feat: add release-tests orchestrator workflow (test-all.yml) - #209
Merged
Merged
Conversation
Adds three workflows: - test-unit.yml: reusable workflow for unit tests - test-build-package.yml: reusable workflow for build-package integration test - release-tests.yml: orchestrator that runs all tests in order (unit → build-package → all-types) with fail-fast Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Elizabeth Maher (EMaher)
force-pushed
the
emaher-feat-release-test-workflow
branch
from
July 1, 2026 19:44
7ee4487 to
d1a968b
Compare
Move id-token: write from workflow-level to the two integration job calls that need OIDC login. The ci job no longer receives it, satisfying least-privilege while keeping OIDC working. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Peter Hauge (petehauge)
approved these changes
Jul 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a
Test: Release Testsorchestrator workflow that runs all test suites sequentially before a release, with fail-fast behavior. Also runs monthly on a cron schedule.Execution Order
ci.yml)test-round-trip.yml)test-redact-secrets.yml)Each step requires the previous to pass. If any stage fails, subsequent stages are skipped.
Changes
ci.yml: Addedworkflow_calltrigger so it can be reused by the orchestratortest-all.yml(new): Orchestrator workflow (manual dispatch + monthly cron) that chains all tests in ordertest-round-trip.yml(renamed fromintegration-test.yml): Removedsecrets:contract fromworkflow_call, added "Validate Required Secrets" and "Validate Azure Region" pre-flight steps, madeAPIM_PUBLISHER_EMAILoptional, usedchoicetype for inputs, extracted defaults intoenv:variablestest-redact-secrets.yml(renamed fromintegration-redact-secrets.yml): Same simplifications as aboveSKILL.md: Updated prerequisites documentation for the new workflow architectureKey Design Decisions
environment: integration-testdeclaration — no secret pass-through from the orchestratorvars.DEFAULT_*repo variables are used for configurable defaults in the orchestrator (with hardcoded fallbacks)if: github.ref == 'refs/heads/main'guards ensure integration tests only run from main