ci: migrate all workflows to Ubicloud (Linux + Windows, 8-core)

Switch every `runs-on` in this repo to Ubicloud so CI has a single billing
surface, consistent capacity, and 4x more cores on the workloads that were
previously stuck on free `ubuntu-latest` (2 cores). Windows uses Ubicloud's
Windows pool too — `ubicloud-standard-8-windows` — so the queued-forever
problem with GitHub's `windows-latest-8-cores` paid larger runner (org-level
larger-runner billing not enabled) goes away.

Workflows touched (9):
- evals.yml, evals-periodic.yml, ci-image.yml — bump default + matrix from
  `ubicloud-standard-2` to `ubicloud-standard-8`. The one matrix entry that
  was already on -8 stays.
- windows-free-tests.yml — `ubicloud-standard-2-windows` → `ubicloud-standard-8-windows`.
- make-pdf-gate.yml — matrix `ubuntu-latest` → `ubicloud-standard-8`. macOS
  entry preserved; the poppler-install `if: matrix.os` conditional swaps to
  match the new label.
- actionlint.yml, pr-title-sync.yml, skill-docs.yml, version-gate.yml —
  `ubuntu-latest` → `ubicloud-standard-8`.

.github/actionlint.yaml registers all four Ubicloud labels in one place:
- ubicloud-standard-2
- ubicloud-standard-8
- ubicloud-standard-2-windows  (the v1.38.0.0 windows-free-tests target)
- ubicloud-standard-8-windows  (this PR's windows-free-tests target)

Removed the duplicate `actionlint.yaml` at the repo root that I accidentally
created in the prior commit — actionlint only reads `.github/actionlint.yaml`,
so the root file was dead weight.

