Skip to content

[WoA] Add manual cross-repository broker - #3025

Open
isVoid wants to merge 2 commits into
mainfrom
codex/woa-xrepo-public-manual-broker
Open

isVoid wants to merge 2 commits into
mainfrom
codex/woa-xrepo-public-manual-broker

Conversation

@isVoid

@isVoid isVoid commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Description

Tracks https://github.com/NVIDIA-dev/cuda-python-private/issues/584.

This is public PR A of the four-PR WoA cross-repository CI rollout. It adds two manually dispatched brokers and enables no automatic main trigger:

  • a transport-smoke broker that resolves an open same-repository PR head and dispatches the private smoke endpoint; and
  • an exact-run broker that validates one successful public main CI run, its producer jobs, SHA ancestry, artifact names, IDs, and server digests before dispatching private validation.

The private-dispatch App credential is referenced only by isolated jobs with permissions: {}. Those jobs do not check out source or download artifacts.

Depends on private foundation PR https://github.com/NVIDIA-dev/cuda-python-private/pull/650.

Rollout

After both foundation PRs merge:

  1. Run WoA cross-repository transport smoke against a public draft PR and verify cuda-python WoA integration / transport smoke completes neutral without a GB10 job.
  2. Run WoA exact public-main dispatch with known eligible run 37333876562 and verify the canonical check plus the minimal GB10 import test.
  3. Repeat with one deliberately invalid claim and verify failure occurs before GB10 allocation.

Validation

  • actionlint passes for both added workflows.
  • git diff --check passes.
  • Live read-only metadata validation found the exact expected Windows Arm64 artifact set on run 37333876562.
  • Execute both cross-repository smoke paths after merge.

Checklist

  • New or existing tests cover these changes where they can run before merge.
  • The design document is up to date with these changes.

@copy-pr-bot

copy-pr-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions github-actions Bot added the CI/CD CI/CD infrastructure label Oct 5, 2026
@isVoid
isVoid marked this pull request as ready for review October 6, 2026 18:25
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

📝 Summary

Summary by CodeRabbit

  • Chores
    • Added manually triggered checks for WoA cross-repository transport and private validation. The checks verify eligible pull requests or successful public CI runs, including required Windows Arm64 results and artifact integrity, before dispatching validation.
    • Added confirmation that the dispatched run is on the expected private repository and branch.

Walkthrough

Adds two manually triggered workflows that validate public pull request or CI-run data, dispatch private WoA workflows on ctk-next, and verify the returned workflow runs.

Changes

Cross-repository PR smoke

Layer / File(s) Summary
Resolve and validate pull request
.github/workflows/woa-crossrepo-smoke.yml
Accepts a PR number only when the PR is open, targets main, comes from the expected repository, and has a valid head SHA.
Dispatch and verify private smoke run
.github/workflows/woa-crossrepo-smoke.yml
Creates a scoped token, dispatches the private workflow on ctk-next, and verifies the returned run identity and trigger fields.

Private WoA validation

Layer / File(s) Summary
Validate public run and artifacts
.github/workflows/woa-private-dispatch.yml
Checks the public CI run, commit position, producer job, and three expected unexpired artifacts, then exports the resolved values.
Dispatch and verify private validation
.github/workflows/woa-private-dispatch.yml
Creates a scoped token, dispatches private validation on ctk-next with the run and artifact data, and verifies the returned run.

Priority: ⬇️ Low

Change: Feature

Merge Risk: 🟡 Moderate · up to eb4ad

The new brokers can be run from any branch, and a modified branch could obtain write access to the private repository's Actions. Gate the dispatch credential behind a main-only protected environment before merging.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/woa-private-dispatch.yml (1)

67-83: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

suggestion: Derive the CUDA build version from ci/versions.yml at public_sha. Do not hard-code 13.4.2.

Two values are fixed to 13.4.2:

  • the producer job name Build win-arm64, CUDA 13.4.2 / py3.13;
  • the artifact name cuda-bindings-python313-cuda13.4.2-win-arm64-<sha>.

In .github/workflows/ci.yml, both values come from .cuda.build.version (Lines 224-242 and 444-467). After the next CUDA version bump, this broker will reject every valid public run until someone edits this file. The failure is safe, but the broker becomes unusable.

Fix: read ci/versions.yml at public_sha with gh api repos/NVIDIA/cuda-python/contents/ci/versions.yml?ref=$public_sha. Then build the job name and the artifact names from .cuda.build.version.


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/cuda-python/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 3bdf7831-9285-4563-bf65-3d0b14907b12
📥 Commits

Reviewing files that changed from the base of the PR and between 669e608 and eb4adea.

📒 Files selected for processing (2)
  • .github/workflows/woa-crossrepo-smoke.yml
  • .github/workflows/woa-private-dispatch.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.

Comment on lines +125 to +139
dispatch-private-validation:
needs: resolve-public-build
runs-on: ubuntu-latest
timeout-minutes: 10
permissions: {}
steps:
- name: Create private dispatch token
id: private-app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }}
private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }}
owner: NVIDIA-dev
repositories: cuda-python-private
permission-actions: write

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

important: Put the private-dispatch App key behind a protected environment.

dispatch-private-validation has no environment:. As a result, CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY is a repository-level or organization-level secret. A user with write access can push a branch that changes this workflow and dispatch it from that branch.

The modified workflow can then mint an actions: write token for NVIDIA-dev/cuda-python-private. That token can:

  • dispatch arbitrary workflows, including GB10 jobs;
  • cancel runs;
  • delete runs, logs, and artifacts.

All checks in resolve-public-build run from the dispatched ref, so a modified branch can bypass all of them. An if: github.ref == 'refs/heads/main' guard does not help for the same reason.

Fix:

  • Move the secret, and optionally the client ID variable, to an environment.
  • Set that environment's deployment branch policy to main only.
  • Reference the environment from this job.
   dispatch-private-validation:
     needs: resolve-public-build
     runs-on: ubuntu-latest
     timeout-minutes: 10
+    environment: woa-private-dispatch
     permissions: {}

Apply the same change to the dispatch job in woa-crossrepo-smoke.yml. That job uses the same credential pattern.

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
dispatch-private-validation:
needs: resolve-public-build
runs-on: ubuntu-latest
timeout-minutes: 10
permissions: {}
steps:
- name: Create private dispatch token
id: private-app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }}
private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }}
owner: NVIDIA-dev
repositories: cuda-python-private
permission-actions: write
dispatch-private-validation:
needs: resolve-public-build
runs-on: ubuntu-latest
timeout-minutes: 10
environment: woa-private-dispatch
permissions: {}
steps:
- name: Create private dispatch token
id: private-app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
client-id: ${{ vars.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_CLIENT_ID }}
private-key: ${{ secrets.CUDA_PYTHON_WOA_XREPO_CI_PRIVATE_APP_PRIVATE_KEY }}
owner: NVIDIA-dev
repositories: cuda-python-private
permission-actions: write

Source: Path instructions

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@isVoid isVoid self-assigned this Oct 7, 2026
@isVoid isVoid added the feature New feature or request label Oct 7, 2026
@isVoid isVoid added this to the cuda.core next milestone Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI/CD CI/CD infrastructure feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant