CI workflows
Every repository runs its own workflows on Blacksmith
runners. Production is deployed by entrosity-infra since the cutover of
2026-09-26; the deploy, agent-builds, release and platform-cutover
workflows of the monorepo entrosity/RMM are disabled.
| Repository | Workflow | Trigger | Does |
|---|---|---|---|
entrosity-shared-go | ci.yml | Push, pull request, tags | go mod tidy check, golangci-lint, go vet for Linux and Windows, tests on Linux and Windows. |
security.yml | Push, pull request, weekly | govulncheck (Linux and Windows), gosec, gitleaks. | |
entrosity-axis.backend, entrosity-hub.backend | ci.yml | Push, pull request | go mod tidy check, make gen leaves no diff, golangci-lint, unit and integration tests; on main, once they pass, the image job pushes ghcr.io/entrosity/{axis,hub}-backend:main and :main-<sha12> and sends deploy to entrosity-infra. |
security.yml | Push, pull request, weekly | govulncheck, gosec, gitleaks, image build with Trivy and an SPDX SBOM. | |
release.yml | Tag v* | Pushes ghcr.io/entrosity/{axis,hub}-backend:X.Y.Z (and latest unless the tag has a -suffix), GitHub release. | |
openapi-changed.yml | Push to main changing api/openapi.yaml | repository_dispatch openapi-updated to the app and to entrosity-docs. | |
entrosity-axis.frontend, entrosity-hub.frontend | ci.yml | Push, pull request | pnpm gen:api leaves no diff, lint, format, typecheck, tests, build; on main pushes the static image ghcr.io/entrosity/{axis,hub}-frontend:main and sends deploy to entrosity-infra. |
ui-bump.yml | ui-released dispatch, manual | Updates @entrosity/ui, runs every check, pushes the bump to main only if all pass. | |
openapi-bump.yml | openapi-updated dispatch, manual | Refreshes api/openapi.yaml, regenerates the client, pushes to main when typecheck and tests pass. | |
entrosity-ui | ci.yml | Push, pull request | Lint, format, typecheck, tests, build, package contents. |
release.yml | Tag v* | Publishes @entrosity/ui to GitHub Packages, GitHub release, ui-released dispatch to both apps. | |
entrosity-axis-agent, entrosity-axis-connector | ci.yml | Push, pull request | Linux lint, vet and tests; Windows tests, MSI build, install/uninstall smoke test; connector: LDAP tests against Samba AD. |
dev-release.yml | Push to main, manual | MSI and executable as version 0.1.<run>-dev.<sha> on the rolling dev pre-release. | |
release.yml | Tag v* | MSI and executable on a GitHub release. | |
entrosity-edge-connector | ci.yml | Push, pull request | go mod tidy check, vet for Linux and Windows, tests on Linux and Windows, MSI build, install/uninstall smoke test. |
dev-release.yml | Push to main, manual | MSI and executable as version 0.0.<build>-dev.<commit> on the rolling dev pre-release; published to Edge on the beta channel (below). | |
release.yml | Tag v* | MSI and executable on a GitHub release; published to Edge (stable, or beta for a -suffix tag). | |
entrosity-sphere-connector | ci.yml | Push, pull request | go mod tidy check, vet for Linux and Windows, tests on Linux and Windows, MSI build, install/uninstall smoke test. |
dev-release.yml | Push to main, manual | MSI and executable as version 0.0.<build>-dev.<commit> on the rolling dev pre-release; published to Sphere on the dev channel (below). | |
release.yml | Tag v* | MSI and executable on a GitHub release; published to Sphere (stable, or dev for a -suffix tag). | |
entrosity-infra | ci.yml | Push, pull request | actionlint, shellcheck, compose config, the custom Caddy build, Trivy on deploy/, gitleaks. |
integration.yml | 02:30 UTC, manual | Against the main branches: both Playwright suites (scripts/e2e.sh), the connector smoke test, and the Windows end-to-end test (real agent MSI, 7-Zip deployment). | |
deploy.yml | deploy dispatch, push to main changing deploy/, manual | Production deploy (Continuous deployment). | |
web-image.yml | Manual | Builds and pushes ghcr.io/entrosity/entrosity-web:<tag> from the published app and docs images. | |
entrosity-docs | ci.yml | Push, pull request | Site build (fails on broken links and anchors); on main pushes ghcr.io/entrosity/docs:main and sends deploy to entrosity-infra. |
openapi-updated.yml | openapi-updated dispatch, manual | Refreshes specs/*.yaml and pushes to main when the site builds. |
Dependabot keeps Go modules, npm packages, actions and Docker images up to
date in every repository. The apps ignore @entrosity/ui there
(ui-bump.yml handles it).
