 * 1024 * 1024;
1038/// What one run's artifacts may hold together.
1039pub const RUN_ARTIFACTS_MAX_BYTES: u64 = 10 * 1024 * 1024 * 1024;
1040/// How long artifacts are kept unless a repository says otherwise.
1041pub const ARTIFACT_RETENTION_DEFAULT_DAYS: u32 = 14;
1042/// The longest a repository may keep them.
1043pub const ARTIFACT_RETENTION_MAX_DAYS: u32 = 90;
1044/// A native upload is sent in parts of this size (the last may be smaller).
1045pub const ARTIFACT_PART_BYTES: u64 = 32 * 1024 * 1024;
1046
1047/// An artifact, as the API and the site show it.
1048#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1049pub struct Artifact {
1050 pub id: u64,
1051 pub name: String,
1052 pub size: u64,
1053 /// `sha256:<hex>`, when the uploader said.
1054 pub digest: Option<String>,
1055 /// `zip`, or `tgz` for one an older runner sent.
1056 pub format: String,
1057 pub run_id: String,
1058 pub job_id: String,
1059 pub repo_id: String,
1060 /// Whether it has expired or been deleted (its bytes are gone).
1061 pub expired: bool,
1062 pub created_at: String,
1063 pub updated_at: String,
1064 pub expires_at: String,
1065 /// The run's branch and commit, for the REST shape.
1066 #[serde(default)]
1067 pub head_branch: Option<String>,
1068 #[serde(default)]
1069 pub head_sha: Option<String>,
1070}
1071
1072/// An artifact with where its bytes are, and a signed token for them.
1073#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1074pub struct ArtifactBlob {
1075 pub artifact: Artifact,
1076 pub object: String,
1077 /// For the toolkit's blob endpoint (`/actions/toolkit/blobs/{blob}`).
1078 pub blob: String,
1079}
1080
1081/// A page of artifacts, in GitHub's shape.
1082#[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
1083pub struct ArtifactList {
1084 pub total_count: u64,
1085 pub artifacts: Vec<Artifact>,
1086}
1087
1088/// `artifact_reserve`: a job about to upload an artifact. Refused when its
1089/// run has one of that name and `overwrite` is not set (`conflict`), or it
1090/// is too large. Returns `Outcome<ArtifactReservation>`.
1091#[derive(Debug, Default, Serialize, Deserialize)]
1092pub struct ArtifactReserveArgs {
1093 pub job: String,
1094 /// The job's token, or its runtime token.
1095 pub token: String,
1096 pub name: String,
1097 /// Its size, when known before it is sent (0 otherwise).
1098 #[serde(default)]
1099 pub size: u64,
1100 /// Days to keep it: 0 for the repository's default; at most the
1101 /// repository's setting.
1102 #[serde(default)]
1103 pub retention_days: u32,
1104 /// When to expire it, RFC 3339, as the toolkit says it (in place of
1105 /// `retention_days`).
1106 #[serde(default)]
1107 pub expires_at: Option<String>,
1108 #[serde(default)]
1109 pub overwrite: bool,
1110 /// `zip` (the default) or `tgz`.
1111 #[serde(default)]
1112 pub format: Option<String>,
1113}
1114
1115#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1116pub struct ArtifactReservation {
1117 pub id: u64,
1118 /// Where the API puts it in R2.
1119 pub object: String,
1120 /// The days it will be kept, and until when.
1121 pub retention_days: u32,
1122 pub expires_at: String,
1123}
1124
1125/// `artifact_commit`: its upload is complete, at `size` bytes. The artifact
1126/// is named by `id`, or by `name` in the job's run (the toolkit's way).
1127/// Returns `Outcome<Artifact>`.
1128#[derive(Debug, Default, Serialize, Deserialize)]
1129pub struct ArtifactCommitArgs {
1130 pub job: String,
1131 pub token: String,
1132 #[serde(default)]
1133 pub id: Option<u64>,
1134 #[serde(default)]
1135 pub name: Option<String>,
1136 pub size: u64,
1137 #[serde(default)]
1138 pub digest: Option<String>,
1139}
1140
1141/// `job_artifacts`: a running job listing the artifacts of its own run, or
1142/// of another run of its repository (`run_id`), narrowed by `name` or
1143/// `id`: `Outcome<Vec<Artifact>>`. `job_artifact` gives the one named, with
1144/// a token to download it: `Outcome<ArtifactBlob>`. `job_delete_artifact`
1145/// deletes one of its own run's: `Outcome<Artifact>`. `artifact_abort`
1146/// gives up an upload by `id`: `Outcome<bool>`.
