diff --git a/.github/workflows/mmctl-test-template.yml b/.github/workflows/mmctl-test-template.yml index 1cde38dd92b..62e858d8d26 100644 --- a/.github/workflows/mmctl-test-template.yml +++ b/.github/workflows/mmctl-test-template.yml @@ -30,6 +30,8 @@ jobs: COMPOSE_PROJECT_NAME: ghactions steps: - name: buildenv/docker-login + # Only FIPS requires login for private build container. (Forks won't have credentials.) + if: inputs.fips-enabled uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }} diff --git a/.github/workflows/server-ci.yml b/.github/workflows/server-ci.yml index a5aaa8f910f..75d120007ec 100644 --- a/.github/workflows/server-ci.yml +++ b/.github/workflows/server-ci.yml @@ -205,6 +205,8 @@ jobs: go-version: ${{ needs.go.outputs.version }} fips-enabled: false test-postgres-normal-fips: + # Skip FIPS testing for forks, which won't have docker login credentials. + if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository name: Postgres (FIPS) needs: go uses: ./.github/workflows/server-test-template.yml @@ -217,9 +219,9 @@ jobs: go-version: ${{ needs.go.outputs.version }} fips-enabled: true test-coverage: + name: Generate Test Coverage # Skip coverage generation for cherry-pick PRs into release branches. if: ${{ github.event_name != 'pull_request' || !startsWith(github.event.pull_request.base.ref, 'release-') }} - name: Generate Test Coverage needs: go uses: ./.github/workflows/server-test-template.yml secrets: inherit @@ -245,6 +247,8 @@ jobs: fips-enabled: false test-mmctl-fips: name: Run mmctl tests (FIPS) + # Skip FIPS testing for forks, which won't have docker login credentials. + if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository needs: go uses: ./.github/workflows/mmctl-test-template.yml secrets: inherit diff --git a/.github/workflows/server-test-template.yml b/.github/workflows/server-test-template.yml index af696ab5081..838957adf86 100644 --- a/.github/workflows/server-test-template.yml +++ b/.github/workflows/server-test-template.yml @@ -43,6 +43,8 @@ jobs: COMPOSE_PROJECT_NAME: ghactions steps: - name: buildenv/docker-login + # Only FIPS requires login for private build container. (Forks won't have credentials.) + if: inputs.fips-enabled uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0 with: username: ${{ secrets.DOCKERHUB_USERNAME }}