Skip to content

CI: run push workflows on master only, stop duplicate PR runs - #934

Merged
bniwredyc merged 1 commit into
masterfrom
ci-push-on-master-only
Sep 28, 2026
Merged

bniwredyc merged 1 commit into
masterfrom
ci-push-on-master-only

Conversation

@bniwredyc

Copy link
Copy Markdown
Contributor

Why

Workflows currently trigger on both push (all branches) and pull_request. For a PR whose branch lives in this repo, GitHub fires both events for the same commit, so each workflow runs twice per push — the push run plus the PR run. This showed up as PR #484 showing 6 checks while fork-based PR #478 showed 2 (fork pushes run workflows in the fork, so the base repo only ever saw the pull_request run).

The duplicate push run adds no signal — it runs the exact same commit.

Change

pull_request becomes the only source of PR checks; push CI happens only on master:

  • .github/workflows/build-deploy.yml: push: branches: ["**"] + tags: v* → push: branches: [master]
  • .github/workflows/markdown-lint.yml: bare push: (all branches) → push: branches: [master]

pull_request, workflow_dispatch, jobs, steps, and check names are untouched. crowdin.yml already ran on master only — unchanged. The same change is being applied across all AdGuard knowledge bases (KnowledgeBaseDNS, KnowledgeBaseVPN, KnowledgeBaseMail, KnowledgeBaseWallet).

Effect

  • Every PR — same-repo or fork — shows the same checks; no more doubled runs
  • Deploys run exactly once per master push (prod deploy), instead of racing with a duplicate run
  • ~Half the Actions minutes spent on same-repo PR branches

Please note (deliberate trade-offs, approved)

  • Per-branch preview URLs from topic branches are dropped. PR previews continue to work: pushing to a PR branch triggers the pull_request run, which still builds and deploys a pull-request-<N> preview with a comment link. What goes away is CI/preview for pushes to branches that have no PR yet (e.g. grabbing a preview URL before opening a PR) — open the PR and everything works. Speak up if you relied on that.
  • v* tag builds/deploys are dropped. Tag pushes no longer trigger build-deploy. If release tags should build/deploy, say so and we'll add tags: [v*] back.
  • Pushing to an open same-repo PR now runs CI exactly once instead of twice, so the push no longer also lands as a second set of checks.

Restrict the push trigger to master in build-deploy and markdown-lint
workflows. pull_request stays the only source of PR checks, so
same-repo PRs no longer run each workflow twice per push (push run +
PR run), which showed up as 6 checks for same-repo PRs vs 2 for fork
PRs. Deploys now run once per master push; per-branch preview deploys
from topic branches and v* tag builds are dropped.
@github-actions

Copy link
Copy Markdown

Preview was deployed to: https://pull-request-934.kb-adg.pages.dev/

@bniwredyc
bniwredyc merged commit 8443dbf into master Sep 28, 2026
3 checks passed
@bniwredyc
bniwredyc deleted the ci-push-on-master-only branch September 28, 2026 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants