MIP-0065 tasks¶
Ordered delivery of MIP-0065 as stacked PRs
(.claude/skills/mip-tasks/SKILL.md, scripts/stack.sh). Branch mip-0065/<k>-<slug>, each based
on the previous; merge bottom-up, scripts/stack.sh restack after each squash-merge.
Task 1 depends on 0064-T4 (#458), MIP-0064's last task. MIP-0064 is a chain, so that one edge
blocks this whole stack until MIP-0064 is done; the edge is drawn from the column like every other
(#462).
| # | slug | delivers | tests (must exist before the PR) | depends on |
|---|---|---|---|---|
| 1 | hosted-runners | §5.1 and §5.3: every vars.CI_RUNNER \|\| 'self-hosted' in ci.yml, site.yml, api-docs.yml, pr-body.yml, scala-steward.yml, site-health.yml and profile-activity.yml's runner: becomes ubuntu-latest. quality-other and repo-stats install Nix (nix-installer-action v23 + magic-nix-cache-action v15) and take ruff/actionlint/hadolint/shellcheck/cloc/coverage from nix develop .#lint; the runner.environment pairs, the apt-get steps and ruff-action go. The cron comments written around the desktop sleeping go. §5.2's scripts/workflow_runners.py wired into quality-other. MIP-0064's mkdocs + Kroki step in api-docs.yml verified on the hosted runner, and MIP-0064 §5.4's "the runners are self-hosted" sentence corrected |
scripts/workflow_runners.py --self-test (clean tree; stray self-hosted in ci.yml; a CI_RUNNER fallback; pull_request added to marola-sea-publish.yml), then the script over the real tree reports zero. §7 steps 2–4: every ci.yml path filter forced on once, tool versions printed equal nix develop .#lint --command <tool> --version, site.yml and api-docs green on ubuntu-latest with marola.dev/docs/ serving |
0064-T4 |
| 2 | docker-on | §5.4: the DOCKER_CI gates and their comment removed from docker.yml, docker-smoke.yml, docker-local.yml; every image reference is ghcr.io/marola-dev/marola (docker-smoke.yml ×2, docker-compose.yml ×2 + comment); Dockerfile.local's hadolint failure fixed in the file or ignored with a reason, never by lowering failure-threshold |
hadolint Dockerfile Dockerfile.local; docker.yml green on the PR. After merge (§7 step 5): gh workflow run docker-smoke.yml and marola.dev shows a new "Last live run"; docker-local runs its benchmark gate; docker pull ghcr.io/marola-dev/marola:jvm logged out, once the package is public |
1 |
| 3 | workflow-fixes | §5.5: gh run cancel --repo "$GITHUB_REPOSITORY" in ci-short-circuit-pr-close.yml; ghcr-retention.yml deleted; scala-steward judged on the hosted runner, with a follow-up issue if it still fails |
actionlint. §7 step 6: a PR closed with a run still in flight gets that run cancelled and the short-circuit job succeeds; gh workflow run scala-steward.yml finishes |
1 |
| 4 | ci-cd-doc | docs/3-Working-on-the-repo/CI-CD.md: one row per workflow (trigger, runner, what it gates or deploys, secrets and variables, how to run it by hand), the self-hosted rule and why, the maintainer's manual settings. Rows in AGENTS.md's doc table and docs/index.md; FUTURE-WORK.md §7.2 reduced to the pointer; MIP-0065 flipped to Implemented |
just docs green under MIP-0064's --strict; every workflow file in .github/workflows/ has a row (checked by listing, in the PR) |
2, 3 |
Decisions¶
- The guard ships with the move, not before it. Wired into
quality-otheron its own, it would failmainon the nine jobs it exists to forbid. - The maintainer's settings sit between tasks 1 and 2: relabel the desktop runner
marola-seaonly, set fork PR approval to "Require approval for all external contributors", delete theCI_RUNNERvariable. Makingmarola-dev'smarolapackage public follows task 2's first push, since a package does not exist until something pushes it. - Tasks 2 and 3 are independent of each other; both need only task 1. Stacked 1 → 2 → 3 for
review order, but
depends onsays the real graph.