CHANGELOG entry updated: a single "all Ubicloud" sentence in the narrative
plus a metrics-row covering the runner pool change, and the itemized line
expanded to enumerate the 9 affected workflows. The previously-orphaned
"Itemized changes" line about just `windows-free-tests.yml` is replaced.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-05-14 20:10:50 -07:00
parent bd15dfc985
commit 818bb02f28
12 changed files with 24 additions and 25 deletions
+2
View File
@@ -2,3 +2,5 @@ self-hosted-runner:
labels:
- ubicloud-standard-2
- ubicloud-standard-8
- ubicloud-standard-2-windows
- ubicloud-standard-8-windows
+1 -1
View File
@@ -2,7 +2,7 @@ name: Workflow Lint
on: [push, pull_request]
jobs:
actionlint:
runs-on: ubuntu-latest
runs-on: ubicloud-standard-8
steps:
- uses: actions/checkout@v4
- uses: rhysd/actionlint@v1.7.11
+1 -1
View File
@@ -15,7 +15,7 @@ on:
jobs:
build:
runs-on: ubicloud-standard-2
runs-on: ubicloud-standard-8
permissions:
contents: read
packages: write
+2 -2
View File
@@ -15,7 +15,7 @@ env:
jobs:
build-image:
runs-on: ubicloud-standard-2
runs-on: ubicloud-standard-8
permissions:
contents: read
packages: write
@@ -56,7 +56,7 @@ jobs:
${{ env.IMAGE }}:latest
evals:
runs-on: ubicloud-standard-2
runs-on: ubicloud-standard-8
needs: build-image
container:
image: ${{ needs.build-image.outputs.image-tag }}
+4 -4
View File
@@ -15,7 +15,7 @@ env:
jobs:
# Build Docker image with pre-baked toolchain (cached — only rebuilds on Dockerfile/lockfile change)
build-image:
runs-on: ubicloud-standard-2
runs-on: ubicloud-standard-8
permissions:
contents: read
packages: write
@@ -56,7 +56,7 @@ jobs:
${{ env.IMAGE }}:latest
evals:
runs-on: ${{ matrix.suite.runner || 'ubicloud-standard-2' }}
runs-on: ${{ matrix.suite.runner || 'ubicloud-standard-8' }}
needs: build-image
container:
image: ${{ needs.build-image.outputs.image-tag }}
@@ -155,7 +155,7 @@ jobs:
retention-days: 90
report:
runs-on: ubicloud-standard-2
runs-on: ubicloud-standard-8
needs: evals
if: always() && github.event_name == 'pull_request'
timeout-minutes: 5
@@ -219,7 +219,7 @@ jobs:
$(echo -e "$SUITE_LINES")
---
*12x ubicloud-standard-2 (Docker: pre-baked toolchain + deps) | wall clock ≈ slowest suite*"
*12x ubicloud-standard-8 (Docker: pre-baked toolchain + deps) | wall clock ≈ slowest suite*"
if [ "$FAILED" -gt 0 ]; then
FAILURES=""
+2 -2
View File
@@ -22,7 +22,7 @@ jobs:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
os: [ubicloud-standard-8, macos-latest]
# Windows is tolerant-mode — Xpdf / Poppler-Windows extraction
# differs enough from the Linux/macOS baseline that the strict
# exact-diff gate is unreliable. Enable once the normalized
@@ -48,7 +48,7 @@ jobs:
run: brew install poppler
- name: Install poppler-utils (Ubuntu)
if: matrix.os == 'ubuntu-latest'
if: matrix.os == 'ubicloud-standard-8'
run: sudo apt-get update && sudo apt-get install -y poppler-utils
- name: Install Playwright Chromium
+1 -1
View File
@@ -13,7 +13,7 @@ concurrency:
jobs:
sync:
name: Sync PR title to VERSION
runs-on: ubuntu-latest
runs-on: ubicloud-standard-8
permissions:
contents: read
pull-requests: write
+1 -1
View File
@@ -2,7 +2,7 @@ name: Skill Docs Freshness
on: [push, pull_request]
jobs:
check-freshness:
runs-on: ubuntu-latest
runs-on: ubicloud-standard-8
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
+1 -1
View File
@@ -14,7 +14,7 @@ concurrency:
jobs:
check:
name: Check VERSION is not stale vs queue
runs-on: ubuntu-latest
runs-on: ubicloud-standard-8
permissions:
contents: read
pull-requests: read
+5 -5
View File
@@ -8,10 +8,10 @@ name: Windows Free Tests
# targeted resolver tests that exercise the Bun.which-based claude binary
# resolution + the GSTACK_CLAUDE_BIN override path on Windows.
#
# Runner: Ubicloud Windows runner (`ubicloud-standard-2-windows`). Matches
# the Ubicloud Linux runner the evals workflow already uses, so billing
# stays consolidated under one provider. Swap to `windows-latest` to revert
# to GitHub's free runner if Ubicloud has Windows capacity issues. Note
# Runner: Ubicloud Windows runner (`ubicloud-standard-8-windows`). All CI
# in this repo runs on Ubicloud (Linux + Windows) for billing consolidation
# and consistent capacity. Swap to `windows-latest` to revert to GitHub's
# free runner if Ubicloud has Windows capacity issues. Note
# `windows-latest-8-cores` (GitHub paid larger runner) sat queued because
# org-level larger-runner billing wasn't enabled.
#
@@ -36,7 +36,7 @@ jobs:
windows-free-tests:
# Ubicloud Windows runner (same provider as the Linux evals workflow).
# To revert: swap to `windows-latest` (GitHub's free 4-core Windows runner).
runs-on: ubicloud-standard-2-windows
runs-on: ubicloud-standard-8-windows
timeout-minutes: 15
steps:
+4 -3
View File
@@ -9,7 +9,7 @@ Windows users who pull `git pull && ./setup` now get fresh skill files for every
The browse server's Unicode sanitization lifts from `handleCommand` (PR #1463's original target) to `handleCommandInternal` so the batch command path (`/command/batch`) inherits it too. Both SSE producers (activity feed at `/activity/stream` and inspector stream) now stringify with a `sanitizeReplacer` function that cleans every string value during JSON.stringify — post-stringify regex is ineffective there because `JSON.stringify` has already converted `\uD800` into the escape sequence `"\\ud800"` before the regex would run. Result: every page-content payload that ships from the server has lone UTF-16 surrogate halves replaced with U+FFFD before any downstream consumer (Anthropic API, sidebar JSON.parse) sees them.
