diff --git a/.github/workflows/drift-to-issue.yml b/.github/workflows/drift-to-issue.yml index 984edb4..6fa85c3 100644 --- a/.github/workflows/drift-to-issue.yml +++ b/.github/workflows/drift-to-issue.yml @@ -8,6 +8,11 @@ name: Drift to issue # # Only fires on main / scheduled runs, not on PRs (we don't want every PR # to open issues — the in-PR annotation from harness.yml is enough there). +# +# Every Harness job sets continue-on-error: true, so the Harness *run* +# concludes `success` even when a sensor fails. Don't gate on +# workflow_run.conclusion — the per-job conclusions from the jobs API are +# the only place a failed sensor shows up (as `failure`). on: workflow_run: @@ -21,12 +26,14 @@ permissions: jobs: open-or-update-issue: + # `branches:` above matches the Harness run's head branch, which a fork + # PR from `:main` also satisfies — exclude PR runs explicitly. + if: github.event.workflow_run.event != 'pull_request' runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Find failed jobs and (re)open issues - if: github.event.workflow_run.conclusion == 'failure' env: GH_TOKEN: ${{ github.token }} RUN_ID: ${{ github.event.workflow_run.id }} @@ -79,6 +86,14 @@ jobs: ) print(f"updated #{num}: {title}") else: + # `gh issue create --label` fails if the label doesn't exist + # yet; --force makes this an idempotent create-or-update. + subprocess.run( + ["gh", "label", "create", "harness-drift", "--force", + "--color", "d93f0b", + "--description", "Tracking issue opened by drift-to-issue.yml"], + check=True, + ) subprocess.run( ["gh", "issue", "create", "--title", title, "--body", body, "--label", "harness-drift"],