Skip to content
CI Workflows

CI Workflows

Every file in .github/workflows/, with its triggers as declared in its on: block and its purpose as its own name: states it. Cron expressions are copied verbatim and are UTC. When this page and a workflow disagree, the workflow is right: put cadence in the workflow and let docs point at it.

Legend: dispatch = workflow_dispatch, call = workflow_call, rd: = repository_dispatch types, comment = issue_comment: created.

Agents

WorkflowTriggersPurpose
core-code-review.ymlpull_request opened/synchronize · comment · dispatch · call · rd: core-reviewsovereign code review (reviewer + inline fixer)
core-review-sweep.ymlcron */10 * * * * · dispatchreview every open PR in the org, centrally
core-agent-fixer.ymldispatch (pr) · comment (@core_fix)draft a fix from review findings
core-agent-resolver.ymlrd: core-resolve · cron 17 */3 * * * · dispatch (repo, pr)resolve findings the fixer could not
core-agent-triage.ymlissues: opened · dispatch (issue) · callcategorize and label new issues
core-agent-selfheal.ymlworkflow_run: completed on eight named workflows · dispatch (run_id) · calldiagnose failing CI
core-agent-risk.ymlcron 23 5 * * * · dispatch · rd: core-playbookproactive dependency-vulnerability scan
core-agent-compliance.ymlcron 13 1 * * * · dispatch · rd: core-playbook, core-agent-complianceverify framework alignment
core-curate.ymlcron 17 6 * * * · comment (core @curate) · dispatch (scope, dry) · rd: core-playbookthe curator
core-agent-deployer.ymlcomment (@core_deploy) · dispatch (issue, app)execute a task issue on the sovereign model
core-agent-datagov.ymlcron 11 7 * * * · comment (@core_datagov) · dispatch · rd: core-playbook, core-agent-datagovassess the connected data sources
core-agent-judge.ymlcron 29 8 * * * · comment (@core_judgement) · dispatch · rd: core-playbookindependently judge submitted findings
core-agent-recon.ymlcron 37 9 * * * · comment (@core_recon) · dispatch · rd: core-playbookreconcile the governance rule book against the engine
core-agent-users.ymlissues opened/labeled/closed/reopened/edited · dispatch · callcore @add_users: grant or revoke access on any target
core-forge-run.ymlcron 41 3,9,15,21 * * * · dispatch (repo, issue, dry)build the next forge issue (the forger)
core-inference-bench.ymldispatch (url, model, max_tokens, runs)TTFT + decode tok/s, the number every agent budget is written against
core-tag-help.ymlcommentanswer an unrecognised agent tag with the ones that work
core-agents-build.ymlpull_request / push to main on grpc/agents/** and the inference/ml snapshots · dispatchbuild/vet/test the stdlib agent modules

core-agent-selfheal.yml watches exactly these workflow names: core @build, core deploy, core images build, core CD, core @apply, core frontend-config, core edge-auth, and core ship (comment).

PR gates and guards

WorkflowTriggersPurpose
core-pr-gate.ymlpull_request opened/synchronize/reopened/ready_for_reviewthe one check branch protection can require
core-ci.ymlpull_request on operator, agent, CLI, modelrouter and appbench paths · dispatchalways-on CI
core-compliance-gate.ymlpull_request · call (repo_subdir, core_ref)deterministic control checks on every PR, with no model and no network
core-license-policy.ymlpull_request · push to main · dispatchfail a PR that adds a denied-licence dependency
core-terraform-guard.ymlpull_request · push to mainTerraform only as the Marketplace package format
core-snapshot-guard.ymlpull_request on the .github/*-snapshot trees, the core operator, ambassador, devgateway, grpc/go.mod/go.sum · dispatchcompile the consumers against the committed sibling snapshots
core-vendor-guard.ymlpull_request on grpc/**, .gitignore · dispatchprove grpc/vendor/ is complete and builds offline
core-manifest-validate.ymlpull_request / push to main on grpc/infrastructure/apps/onhost/** · dispatchschema-validate the on-host manifests
core-webui-flutter.ymlpull_request / push to main on flutter/**, .github/ui-snapshot/** · dispatchconsole web UI: flutter analyze + test
core-dev-workstation.ymlpull_request / push to main on dev/workstation/**shellcheck + pins for the developer bootstrap
core-automerge-docs.ymlpull_request opened/reopened/synchronize/ready_for_review/converted_to_draft/labeled/unlabeledauto-merge documentation-only PRs (no-auto-merge label opts out)
gatekeeper.ymlpull_request · push to mainorg-wide security gate: secret scan, workflow lint, credential checks, dependency review
sovereignty.ymlpull_request · push to mainCI backstop for the sovereignty guardrail