The `windows-free-tests.yml` CI lane migrates from GitHub-hosted `windows-latest` to `ubicloud-standard-2-windows` — same provider as the existing `ubicloud-standard-2` Linux evals runner, so billing stays consolidated. Earlier attempts used GitHub's paid `windows-latest-8-cores` larger runner but that queued indefinitely waiting for org-level larger-runner billing enablement. Four new wave tests get registered: sanitizer unit + bug-repro + wiring invariants, setup helper static-invariant + behavior matrix, build-script POSIX-shell sanity, and a doc-vs-config deprecated-key drift guard. Docs that still referenced the renamed `gbrain_sync_mode` config key now say `artifacts_sync_mode` consistently, and the drift guard prevents reintroduction.
All CI jobs migrate to Ubicloud runners (Linux + Windows on `ubicloud-standard-8` / `ubicloud-standard-8-windows`) for consolidated billing and consistent capacity. Eight workflows touch the runner pool: `evals.yml`, `evals-periodic.yml`, `ci-image.yml`, `windows-free-tests.yml`, `make-pdf-gate.yml`, `actionlint.yml`, `pr-title-sync.yml`, `skill-docs.yml`, `version-gate.yml`. Earlier ship attempts used GitHub's paid `windows-latest-8-cores` larger runner but it queued indefinitely waiting for org-level larger-runner billing enablement. `.github/actionlint.yaml` registers all four Ubicloud labels (`ubicloud-standard-2/8` and `ubicloud-standard-2/8-windows`) so future workflow edits don't have to fight the linter. Four new wave tests get registered: sanitizer unit + bug-repro + wiring invariants, setup helper static-invariant + behavior matrix, build-script POSIX-shell sanity, and a doc-vs-config deprecated-key drift guard. Docs that still referenced the renamed `gbrain_sync_mode` config key now say `artifacts_sync_mode` consistently, and the drift guard prevents reintroduction.
Contributed by @realcarsonterry: PRs #1460, #1461, #1462, and #1463 are the seed of this wave. The scope expansion to all 42 setup sites + every server egress path + Windows CI migration is the gstack maintainer's follow-through.
@@ -24,7 +24,7 @@ Source: this branch's diff against `origin/main` and the wave plan at `~/.claude
| Bash brace groups in `package.json` build script (Bun-Windows-hostile) | 3 | 0 | -3 |
| Stale `gbrain_sync_mode` references in docs | 5 | 0 | -5 |
| New regression tests | 0 | 29 (4 files) | +29 |
| Windows CI runner | windows-latest (GitHub free) | ubicloud-standard-2-windows | consolidates Windows + Linux CI under one Ubicloud account |
| CI runner pool | mix of `ubuntu-latest` + `ubicloud-standard-2` + `windows-latest` | `ubicloud-standard-8` everywhere (Windows = `ubicloud-standard-8-windows`) | single billing surface, 4x more cores on Linux jobs, paid Windows that actually runs |
The static invariant test (D7) reads `setup` and asserts zero raw `ln` calls outside the `_link_or_copy` helper body — even a single one-line slip by a future contributor fails the build.
@@ -46,7 +46,8 @@ If you run gstack on Windows: `./setup` now produces a working install across ev
- **`browse/src/server.ts`** — `handleCommandInternal` split into `handleCommandInternalImpl` (raw) + thin sanitizing wrapper. Single egress point for both HTTP and batch consumers. Inline INVARIANT comment near the wrapper documents the architectural constraint.
- **`browse/src/server.ts` SSE producers** — activity feed (`/activity/stream`) and inspector stream stringify with `sanitizeReplacer`, a `JSON.stringify` replacer function that cleans every string value during encoding. Post-stringify regex is a no-op because `JSON.stringify` has already converted `\uD800` to `"\\ud800"` before the regex could match. Inline INVARIANT comment in each.
- **`setup`** — new `_link_or_copy SRC DST` helper near `IS_WINDOWS` detection (~line 33). Auto-dispatches on file-vs-directory + Windows-vs-Unix, and skips Unix-style name-only aliases (e.g. `gstack/open-gstack-browser` for the connect-chrome alias) when the source doesn't resolve on disk so Windows installs don't abort under `set -e`. All 42 prior `ln -snf` call sites converted to `_link_or_copy`. New `_print_windows_copy_note_once` helper called from `link_claude_skill_dirs` after any link work completes. `cleanup_old_claude_symlinks` and `cleanup_prefixed_claude_symlinks` extended with a Windows branch so `--prefix` / `--no-prefix` flips remove stale real-file SKILL.md copies instead of leaving them behind.
- **`.github/workflows/windows-free-tests.yml`** — `runs-on: windows-latest``runs-on: ubicloud-standard-2-windows` (Ubicloud Windows runner, same provider as the Linux evals). `actionlint.yaml` registers the new label alongside `ubicloud-standard-2`. Test-list expanded to include the 4 new wave tests.
- **`.github/workflows/*.yml` (all 9 workflows)** — every `runs-on` switched to Ubicloud: `ubicloud-standard-8` for Linux (`evals.yml`, `evals-periodic.yml`, `ci-image.yml`, `actionlint.yml`, `pr-title-sync.yml`, `skill-docs.yml`, `version-gate.yml`, `make-pdf-gate.yml`'s Linux matrix entry) and `ubicloud-standard-8-windows` for Windows (`windows-free-tests.yml`). The `evals.yml` matrix default and the prose footer both updated to reference `ubicloud-standard-8`. Test-list in `windows-free-tests.yml` expanded to include the 4 new wave tests.
- **`.github/actionlint.yaml`** — registers all four Ubicloud labels (`ubicloud-standard-2/8` and `ubicloud-standard-2/8-windows`) so workflow lint stops rejecting any of them. The duplicate dead-weight `actionlint.yaml` at the repo root is removed (actionlint only reads `.github/actionlint.yaml`).
- **`package.json`** — build script's three `{ git rev-parse HEAD 2>/dev/null || true; } > path/.version` brace groups replaced with `( ... )` subshells. POSIX-universal, Bun-Windows-compatible.
- **`docs/gbrain-sync.md`, `docs/gbrain-sync-errors.md`** — 5 stale `gbrain_sync_mode` config-key references → `artifacts_sync_mode` (the rename landed in v1.27.0.0 but two docs still pointed at the old key).
-4
View File
@@ -1,4 +0,0 @@
self-hosted-runner:
labels:
- ubicloud-standard-2
- ubicloud-standard-2-windows