|
| 1 | +name: lock |
| 2 | + |
| 3 | +on: |
| 4 | + workflow_call: |
| 5 | + inputs: |
| 6 | + key: |
| 7 | + description: "Key to lock (e.g., dev, staging, prod)" |
| 8 | + required: true |
| 9 | + type: string |
| 10 | + key_owner: |
| 11 | + description: "Key owner identifier (e.g., PR number, SHA, run ID)" |
| 12 | + required: true |
| 13 | + type: string |
| 14 | + job_name: |
| 15 | + description: "Custom name for the lock job" |
| 16 | + required: false |
| 17 | + type: string |
| 18 | + |
| 19 | +permissions: |
| 20 | + contents: write |
| 21 | + |
| 22 | +jobs: |
| 23 | + lock: |
| 24 | + name: ${{ inputs.job_name || 'lock' }} |
| 25 | + runs-on: ubuntu-latest |
| 26 | + steps: |
| 27 | + - name: Define lock check function |
| 28 | + shell: bash |
| 29 | + run: | |
| 30 | + # Define reusable function for lock ownership checking |
| 31 | + cat << 'EOF' > lock_check_function.sh |
| 32 | + check_lock() { |
| 33 | + # Parse named parameters |
| 34 | + while [[ "$#" -gt 0 ]]; do |
| 35 | + case $1 in |
| 36 | + --key) key="$2"; shift ;; |
| 37 | + --key-owner) key_owner="$2"; shift ;; |
| 38 | + --lock-reason) lock_reason="$2"; shift ;; |
| 39 | + --locked) locked="$2"; shift ;; |
| 40 | + --require-owned) require_owned="$2"; shift ;; |
| 41 | + *) echo "Unknown parameter passed: $1"; return 1 ;; |
| 42 | + esac |
| 43 | + shift |
| 44 | + done |
| 45 | +
|
| 46 | + echo "Key: $key" |
| 47 | + echo "Key owner: $key_owner" |
| 48 | + echo "Lock reason: $lock_reason" |
| 49 | + echo "Locked: $locked" |
| 50 | +
|
| 51 | + local should_proceed=false |
| 52 | + local is_owned_by_us=false |
| 53 | +
|
| 54 | + if [ "$locked" = "true" ]; then |
| 55 | + echo "Lock exists, checking owner..." |
| 56 | + local lock_owner=$(echo "$lock_reason" | grep -o 'owner:[^,]*' | cut -d: -f2 || true) |
| 57 | + echo "Lock owner: $lock_owner" |
| 58 | + echo "Current owner: $key_owner" |
| 59 | + if [ "$lock_owner" = "$key_owner" ]; then |
| 60 | + echo "✓ Lock is held by this owner" |
| 61 | + should_proceed=true |
| 62 | + is_owned_by_us=true |
| 63 | + elif [ -z "$lock_owner" ]; then |
| 64 | + echo "✓ Lock is available (no owner)" |
| 65 | + should_proceed=true |
| 66 | + is_owned_by_us=false |
| 67 | + else |
| 68 | + echo "✗ Lock is held by $lock_owner" |
| 69 | + should_proceed=false |
| 70 | + is_owned_by_us=false |
| 71 | + echo "::error::Key '$key' is locked by $lock_owner" |
| 72 | + return 1 |
| 73 | + fi |
| 74 | + else |
| 75 | + echo "✓ Key is not locked" |
| 76 | + should_proceed=true |
| 77 | + is_owned_by_us=false |
| 78 | + fi |
| 79 | +
|
| 80 | + echo "should_proceed=$should_proceed" >> $GITHUB_OUTPUT |
| 81 | + echo "is_owned_by_us=$is_owned_by_us" >> $GITHUB_OUTPUT |
| 82 | +
|
| 83 | + # Validate ownership requirement if specified |
| 84 | + if [ "$require_owned" = "true" ] && [ "$is_owned_by_us" != "true" ]; then |
| 85 | + echo "::error::Lock ownership is required but not achieved" |
