ci: a stable release waits for a green E2E run on a real Home Assistant

The stable gate proved Validate and Full Performance on the exact SHA but
never ran the release in Home Assistant itself. houseplan-e2e installs
the release's houseplan.zip — the bytes HACS ships — into HA in docker
and walks the sidebar page, dashboards, roles, PDF, restart and the
stable→tag upgrade. release.yml now dispatches e2e.yml on the tag for
`!prerelease` releases and waits for it (scripts/e2e-gate.mjs, modelled
on validate-gate.mjs): the gate recognises its own run by `HP <tag>` in
the job names, ignores foreign dispatches, and reports red / missing /
cancelled / token error with the run link. Betas are untouched.

Mutants: release-ships-on-red-e2e, release-trusts-foreign-e2e-run.

Issue: #514
User-Visible: no
This commit is contained in:
Codex
2026-09-09 21:18:51 +00:00
committed by claude[bot]
parent d20ef60037
commit c50458a098
9 changed files with 309 additions and 3 deletions
+14
View File
@@ -50,6 +50,20 @@ jobs:
set -euo pipefail
SHA=$(git rev-parse HEAD)
node scripts/release-gate.mjs "$SHA" --workflow=performance.yml --label="Полные бенчмарки производительности"
# #514: the only check on a real Home Assistant. houseplan-e2e installs
# the release's houseplan.zip — the bytes HACS ships — into HA in docker
# and walks the sidebar page, dashboards, roles, PDF, restart and the
# stable→tag upgrade. A red, missing or cancelled run withholds the
# assets exactly like Full Performance. Cross-repository dispatch needs a
# token with Actions: write on houseplan-e2e; HP_PROCESS_TOKEN (classic,
# repo scope) has it, E2E_DISPATCH_TOKEN is the fallback for a
# fine-grained token.
- name: Require green E2E on a real Home Assistant for a stable release
if: ${{ !github.event.release.prerelease }}
env:
GH_TOKEN: ${{ secrets.E2E_DISPATCH_TOKEN || secrets.HP_PROCESS_TOKEN }}
TAG: ${{ github.event.release.tag_name }}
run: node scripts/e2e-gate.mjs --tag="$TAG"
build:
name: Сборка бандла и загрузка ассетов
needs: gate