diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml index 6355c01..0b204b4 100644 --- a/.github/actionlint.yaml +++ b/.github/actionlint.yaml @@ -1,3 +1,4 @@ self-hosted-runner: labels: + - blacksmith-6vcpu-macos-latest - tailscale-mutation diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 31541d4..d298ead 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,7 +17,7 @@ concurrency: jobs: test: name: Test (macOS) - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 20 steps: - name: Check out repository @@ -47,7 +47,7 @@ jobs: lint: name: golangci-lint - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 10 steps: - name: Check out repository @@ -65,7 +65,7 @@ jobs: vulnerability-scan: name: govulncheck - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 10 steps: - name: Check out repository @@ -80,7 +80,7 @@ jobs: workflow-lint: name: actionlint - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 5 steps: - name: Check out repository @@ -97,7 +97,7 @@ jobs: release-check: name: GoReleaser check and snapshot - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 15 steps: - name: Check out repository diff --git a/.github/workflows/privileged-macos-integration.yml b/.github/workflows/privileged-macos-integration.yml index 4d28e85..1cf2a65 100644 --- a/.github/workflows/privileged-macos-integration.yml +++ b/.github/workflows/privileged-macos-integration.yml @@ -15,7 +15,7 @@ jobs: lifecycle: name: Privileged lifecycle (ephemeral macOS) if: inputs.confirm == 'RUN-PRIVILEGED-PORTLESS' - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest environment: privileged-macos-integration timeout-minutes: 15 steps: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8cd7b43..076494f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -14,7 +14,7 @@ concurrency: jobs: validate: name: Validate tag - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 20 steps: - name: Check out repository @@ -56,7 +56,7 @@ jobs: release: name: Publish release needs: validate - runs-on: macos-15 + runs-on: blacksmith-6vcpu-macos-latest timeout-minutes: 20 permissions: attestations: write diff --git a/docs/pki-service.md b/docs/pki-service.md index a87cd2c..d64e06f 100644 --- a/docs/pki-service.md +++ b/docs/pki-service.md @@ -141,8 +141,9 @@ trust store, or write `/etc/hosts`. The manual `Privileged macOS integration` workflow covers the provisioned lifecycle that is unsafe on developer machines and ordinary CI. It requires the exact dispatch confirmation `RUN-PRIVILEGED-PORTLESS`, uses the dedicated -`privileged-macos-integration` environment, runs only on a fresh GitHub-hosted -macOS runner, rejects pre-existing Portless artifacts, and exercises real +`privileged-macos-integration` environment, runs only on a fresh +Blacksmith-hosted Apple Silicon macOS runner, rejects pre-existing Portless +artifacts, and exercises real `init`, idempotent install/upgrade, launchd, system CA trust, HTTPS routing on port 443 with both privileged listeners bound, and uninstall. Repository administrators can add required diff --git a/go.mod b/go.mod index 1f42a49..a81117a 100644 --- a/go.mod +++ b/go.mod @@ -1,5 +1,5 @@ module github.com/euforicio/portless -go 1.26.5 +go 1.26.6 require golang.org/x/sys v0.47.0