| 86 | + return 1 |
| 87 | + fi |
| 88 | + } |
| 89 | + EOF |
| 90 | +
|
| 91 | + # Check lock state |
| 92 | + - name: Get lock state |
| 93 | + uses: github/lock@9a5898804aedcdfb43592ed16b6457768d048183 # v3.0.1 |
| 94 | + id: get-lock-state |
| 95 | + with: |
| 96 | + mode: "check" |
| 97 | + environment: ${{ inputs.key }} |
| 98 | + |
| 99 | + - name: Check lock state |
| 100 | + id: check-lock |
| 101 | + shell: bash |
| 102 | + run: | |
| 103 | + source ./lock_check_function.sh |
| 104 | + check_lock \ |
| 105 | + --key "${{ inputs.key }}" \ |
| 106 | + --key-owner "${{ inputs.key_owner }}" \ |
| 107 | + --lock-reason "${{ steps.get-lock-state.outputs.reason }}" \ |
| 108 | + --locked "${{ steps.get-lock-state.outputs.locked }}" |
| 109 | +
|
| 110 | + # Lock |
| 111 | + - name: Prepare lock reason |
| 112 | + id: lock-reason |
| 113 | + run: | |
| 114 | + # Simple reason with owner information |
| 115 | + REASON="owner:${{ inputs.key_owner }}" |
| 116 | + echo "Lock reason: $REASON" |
| 117 | + echo "reason=$REASON" >> $GITHUB_OUTPUT |
| 118 | + if: steps.check-lock.outputs.should_proceed == 'true' |
| 119 | + |
| 120 | + - name: Lock |
| 121 | + uses: github/lock@9a5898804aedcdfb43592ed16b6457768d048183 # v3.0.1 |
| 122 | + id: lock |
| 123 | + with: |
| 124 | + mode: "lock" |
| 125 | + environment: ${{ inputs.key }} |
| 126 | + reason: ${{ steps.lock-reason.outputs.reason }} |
| 127 | + if: steps.check-lock.outputs.should_proceed == 'true' |
| 128 | + |
| 129 | + - name: Wait for lock to propagate |
| 130 | + shell: bash |
| 131 | + run: | |
| 132 | + echo "Waiting for lock to propagate..." |
| 133 | + sleep 1 |
| 134 | +
|
| 135 | + # Recheck lock state after lock |
| 136 | + - name: Get lock state for recheck |
| 137 | + uses: github/lock@9a5898804aedcdfb43592ed16b6457768d048183 # v3.0.1 |
| 138 | + id: get-lock-state-for-recheck |
| 139 | + with: |
| 140 | + mode: "check" |
| 141 | + environment: ${{ inputs.key }} |
| 142 | + |
| 143 | + - name: Recheck lock state |
| 144 | + id: recheck-lock |
| 145 | + shell: bash |
| 146 | + if: steps.lock.outcome == 'success' |
| 147 | + run: | |
| 148 | + source ./lock_check_function.sh |
| 149 | + check_lock \ |
| 150 | + --key "${{ inputs.key }}" \ |
| 151 | + --key-owner "${{ inputs.key_owner }}" \ |
| 152 | + --lock-reason "${{ steps.get-lock-state-for-recheck.outputs.reason }}" \ |
| 153 | + --locked "${{ steps.get-lock-state-for-recheck.outputs.locked }}" \ |
| 154 | + --require-owned true |
| 155 | +
|
| 156 | + - name: Final lock status |
| 157 | + if: always() |
| 158 | + run: | |
| 159 | + echo "=== Lock Result ===" |
| 160 | + echo "Key: ${{ inputs.key }}" |
| 161 | + echo "Owner: ${{ inputs.key_owner }}" |
| 162 | + echo "Status: ${{ steps.lock.outcome }}" |
| 163 | + echo "Verified ownership: ${{ steps.recheck-lock.outputs.is_owned_by_us || 'N/A' }}" |
0 commit comments