Self-update publishing
The agent and connector workflows can publish the MSI to the Axis server
as a self-update release (go run ./cmd/publish-agent from a checkout of
entrosity-axis.backend). That step is skipped unless the repository
variable RELEASE_PUBLISH_ENABLED is true. For Entrosity's production it
is on in both repositories (since 2026-09-26, with the secrets
RELEASE_PUBLIC_KEY and RMM_RELEASE_TOKEN), so every push to main
publishes a dev build that the server rolls out, and every tag a release.
The builds are unsigned: SIGNING_CERT_* is not set. Dev builds are
versioned 0.1.<run>-dev.<sha>, so they sort above the monorepo's last
dev builds (0.0.<run>-dev, up to 0.0.25-dev) although the new
repositories started their run numbers again.
Edge connector releases
The Edge connector's dev-release.yml and release.yml publish the MSI to
Edge (step Publish to Edge), which signs it and rolls it out to the
connectors (Running Entrosity Edge):
tags vX.Y.Z to the stable channel, tags with a -suffix and every
dev build to beta. The step runs only when the repository variable
EDGE_RELEASE_API (the Edge address, https://hub.entrosity.com/edge) is
set, and fails without the secret EDGE_RELEASE_TOKEN. The builds embed
RELEASE_PUBLIC_KEY, the public half of the server's
EDGE_RELEASE_SIGNING_KEY; a build without it warns and refuses updates.
Sphere connector releases
The Sphere connector's dev-release.yml and release.yml upload the MSI
to Sphere (step Publish for self-update, scripts/publish-release.sh),
which signs it and offers it to the connectors
(Running Entrosity Sphere):
tags vX.Y.Z to the stable channel, tags with a -suffix and every
dev build to dev. The step runs only when the repository variable
RELEASE_PUBLISH_ENABLED is true, and fails without the secret
SPHERE_RELEASE_TOKEN; a version Sphere already has (409) counts as
done. The builds embed RELEASE_PUBLIC_KEY, the public half of the
server's SPHERE_RELEASE_SIGNING_KEY; a build without it warns and does
not update itself.
Runners
| Label | Used by |
|---|---|
blacksmith-4vcpu-ubuntu-2404 | Backend CI, image builds, app CI and bumps, integration tests |
blacksmith-2vcpu-ubuntu-2404 | Security scans, small jobs |
blacksmith-4vcpu-windows-2025 | Agent and connector Windows jobs, the Windows end-to-end test |
.github/actionlint.yaml in every repository lists the labels for
actionlint.
Secrets and variables
| Name | Kind | Where | Used for |
|---|---|---|---|
ENTROSITY_CI_TOKEN | secret | every repository (and as a Dependabot secret in the apps) | Read the private repositories, entrosity-shared-go and @entrosity/ui; repository_dispatch; push the automated bumps |
SIGNING_CERT_PFX, SIGNING_CERT_PASSWORD | secret | agent, connector | Authenticode signing (optional) |
RELEASE_PUBLIC_KEY | secret | agent, connector | Compiled into the binaries (verify updates) |
RMM_RELEASE_TOKEN | secret | agent, connector | Publishing self-update releases |
RELEASE_PUBLISH_ENABLED | variable | agent, connector | true turns self-update publishing on |
RMM_API_URL, DEV_RELEASE_CHANNEL, RMM_RELEASE_ROLLOUT | variable | agent, connector | Publishing target, dev channel, rollout percentage |
RELEASE_PUBLIC_KEY | secret | entrosity-edge-connector | Compiled into the Edge connector (verify updates); from edge-server release-keygen |
EDGE_RELEASE_TOKEN | secret | entrosity-edge-connector | Publishing releases to Edge (the server's EDGE_RELEASE_TOKEN) |
EDGE_RELEASE_API | variable | entrosity-edge-connector | The Edge address; unset: builds are not published to Edge |
RELEASE_PUBLIC_KEY | secret | entrosity-sphere-connector | Compiled into the Sphere connector (verify updates); the public half of SPHERE_RELEASE_SIGNING_KEY |
SPHERE_RELEASE_TOKEN | secret | entrosity-sphere-connector | Uploading releases to Sphere (the server's SPHERE_RELEASE_TOKEN) |
RELEASE_PUBLISH_ENABLED | variable | entrosity-sphere-connector | true uploads every build to Sphere |
SPHERE_RELEASE_API | variable | entrosity-sphere-connector | Upload target (optional), default https://hub.entrosity.com/sphere/api/releases/v1 |
DEPLOY_HOST, DEPLOY_SSH_KEY, DEPLOY_KNOWN_HOSTS | secret | entrosity-infra | Production deploy |
DEPLOY_ENABLED, DEPLOY_URL | variable | entrosity-infra | true allows deploys (kill switch); Axis's old host for the final check (optional) |