1147#[derive(Debug, Default, Serialize, Deserialize)]
1148pub struct JobArtifactsArgs {
1149 pub job: String,
1150 pub token: String,
1151 #[serde(default)]
1152 pub run_id: Option<String>,
1153 #[serde(default)]
1154 pub name: Option<String>,
1155 #[serde(default)]
1156 pub id: Option<u64>,
1157}
1158
1159/// `artifacts`: a repository's artifacts, newest first, or one run's.
1160/// Anyone who can see the repository. Returns `Outcome<ArtifactList>`.
1161#[derive(Debug, Serialize, Deserialize)]
1162pub struct ArtifactsArgs {
1163 pub repo: RepoPath,
1164 pub viewer: Viewer,
1165 #[serde(default)]
1166 pub run: Option<String>,
1167 #[serde(default)]
1168 pub name: Option<String>,
1169 #[serde(default)]
1170 pub page: Option<u32>,
1171 #[serde(default)]
1172 pub per_page: Option<u32>,
1173}
1174
1175/// `artifact` (`Outcome<Artifact>`) and `artifact_download`
1176/// (`Outcome<ArtifactBlob>`, with a token good for a few minutes): one
1177/// artifact by `id`, or by `name` within `run`. Anyone who can see the
1178/// repository.
1179#[derive(Debug, Serialize, Deserialize)]
1180pub struct ArtifactArgs {
1181 pub repo: RepoPath,
1182 pub viewer: Viewer,
1183 #[serde(default)]
1184 pub id: Option<u64>,
1185 #[serde(default)]
1186 pub run: Option<String>,
1187 #[serde(default)]
1188 pub name: Option<String>,
1189}
1190
1191/// `delete_artifact`: needs the Write role. Returns `Outcome<Artifact>`.
1192#[derive(Debug, Serialize, Deserialize)]
1193pub struct DeleteArtifactArgs {
1194 pub actor: User,
1195 pub repo: RepoPath,
1196 pub id: u64,
1197}
1198
1199/// `artifact_retention`: anyone who can see the repository. With `days`,
1200/// sets it, which needs the Maintain role. Returns
1201/// `Outcome<ArtifactRetention>`.
1202#[derive(Debug, Serialize, Deserialize)]
1203pub struct ArtifactRetentionArgs {
1204 pub repo: RepoPath,
1205 pub viewer: Viewer,
1206 #[serde(default)]
1207 pub days: Option<u32>,
1208}
1209
1210/// GitHub's shape: the days artifacts are kept by default, and the most a
1211/// repository may choose.
1212#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1213pub struct ArtifactRetention {
1214 pub days: u32,
1215 pub maximum_allowed_days: u32,
1216}
1217
1218// ── The toolkit's protocols ───────────────────────────────────────────────
1219//
1220// Actions built on GitHub's toolkit (`@actions/cache`, `@actions/artifact`,
1221// `@actions/core`'s `getIDToken`) reach g1t with the job's runtime token,
1222// `ACTIONS_RUNTIME_TOKEN`: a JSON Web Token whose `scp` names the run and
1223// job, signed with a key derived from the job's own token, so the actions
1224// service checks it without keeping another secret. Cache and artifact
1225// operations above take it in place of the job's token.
1226
1227/// `runtime_auth`: which job a runtime token is, while it runs:
1228/// `Outcome<RuntimeJob>`. `oidc_claims` takes the same and returns
1229/// `Outcome<Value>`: the claims of the job's OIDC token, less `iss`, `aud`,
1230/// `jti` and the times, or `forbidden` when the job's `permissions` do not
1231/// give it `id-token: write`.
1232#[derive(Debug, Serialize, Deserialize)]
1233pub struct RuntimeAuthArgs {
1234 pub job: String,
1235 pub token: String,
1236}
1237
1238#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1239pub struct RuntimeJob {
1240 pub job: String,
1241 pub run: String,
1242 pub repo_id: String,
1243 pub namespace: String,
1244 /// `owner/name`.
1245 pub repository: String,
1246}
1247
1248/// What a signed blob token lets its holder do.
1249#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1250pub struct BlobGrant {
1251 /// `cache` or `artifact`.
1252 pub kind: String,
1253 /// The entry's id: a cache entry's `cache_…`, an artifact's number.
1254 pub id: String,
1255 pub object: String,
1256 /// The R2 upload it sends parts to; `None` for a download.
1257 pub upload: Option<String>,
1258 /// For a download: what to call the file, and its type.
1259 #[serde(default)]
1260 pub filename: Option<String>,
1261 #[serde(default)]
1262 pub content_type: Option<String>,
1263}
1264
1265/// `blob_sign`: a token for uploading an entry the job reserved, to the R2
1266/// upload the API started for it. Returns `Outcome<String>`.
1267#[derive(Debug, Serialize, Deserialize)]
1268pub struct BlobSignArgs {
1269 pub job: String,
1270 pub token: String,
1271 /// `cache` or `artifact`.
1272 pub kind: String,
1273 pub id: String,
1274 pub upload: String,
1275}
1276
1277/// `blob_open`: what a signed token grants, while it is good and its entry
1278/// is there: `Outcome<BlobGrant>`. `blob_part` records a part sent with an
1279/// upload token (`part`, `etag`, `size`): `Outcome<bool>`. `blob_parts`
1280/// gives the parts recorded, in order: `Outcome<Vec<BlobPart>>`, and
1281/// `blob_done` forgets them: `Outcome<bool>`.
1282#[derive(Debug, Default, Serialize, Deserialize)]
1283pub struct BlobArgs {
1284 pub blob: String,
1285 #[serde(default)]
1286 pub part: u32,
1287 #[serde(default)]
1288 pub etag: String,
1289 #[serde(default)]
1290 pub size: u64,
1291}
1292
1293#[derive(Clone, Debug, PartialEq, Serialize, Deserialize)]
1294pub struct BlobPart {
1295 pub part: u32,
1296 pub etag: String,
1297 pub size: u64,
1298}
1299
1300#[cfg(test)]
1301mod instance_tests {
1302 use super::*;
1303
1304 fn labels(given: &[&str]) -> Vec<String> {
1305 given.iter().map(|l| (*l).to_owned()).collect()
1306 }
1307
1308 #[test]
1309 fn runs_on_picks_the_machine() {
1310 assert_eq!(instance_for(&labels(&["ubuntu-latest"])).container, "standard-1");
1311 assert_eq!(instance_for(&labels(&[])).label, "standard");
1312 assert_eq!(instance_for(&labels(&["g1t-4core"])).container, "standard-4");
1313 assert_eq!(instance_for(&labels(&["ubuntu-latest", "G1T-2Core"])).container, "standard-3");
1314 // Both named: the larger.
1315 assert_eq!(instance_for(&labels(&["g1t-2core", "g1t-4core"])).label, "g1t-4core");
1316 assert_eq!(instance_named("g1t-4core").map(|i| i.vcpu), Some(4.0));
1317 assert_eq!(instance_named("standard"), Some(STANDARD_INSTANCE));
1318 assert_eq!(instance_named("g1t-64core"), None);
1319 }
1320
1321 #[test]
1322 fn start_args_from_older_callers_read() {
1323 let args: StartJobArgs = serde_json::from_value(serde_json::json!({
1324 "job": "job_1", "token": "t", "repo": { "namespace": "acme", "name": "web" }, "timeoutMinutes": 30
1325 }))
1326 .unwrap();
1327 assert!(args.workflow.is_none() && args.environment.is_none() && !args.trusted && args.instance.is_none());
1328 }
1329}
1330
1331#[cfg(test)]
1332mod setting_args_tests {
1333 use super::*;
1334
1335 #[test]
1336 fn who_reads_a_row_is_read_as_the_site_and_api_send_it() {
1337 let args: SetSettingArgs = serde_json::from_value(serde_json::json!({
1338 "actor": { "id": "usr_1", "username": "a" },
1339 "repo": { "namespace": "acme", "name": "web" },
1340 "kind": "secret",
1341 "name": "STRIPE_KEY",
1342 "availableTo": ["deployments"],
1343 "environments": ["production"],
1344 }))
1345 .unwrap();
1346 assert_eq!(args.available_to, Some(vec!["deployments".to_owned()]));
1347 }
1348}