CI Workflows
Every file in .github/workflows/, with its triggers as declared in its on: block and its purpose as its own name: states it. Cron expressions are copied verbatim and are UTC. When this page and a workflow disagree, the workflow is right: put cadence in the workflow and let docs point at it.
Legend: dispatch = workflow_dispatch, call = workflow_call, rd: = repository_dispatch types, comment = issue_comment: created.
Agents
| Workflow | Triggers | Purpose |
|---|---|---|
core-code-review.yml | pull_request opened/synchronize · comment · dispatch · call · rd: core-review | sovereign code review (reviewer + inline fixer) |
core-review-sweep.yml | cron */10 * * * * · dispatch | review every open PR in the org, centrally |
core-agent-fixer.yml | dispatch (pr) · comment (@core_fix) | draft a fix from review findings |
core-agent-resolver.yml | rd: core-resolve · cron 17 */3 * * * · dispatch (repo, pr) | resolve findings the fixer could not |
core-agent-triage.yml | issues: opened · dispatch (issue) · call | categorize and label new issues |
core-agent-selfheal.yml | workflow_run: completed on eight named workflows · dispatch (run_id) · call | diagnose failing CI |
core-agent-risk.yml | cron 23 5 * * * · dispatch · rd: core-playbook | proactive dependency-vulnerability scan |
core-agent-compliance.yml | cron 13 1 * * * · dispatch · rd: core-playbook, core-agent-compliance | verify framework alignment |
core-curate.yml | cron 17 6 * * * · comment (core @curate) · dispatch (scope, dry) · rd: core-playbook | the curator |
core-agent-deployer.yml | comment (@core_deploy) · dispatch (issue, app) | execute a task issue on the sovereign model |
core-agent-datagov.yml | cron 11 7 * * * · comment (@core_datagov) · dispatch · rd: core-playbook, core-agent-datagov | assess the connected data sources |
core-agent-judge.yml | cron 29 8 * * * · comment (@core_judgement) · dispatch · rd: core-playbook | independently judge submitted findings |
core-agent-recon.yml | cron 37 9 * * * · comment (@core_recon) · dispatch · rd: core-playbook | reconcile the governance rule book against the engine |
core-agent-users.yml | issues opened/labeled/closed/reopened/edited · dispatch · call | core @add_users: grant or revoke access on any target |
core-forge-run.yml | cron 41 3,9,15,21 * * * · dispatch (repo, issue, dry) | build the next forge issue (the forger) |
core-inference-bench.yml | dispatch (url, model, max_tokens, runs) | TTFT + decode tok/s, the number every agent budget is written against |
core-tag-help.yml | comment | answer an unrecognised agent tag with the ones that work |
core-agents-build.yml | pull_request / push to main on grpc/agents/** and the inference/ml snapshots · dispatch | build/vet/test the stdlib agent modules |
core-agent-selfheal.yml watches exactly these workflow names: core @build, core deploy, core images build, core CD, core @apply, core frontend-config, core edge-auth, and core ship (comment).
PR gates and guards
| Workflow | Triggers | Purpose |
|---|---|---|
core-pr-gate.yml | pull_request opened/synchronize/reopened/ready_for_review | the one check branch protection can require |
core-ci.yml | pull_request on operator, agent, CLI, modelrouter and appbench paths · dispatch | always-on CI |
core-compliance-gate.yml | pull_request · call (repo_subdir, core_ref) | deterministic control checks on every PR, with no model and no network |
core-license-policy.yml | pull_request · push to main · dispatch | fail a PR that adds a denied-licence dependency |
core-terraform-guard.yml | pull_request · push to main | Terraform only as the Marketplace package format |
core-snapshot-guard.yml | pull_request on the .github/*-snapshot trees, the core operator, ambassador, devgateway, grpc/go.mod/go.sum · dispatch | compile the consumers against the committed sibling snapshots |
core-vendor-guard.yml | pull_request on grpc/**, .gitignore · dispatch | prove grpc/vendor/ is complete and builds offline |
core-manifest-validate.yml | pull_request / push to main on grpc/infrastructure/apps/onhost/** · dispatch | schema-validate the on-host manifests |
core-webui-flutter.yml | pull_request / push to main on flutter/**, .github/ui-snapshot/** · dispatch | console web UI: flutter analyze + test |
core-dev-workstation.yml | pull_request / push to main on dev/workstation/** | shellcheck + pins for the developer bootstrap |
core-automerge-docs.yml | pull_request opened/reopened/synchronize/ready_for_review/converted_to_draft/labeled/unlabeled | auto-merge documentation-only PRs (no-auto-merge label opts out) |
gatekeeper.yml | pull_request · push to main | org-wide security gate: secret scan, workflow lint, credential checks, dependency review |
sovereignty.yml | pull_request · push to main | CI backstop for the sovereignty guardrail |
Scheduled drift and security
| Workflow | Triggers | Purpose |
|---|---|---|
core-security-sast.yml | cron 17 4 * * 0 · dispatch (update_baseline) | weekly SAST sweep (gosec ratchet) across core and its siblings |
core-snapshot-drift.yml | cron 23 7 * * * · rd: security-snapshot, store-snapshot, inference-snapshot, ui-snapshot, billing-snapshot, mesh-snapshot, ml-snapshot · dispatch | byte-compare the snapshots against their upstream siblings |
core-vendor-drift.yml | cron 41 7 * * * · rd: vendor-siblings · dispatch | re-vendor from the siblings’ default branches and fail on any diff |
core-crossrepo-contract.yml | cron 57 7 * * * · rd: crossrepo-contract · dispatch | check both halves of two-repo contracts |
core-images-scan.yml | dispatch (images, tag, origin) · rd: images-scan | SBOM + CVE over the node-local registry, reporting only |
Build, deliver and operate
| Workflow | Triggers | Purpose |
|---|---|---|
core-cd.yml | push to main · dispatch (images) | rebuild and roll what a merge actually changed |
core-images-build.yml | dispatch (images, tag, scan, enforce_digest, base_source) · call | werf + buildah in-cluster build to the node-local registry |
core-build.yml | comment (core @build) · dispatch (ref) | cheap build/vet check, on demand |
core-deploy.yml | dispatch (apps, build) · push of tags deploy-*, v* | production pipeline: build → mesh-ca → deploy → edge → verify |
core-deploy-comment.yml | comment (@core_ship) | build image(s) and roll what runs them |
core-apply-onhost.yml | push to main on the on-host manifests and RBAC · dispatch | apply the on-host manifests from main |
core-redeploy-base.yml | dispatch (namespace, deployment, image, health_host) | roll a base-stack app to its freshly built image |
core-bare-deploy.yml | issues opened/labeled · dispatch | provision a demo instance on the bare-metal k0s |
core-argo-sync.yml | dispatch (app) | force one Argo CD Application to reconcile now |
core-edge-tls.yml | cron */30 * * * * · dispatch · call | sovereign DNS-01 wildcard TLS for the edge |
core-edge-auth-enroll.yml | cron 17 6 * * * · dispatch · call | enroll per-host OIDC into the k0s edge |
core-frontend-config.yml | dispatch · call · workflow_run of core edge — pass-through (app-level login) | publish each app’s public UI config per host |
core-gh-app-secret.yml | dispatch | publish the GitHub App key to the in-cluster runners |
core-k0s-upgrade.yml | dispatch (mode: preflight, upgrade, verify) | self-applied k0s upgrade via an in-cluster Job |
core-ops-probe.yml | dispatch (probe) · call | read-only app-readiness diagnosis of the box |
core-verify-sweep.yml | cron */10 * * * * · dispatch | find FORGE and forged-app commits CORE has not verified |
core-verify.yml | rd: core-verify · dispatch (repo, sha) | CORE’s central CI for FORGE and every forged app (core/ci) |
core-river-iso-build.yml | dispatch | build the Runink server ISO (public base + core’s river-payload) |
core-marketplace-image.yml | dispatch | build the commercial Compute Engine image |
core-marketplace-deploy-test.yml | dispatch | boot a test VM from a CORE image, check it, delete it |
docs-deploy.yml | push to main or a PR on website/** | check that this documentation site builds (to a scratch dir; never into docs/, publishes nothing) |
face-fix-session-key.yml | dispatch | give a FaceInstance runner the shared session key |
face-unpin-runner.yml | dispatch | move a FaceInstance image off a frozen digest onto a tag |
forge-bootstrap-secrets.yml | dispatch | create forge-secrets and the envelope KEK in forge-system |
luna-bootstrap-secrets.yml | dispatch | create luna-secrets in a fresh namespace |
Things that bite
core @buildis on demand, not always-on.core-build.ymlbuilds against the live sibling repos, so it can stay green while an image built from the committed.github/security-snapshotfails. That is whatcore-snapshot-guard.ymlexists to catch.- The image scan never delays a roll.
core-images-build.ymldispatchescore-images-scan.ymland does not wait; the scan uses--exit-code 0and gates nothing. - After a CD roll, workloads are digest-pinned.
core-cd.ymlre-pins containers to:latest@<digest>and stamps therunink.org/commitlabel. A barekubectl rollout restartrestarts onto the same digest. To move a workload onto new bits, dispatchcore-cd.ymlwithimages=<img>. See Console Pages. - Commands with no caller.
core scan-sweepandcore security autoupdate(the CLI ports of the oldscan-sweep.shandsecurity-autoupdate.sh) are invoked by no workflow. The live remediation path iscore scan --fix, run by hand. - A trigger that cannot fire.
core-frontend-config.ymllistens forworkflow_runofcore edge — pass-through (app-level login), but no workflow in this directory has that name today. It runs only when dispatched or called bycore-deploy.yml.