Scheduled drift and security

WorkflowTriggersPurpose
core-security-sast.ymlcron 17 4 * * 0 · dispatch (update_baseline)weekly SAST sweep (gosec ratchet) across core and its siblings
core-snapshot-drift.ymlcron 23 7 * * * · rd: security-snapshot, store-snapshot, inference-snapshot, ui-snapshot, billing-snapshot, mesh-snapshot, ml-snapshot · dispatchbyte-compare the snapshots against their upstream siblings
core-vendor-drift.ymlcron 41 7 * * * · rd: vendor-siblings · dispatchre-vendor from the siblings’ default branches and fail on any diff
core-crossrepo-contract.ymlcron 57 7 * * * · rd: crossrepo-contract · dispatchcheck both halves of two-repo contracts
core-images-scan.ymldispatch (images, tag, origin) · rd: images-scanSBOM + CVE over the node-local registry, reporting only

Build, deliver and operate

WorkflowTriggersPurpose
core-cd.ymlpush to main · dispatch (images)rebuild and roll what a merge actually changed
core-images-build.ymldispatch (images, tag, scan, enforce_digest, base_source) · callwerf + buildah in-cluster build to the node-local registry
core-build.ymlcomment (core @build) · dispatch (ref)cheap build/vet check, on demand
core-deploy.ymldispatch (apps, build) · push of tags deploy-*, v*production pipeline: build → mesh-ca → deploy → edge → verify
core-deploy-comment.ymlcomment (@core_ship)build image(s) and roll what runs them
core-apply-onhost.ymlpush to main on the on-host manifests and RBAC · dispatchapply the on-host manifests from main
core-redeploy-base.ymldispatch (namespace, deployment, image, health_host)roll a base-stack app to its freshly built image
core-bare-deploy.ymlissues opened/labeled · dispatchprovision a demo instance on the bare-metal k0s
core-argo-sync.ymldispatch (app)force one Argo CD Application to reconcile now
core-edge-tls.ymlcron */30 * * * * · dispatch · callsovereign DNS-01 wildcard TLS for the edge
core-edge-auth-enroll.ymlcron 17 6 * * * · dispatch · callenroll per-host OIDC into the k0s edge
core-frontend-config.ymldispatch · call · workflow_run of core edge — pass-through (app-level login)publish each app’s public UI config per host
core-gh-app-secret.ymldispatchpublish the GitHub App key to the in-cluster runners
core-k0s-upgrade.ymldispatch (mode: preflight, upgrade, verify)self-applied k0s upgrade via an in-cluster Job
core-ops-probe.ymldispatch (probe) · callread-only app-readiness diagnosis of the box
core-verify-sweep.ymlcron */10 * * * * · dispatchfind FORGE and forged-app commits CORE has not verified
core-verify.ymlrd: core-verify · dispatch (repo, sha)CORE’s central CI for FORGE and every forged app (core/ci)
core-river-iso-build.ymldispatchbuild the Runink server ISO (public base + core’s river-payload)
core-marketplace-image.ymldispatchbuild the commercial Compute Engine image
core-marketplace-deploy-test.ymldispatchboot a test VM from a CORE image, check it, delete it
docs-deploy.ymlpush to main or a PR on website/**check that this documentation site builds (to a scratch dir; never into docs/, publishes nothing)
face-fix-session-key.ymldispatchgive a FaceInstance runner the shared session key
face-unpin-runner.ymldispatchmove a FaceInstance image off a frozen digest onto a tag
forge-bootstrap-secrets.ymldispatchcreate forge-secrets and the envelope KEK in forge-system
luna-bootstrap-secrets.ymldispatchcreate luna-secrets in a fresh namespace

Things that bite

  • core @build is on demand, not always-on. core-build.yml builds against the live sibling repos, so it can stay green while an image built from the committed .github/security-snapshot fails. That is what core-snapshot-guard.yml exists to catch.
  • The image scan never delays a roll. core-images-build.yml dispatches core-images-scan.yml and does not wait; the scan uses --exit-code 0 and gates nothing.
  • After a CD roll, workloads are digest-pinned. core-cd.yml re-pins containers to :latest@<digest> and stamps the runink.org/commit label. A bare kubectl rollout restart restarts onto the same digest. To move a workload onto new bits, dispatch core-cd.yml with images=<img>. See Console Pages.
  • Commands with no caller. core scan-sweep and core security autoupdate (the CLI ports of the old scan-sweep.sh and security-autoupdate.sh) are invoked by no workflow. The live remediation path is core scan --fix, run by hand.
  • A trigger that cannot fire. core-frontend-config.yml listens for workflow_run of core edge — pass-through (app-level login), but no workflow in this directory has that name today. It runs only when dispatched or called by core-deploy.yml.