CI: Switch to merge request pipelines

Switch PyTango from branch pipelines to merge request pipelines, so that rules: can see the merge request metadata: labels, title, target branch. Today none of that exists, because a branch pipeline knows nothing about the merge request it belongs to.

What changes

  • New workflow:rules: a merge request pipeline for every open MR, a branch pipeline only for a branch with no open MR, plus tags and schedules. A push therefore never creates two pipelines for the same commit, and pushing a branch without an MR still gives CI, as today.
  • The $CI_PIPELINE_SOURCE != "merge_request_event" fallbacks of .rules-wheel and .test-pixi become plain when: manual, so the wheels and the pixi jobs stay manual on merge request pipelines exactly as they are on branch pipelines. Nothing new starts automatically because of this MR.
  • linux:test-main-cpptango no longer excludes merge request pipelines; it stays manual there.
  • $CI_COMMIT_BRANCH is not set in a merge request pipeline, so the two places that key off the branch name now also look at $CI_MERGE_REQUEST_SOURCE_BRANCH_NAME: the *windows* branch trick in .windows-gitlab-ci.yml, and the valgrind check of linux:test-source.
  • interruptible: true by default (the publishing jobs opt out), so a new push supersedes the pipeline of the previous one. Separate commit, easy to drop if you prefer to keep every pipeline running.

Project settings to flip alongside

  • Settings > CI/CD > General pipelines: Auto-cancel redundant pipelines must stay on, otherwise interruptible does nothing. It is on today.
  • Optional: Run pipelines for merge requests from forks in this project, so fork contributions get CI on our runners. Merge request pipelines never receive protected variables, so the PyPI token stays out of reach.

Not included

  • Merged results pipelines and merge trains are Premium features, so we keep detached pipelines: jobs still test the source branch, not the merge result.
  • Follow-up worth doing once this and !1040 (merged) are in: with merge request pipelines rules:changes compares against the target branch, so the docs-only detection can become automatic (changes: [doc/**/*]), with the label left as a manual override.

Verified on this MR

  • Pushing to the open MR created a merge request pipeline only, no branch pipeline for the same commit.
  • The merge request pipeline of the previous push was auto-cancelled, so interruptible: true takes effect right away.
  • With the Only docs label of !1040 (merged) set, the five linux:test-source jobs were created as manual: pipeline 2805180382. That is the part that cannot work without this MR.

test-docs fails until !1043 (merged) is merged: the doc build is broken on develop itself.

Edited by Yury Matveev

Merge request reports

Loading
Loading