ci: compose CI from devenv's building blocks - #954
Merged
Merged
Conversation
- Retire the dead .circleci ignore lines (devenv's new retirement lists). - eslint base config: presets apply again and Markdown code blocks are linted, which reformats the compose YAML example in docs/DOCKER.md. - pyproject template: T201 exemption for bin/release_info.py. - eslint-plugin-package-json bump. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ci.yml is now a caller of devenv's CI building blocks (copied in by `make update-devenv`) plus codex's own image jobs: - ci: devenv-check.yml with ci-target codex-ci and the same four checks. Its gate runs the Release Preflight and, on a main push, reuses the python-dist of an earlier run that passed on the same git tree (keyed by tree hash, replacing the "last merged PR" lookup). One image job builds codex-ci and pushes it by digest; each check pulls it instead of building and loading its own. The required check becomes "CI / Lint, Test & Build Dist". - build, deploy, deploy-hub: unchanged in substance, but they read deploy/version/final from ci's outputs instead of testing the event or grepping pyproject.toml. deploy publishes to PyPI through devenv-pypi (uv publish --check-url) after the manifest. deploy-hub now skips at the job level for alphas. - release: devenv-release.yml (tag, GitHub Release, merge-back), after deploy and deploy-hub. Removes .github/actions/ci-container (now devenv-ci-container) and the release-engine tests, which devenv owns now; codex keeps its golden NEWS.md tests. tests/test_ci_workflow.py pins how codex wires the blocks. CLAUDE.md describes the new graph and the current Dockerfile stages. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Since the ESLint preset fix (#931, #932), import-x/no-unresolved resolves the frontend's `@/choices/*.json` imports, which bin/build-choices.sh generates and git ignores. A checkout that never built them, such as CI's fresh codex-ci container, fails `make lint` and `make fix` with 19 unresolved-import errors. Give lint and fix the same build-choices prerequisite test-frontend and build already have. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ci.ymlbecomes a caller of devenv's CI building blocks (thedevenv-*workflows and actions, copied in bymake update-devenv), plus codex's own image jobs. It's the same design as the September gate/matrix/release work, now shared with the other repos and tested in devenv.cidevenv-check.ymlwithci-target: codex-ciand the same four checks, described below.buildci's outputs, not from greppingpyproject.toml.deploydevenv-pypi(uv publish --check-url, so a re-run skips files already on PyPI).deploy-hubreleasedevenv-release.yml: tag, GitHub Release, merge-back. Runs afterdeployanddeploy-hub.What
devenv-checkdoes insideci:python-distof an earlier run that passed on the same git tree. It keys on the tree hash, replacing the "last merged PR" lookup, and ignores runs from forks.codex-ciand pushes it by digest toghcr.io/ajslater/codex-ci. The four checks pull it instead of each building and loading their own. In bochord's pilot this cut runner time by 40%.CI / Lint, Test & Build Dist.Every later job reads
ci's outputs (deploy,release,version,final) instead of testing the event, and gates on!cancelled()plus an explicitneeds.X.result.Removed:
.github/actions/ci-container, now devenv'sdevenv-ci-container.tests/test_release_tag_script.pyand the engine tests intests/test_release_info.py. devenv owns and tests the release engine now; codex keeps its golden NEWS.md tests.Also updated:
tests/test_ci_workflow.pynow pins how codex wires the blocks.CLAUDE.mddescribes the new graph, and its Docker section now matches the actual Dockerfile stages.Also fixes CI Lint, which was already broken on
develop.import-x/no-unresolvedresolves the frontend's@/choices/*.jsonimports.bin/build-choices.shgenerates those files, and git ignores them.cfg/codex.mknow giveslintandfixthe samebuild-choicesprerequisite thattest-frontendandbuildalready have.The first commit is a routine
make update-devenv:.circleciignore lines are retireddocs/DOCKER.mdRequired check on main
Done:
main's branch protection now requiresCI / Lint, Test & Build Dist(GitHub Actions app, strict) instead ofLint, Test & Build Dist.Test plan
make fix,make lint(including actionlint on every workflow) andmake typasscodex/views/browser/annotate/cover.py, which this PR doesn't touchmake lintfrom a checkout with no generated choices (CI's conditions):build-choicesruns first and lint passesmake test:codex-ciand pushes it by digestCI / Lint, Test & Build Distis greenci-passed-<tree>marker andpython-distare uploadedbuild,deploy,deploy-hubandreleasefirst run on apre-releasePR or the next main push🤖 Generated with Claude Code