Skip to content

HyperShell

HyperShell #4

Workflow file for this run

name: HyperShell
on:
push:
branches: [main]
workflow_dispatch:
permissions:
contents: read
concurrency:
group: hypershell-${{ github.repository }}-${{ github.ref }}
cancel-in-progress: false
jobs:
canonical-remote:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
with:
# This job builds and runs repository-controlled code; don't leave the
# GITHUB_TOKEN in the local git config for it to reach.
persist-credentials: false
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- name: Build harness
run: CGO_ENABLED=0 go build -ldflags '-s -w -X main.version=ci' -o harness .
# Platform bootstrap adds this service-account subject to the gateway's
# default workspace once. No administrator credential belongs in the repo.
- name: Run canonical remote lifecycle
env:
HYPERSHELL_GATEWAY: ${{ secrets.HYPERSHELL_GATEWAY }}
HYPERSHELL_OIDC_ISSUER: ${{ secrets.HYPERSHELL_OIDC_ISSUER }}
HYPERSHELL_OIDC_AUDIENCE: ${{ secrets.HYPERSHELL_OIDC_AUDIENCE }}
HYPERSHELL_SANDBOX_SA_ID: ${{ secrets.HYPERSHELL_SANDBOX_SA_ID }}
OPENSHELL_OIDC_CLIENT_SECRET: ${{ secrets.HYPERSHELL_SANDBOX_SA_SECRET }}
run: |
# Gateway caps sandbox names at 19 chars; run_id is ~11 digits, so
# take its last 9 to stay bounded regardless of run_id growth.
name="sm-${GITHUB_RUN_ID: -9}-${GITHUB_RUN_ATTEMPT}"
output="$(./harness apply "$name" \
--file test/hypershell-workflow.yaml)"
echo "$output"
grep -q 'canonical-sdk-ok' <<<"$output"