Repository navigation
fix: batch the CNCF project matrix to stay under the 256-job limit - #32
Merged
Merged
Conversation
The combined CNCF + manual project list has 263 repositories, which exceeds GitHub Actions' maximum of 256 matrix configurations. Since 2026-09-11 the generate-sbom-cncf job was therefore never scheduled and no project SBOMs were produced by the weekly runs (e.g. kptdev/kpt v1.0.1 was missed). Split the project matrix into batches of 200 and run them through the reusable workflow, mirroring the existing subproject batching. Signed-off-by: Mario Fahlandt <mfahlandt@pixel-haufen.de>
mfahlandt
force-pushed
the
fix/batch-cncf-matrix
branch
from
October 5, 2026 14:31
c253744 to
117f30f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The scheduled run https://github.com/cncf/sbom/actions/runs/37172336090 failed with:
cncf-projects.yaml(229 repos) + the manually maintainedrepositories.yaml(34 repos) yield 263 matrix entries. Sincerepositories.yamlgrew on 2026-09-11, thegenerate-sbom-cncfjob has never been scheduled in any weekly run, so no project SBOMs have been generated since then – e.g.kptdev/kptv1.0.1 (published 2026-09-25) was missed.Fix
prepare-cncf-matrixnow splits the project list into up to 3 batches of 200 (matrix1..3/has_repos1..3) and fails loudly if even that is exceeded.generate-sbom-cncfjob is replaced bygenerate-sbom-cncf-{1,2,3}, which callreusable-generate-sbom.yml– the same path the subproject batches already use (emptysbom_path_prefix→ project bucket, unchanged key layout).summarize-sbom-rundependencies and job-name filters updated accordingly.Locally verified:
util/prepare-project-matrix.sh all→ 263 repos → batches of 200 / 63 / 0;util/tests/prepare-project-matrix.shpasses; workflow YAML parses.Follow-up
After merging, backfill the missed releases with a manual run:
source=cncf,releases_mode=latest,max_releases=3.