Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
self-hosted-runner:
labels:
- blacksmith-6vcpu-macos-latest
- tailscale-mutation
10 changes: 5 additions & 5 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ concurrency:
jobs:
test:
name: Test (macOS)
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 20
steps:
- name: Check out repository
Expand Down Expand Up @@ -47,7 +47,7 @@ jobs:

lint:
name: golangci-lint
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 10
steps:
- name: Check out repository
Expand All @@ -65,7 +65,7 @@ jobs:

vulnerability-scan:
name: govulncheck
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 10
steps:
- name: Check out repository
Expand All @@ -80,7 +80,7 @@ jobs:

workflow-lint:
name: actionlint
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 5
steps:
- name: Check out repository
Expand All @@ -97,7 +97,7 @@ jobs:

release-check:
name: GoReleaser check and snapshot
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 15
steps:
- name: Check out repository
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/privileged-macos-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
lifecycle:
name: Privileged lifecycle (ephemeral macOS)
if: inputs.confirm == 'RUN-PRIVILEGED-PORTLESS'
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
environment: privileged-macos-integration
timeout-minutes: 15
steps:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ concurrency:
jobs:
validate:
name: Validate tag
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 20
steps:
- name: Check out repository
Expand Down Expand Up @@ -56,7 +56,7 @@ jobs:
release:
name: Publish release
needs: validate
runs-on: macos-15
runs-on: blacksmith-6vcpu-macos-latest
timeout-minutes: 20
permissions:
attestations: write
Expand Down
5 changes: 3 additions & 2 deletions docs/pki-service.md
Original file line number Diff line number Diff line change
Expand Up @@ -141,8 +141,9 @@ trust store, or write `/etc/hosts`.
The manual `Privileged macOS integration` workflow covers the provisioned
lifecycle that is unsafe on developer machines and ordinary CI. It requires the
exact dispatch confirmation `RUN-PRIVILEGED-PORTLESS`, uses the dedicated
`privileged-macos-integration` environment, runs only on a fresh GitHub-hosted
macOS runner, rejects pre-existing Portless artifacts, and exercises real
`privileged-macos-integration` environment, runs only on a fresh
Blacksmith-hosted Apple Silicon macOS runner, rejects pre-existing Portless
artifacts, and exercises real
`init`, idempotent install/upgrade, launchd, system CA trust, HTTPS routing on
port 443 with both privileged listeners bound, and uninstall. Repository
administrators can add required
Expand Down
2 changes: 1 addition & 1 deletion go.mod
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
module github.com/euforicio/portless

go 1.26.5
go 1.26.6

require golang.org/x/sys v0.47.0