Skip to content

MIP-0065 tasks

Ordered delivery of MIP-0065 as stacked PRs (.claude/skills/mip-tasks/SKILL.md, scripts/stack.sh). Branch mip-0065/<k>-<slug>, each based on the previous; merge bottom-up, scripts/stack.sh restack after each squash-merge.

Task 1 depends on 0064-T4 (#458), MIP-0064's last task. MIP-0064 is a chain, so that one edge blocks this whole stack until MIP-0064 is done; the edge is drawn from the column like every other (#462).

# slug delivers tests (must exist before the PR) depends on
1 hosted-runners §5.1 and §5.3: every vars.CI_RUNNER \|\| 'self-hosted' in ci.yml, site.yml, api-docs.yml, pr-body.yml, scala-steward.yml, site-health.yml and profile-activity.yml's runner: becomes ubuntu-latest. quality-other and repo-stats install Nix (nix-installer-action v23 + magic-nix-cache-action v15) and take ruff/actionlint/hadolint/shellcheck/cloc/coverage from nix develop .#lint; the runner.environment pairs, the apt-get steps and ruff-action go. The cron comments written around the desktop sleeping go. §5.2's scripts/workflow_runners.py wired into quality-other. MIP-0064's mkdocs + Kroki step in api-docs.yml verified on the hosted runner, and MIP-0064 §5.4's "the runners are self-hosted" sentence corrected scripts/workflow_runners.py --self-test (clean tree; stray self-hosted in ci.yml; a CI_RUNNER fallback; pull_request added to marola-sea-publish.yml), then the script over the real tree reports zero. §7 steps 2–4: every ci.yml path filter forced on once, tool versions printed equal nix develop .#lint --command <tool> --version, site.yml and api-docs green on ubuntu-latest with marola.dev/docs/ serving 0064-T4
2 docker-on §5.4: the DOCKER_CI gates and their comment removed from docker.yml, docker-smoke.yml, docker-local.yml; every image reference is ghcr.io/marola-dev/marola (docker-smoke.yml ×2, docker-compose.yml ×2 + comment); Dockerfile.local's hadolint failure fixed in the file or ignored with a reason, never by lowering failure-threshold hadolint Dockerfile Dockerfile.local; docker.yml green on the PR. After merge (§7 step 5): gh workflow run docker-smoke.yml and marola.dev shows a new "Last live run"; docker-local runs its benchmark gate; docker pull ghcr.io/marola-dev/marola:jvm logged out, once the package is public 1
3 workflow-fixes §5.5: gh run cancel --repo "$GITHUB_REPOSITORY" in ci-short-circuit-pr-close.yml; ghcr-retention.yml deleted; scala-steward judged on the hosted runner, with a follow-up issue if it still fails actionlint. §7 step 6: a PR closed with a run still in flight gets that run cancelled and the short-circuit job succeeds; gh workflow run scala-steward.yml finishes 1
4 ci-cd-doc docs/3-Working-on-the-repo/CI-CD.md: one row per workflow (trigger, runner, what it gates or deploys, secrets and variables, how to run it by hand), the self-hosted rule and why, the maintainer's manual settings. Rows in AGENTS.md's doc table and docs/index.md; FUTURE-WORK.md §7.2 reduced to the pointer; MIP-0065 flipped to Implemented just docs green under MIP-0064's --strict; every workflow file in .github/workflows/ has a row (checked by listing, in the PR) 2, 3

Decisions

  1. The guard ships with the move, not before it. Wired into quality-other on its own, it would fail main on the nine jobs it exists to forbid.
  2. The maintainer's settings sit between tasks 1 and 2: relabel the desktop runner marola-sea only, set fork PR approval to "Require approval for all external contributors", delete the CI_RUNNER variable. Making marola-dev's marola package public follows task 2's first push, since a package does not exist until something pushes it.
  3. Tasks 2 and 3 are independent of each other; both need only task 1. Stacked 1 → 2 → 3 for review order, but depends on says the real graph.