Skip to content

ci(e2e): identify PR gate controller runs by exact revision #7860

Description

@cjagwani

Summary

Trusted PR E2E controller runs triggered by workflow_run or workflow_dispatch are named only E2E Gate <event> <run-id>. During v0.0.97 release validation, simultaneous controller runs for PRs #7778 and #7811 were indistinguishable in the Actions list without opening each run. The manual approval run also omitted the supplied PR number, head SHA, and base SHA from its display name.

Evidence

  • Release gate run #30449082998 and nearby controller runs used the generic workflow-run name.
  • Manual approval run #30449149188 used the generic workflow-dispatch name.
  • The controller already receives exact PR/head/base identity for both events and binds execution to those values.
  • .github/workflows/pr-e2e-gate.yaml exposes exact identity only for pull_request_target; its fallback run name uses only event name and run ID.

Expected behavior

Every PR gate controller run should expose the PR number and base revision in the Actions list before an operator opens it. The display name is diagnostic only and must not weaken the existing authenticated identity checks.

Acceptance criteria

  • workflow_run display names include the source PR number, source head SHA, and source base SHA.
  • workflow_dispatch approval display names include the supplied PR number, expected head SHA, and expected base SHA.
  • pull_request_target naming remains exact-revision aware.
  • Names distinguish coordination, approval, and close events without exposing review reasons or secrets.
  • Focused workflow contract tests cover all trigger-specific identity expressions.
  • Maintainer documentation points operators to the identity-bearing run name when coordinating or diagnosing E2E.

Scope

This changes internal CI observability only. It does not change E2E authorization, dispatch, or product behavior.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: ciCI workflows, checks, release automation, or GitHub Actionsarea: e2eEnd-to-end tests, nightly failures, or validation infrastructurearea: observabilityLogging, metrics, tracing, diagnostics, or debug output

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions