Skip to main content

CI workflows

Every repository runs its own workflows on Blacksmith runners. Production is deployed by entrosity-infra since the cutover of 2026-09-26; the deploy, agent-builds, release and platform-cutover workflows of the monorepo entrosity/RMM are disabled.

RepositoryWorkflowTriggerDoes
entrosity-shared-goci.ymlPush, pull request, tagsgo mod tidy check, golangci-lint, go vet for Linux and Windows, tests on Linux and Windows.
security.ymlPush, pull request, weeklygovulncheck (Linux and Windows), gosec, gitleaks.
entrosity-axis.backend, entrosity-hub.backendci.ymlPush, pull requestgo mod tidy check, make gen leaves no diff, golangci-lint, unit and integration tests; on main, once they pass, the image job pushes ghcr.io/entrosity/{axis,hub}-backend:main and :main-<sha12> and sends deploy to entrosity-infra.
security.ymlPush, pull request, weeklygovulncheck, gosec, gitleaks, image build with Trivy and an SPDX SBOM.
release.ymlTag v*Pushes ghcr.io/entrosity/{axis,hub}-backend:X.Y.Z (and latest unless the tag has a -suffix), GitHub release.
openapi-changed.ymlPush to main changing api/openapi.yamlrepository_dispatch openapi-updated to the app and to entrosity-docs.
entrosity-axis.frontend, entrosity-hub.frontendci.ymlPush, pull requestpnpm gen:api leaves no diff, lint, format, typecheck, tests, build; on main pushes the static image ghcr.io/entrosity/{axis,hub}-frontend:main and sends deploy to entrosity-infra.
ui-bump.ymlui-released dispatch, manualUpdates @entrosity/ui, runs every check, pushes the bump to main only if all pass.
openapi-bump.ymlopenapi-updated dispatch, manualRefreshes api/openapi.yaml, regenerates the client, pushes to main when typecheck and tests pass.
entrosity-uici.ymlPush, pull requestLint, format, typecheck, tests, build, package contents.
release.ymlTag v*Publishes @entrosity/ui to GitHub Packages, GitHub release, ui-released dispatch to both apps.
entrosity-axis-agent, entrosity-axis-connectorci.ymlPush, pull requestLinux lint, vet and tests; Windows tests, MSI build, install/uninstall smoke test; connector: LDAP tests against Samba AD.
dev-release.ymlPush to main, manualMSI and executable as version 0.1.<run>-dev.<sha> on the rolling dev pre-release.
release.ymlTag v*MSI and executable on a GitHub release.
entrosity-edge-connectorci.ymlPush, pull requestgo mod tidy check, vet for Linux and Windows, tests on Linux and Windows, MSI build, install/uninstall smoke test.
dev-release.ymlPush to main, manualMSI and executable as version 0.0.<build>-dev.<commit> on the rolling dev pre-release; published to Edge on the beta channel (below).
release.ymlTag v*MSI and executable on a GitHub release; published to Edge (stable, or beta for a -suffix tag).
entrosity-sphere-connectorci.ymlPush, pull requestgo mod tidy check, vet for Linux and Windows, tests on Linux and Windows, MSI build, install/uninstall smoke test.
dev-release.ymlPush to main, manualMSI and executable as version 0.0.<build>-dev.<commit> on the rolling dev pre-release; published to Sphere on the dev channel (below).
release.ymlTag v*MSI and executable on a GitHub release; published to Sphere (stable, or dev for a -suffix tag).
entrosity-infraci.ymlPush, pull requestactionlint, shellcheck, compose config, the custom Caddy build, Trivy on deploy/, gitleaks.
integration.yml02:30 UTC, manualAgainst the main branches: both Playwright suites (scripts/e2e.sh), the connector smoke test, and the Windows end-to-end test (real agent MSI, 7-Zip deployment).
deploy.ymldeploy dispatch, push to main changing deploy/, manualProduction deploy (Continuous deployment).
web-image.ymlManualBuilds and pushes ghcr.io/entrosity/entrosity-web:<tag> from the published app and docs images.
entrosity-docsci.ymlPush, pull requestSite build (fails on broken links and anchors); on main pushes ghcr.io/entrosity/docs:main and sends deploy to entrosity-infra.
openapi-updated.ymlopenapi-updated dispatch, manualRefreshes specs/*.yaml and pushes to main when the site builds.

Dependabot keeps Go modules, npm packages, actions and Docker images up to date in every repository. The apps ignore @entrosity/ui there (ui-bump.yml handles it).

Self-update publishing​

The agent and connector workflows can publish the MSI to the Axis server as a self-update release (go run ./cmd/publish-agent from a checkout of entrosity-axis.backend). That step is skipped unless the repository variable RELEASE_PUBLISH_ENABLED is true. For Entrosity's production it is on in both repositories (since 2026-09-26, with the secrets RELEASE_PUBLIC_KEY and RMM_RELEASE_TOKEN), so every push to main publishes a dev build that the server rolls out, and every tag a release. The builds are unsigned: SIGNING_CERT_* is not set. Dev builds are versioned 0.1.<run>-dev.<sha>, so they sort above the monorepo's last dev builds (0.0.<run>-dev, up to 0.0.25-dev) although the new repositories started their run numbers again.

Edge connector releases​

The Edge connector's dev-release.yml and release.yml publish the MSI to Edge (step Publish to Edge), which signs it and rolls it out to the connectors (Running Entrosity Edge): tags vX.Y.Z to the stable channel, tags with a -suffix and every dev build to beta. The step runs only when the repository variable EDGE_RELEASE_API (the Edge address, https://hub.entrosity.com/edge) is set, and fails without the secret EDGE_RELEASE_TOKEN. The builds embed RELEASE_PUBLIC_KEY, the public half of the server's EDGE_RELEASE_SIGNING_KEY; a build without it warns and refuses updates.

Sphere connector releases​

The Sphere connector's dev-release.yml and release.yml upload the MSI to Sphere (step Publish for self-update, scripts/publish-release.sh), which signs it and offers it to the connectors (Running Entrosity Sphere): tags vX.Y.Z to the stable channel, tags with a -suffix and every dev build to dev. The step runs only when the repository variable RELEASE_PUBLISH_ENABLED is true, and fails without the secret SPHERE_RELEASE_TOKEN; a version Sphere already has (409) counts as done. The builds embed RELEASE_PUBLIC_KEY, the public half of the server's SPHERE_RELEASE_SIGNING_KEY; a build without it warns and does not update itself.

Runners​

LabelUsed by
blacksmith-4vcpu-ubuntu-2404Backend CI, image builds, app CI and bumps, integration tests
blacksmith-2vcpu-ubuntu-2404Security scans, small jobs
blacksmith-4vcpu-windows-2025Agent and connector Windows jobs, the Windows end-to-end test

.github/actionlint.yaml in every repository lists the labels for actionlint.

Secrets and variables​

NameKindWhereUsed for
ENTROSITY_CI_TOKENsecretevery repository (and as a Dependabot secret in the apps)Read the private repositories, entrosity-shared-go and @entrosity/ui; repository_dispatch; push the automated bumps
SIGNING_CERT_PFX, SIGNING_CERT_PASSWORDsecretagent, connectorAuthenticode signing (optional)
RELEASE_PUBLIC_KEYsecretagent, connectorCompiled into the binaries (verify updates)
RMM_RELEASE_TOKENsecretagent, connectorPublishing self-update releases
RELEASE_PUBLISH_ENABLEDvariableagent, connectortrue turns self-update publishing on
RMM_API_URL, DEV_RELEASE_CHANNEL, RMM_RELEASE_ROLLOUTvariableagent, connectorPublishing target, dev channel, rollout percentage
RELEASE_PUBLIC_KEYsecretentrosity-edge-connectorCompiled into the Edge connector (verify updates); from edge-server release-keygen
EDGE_RELEASE_TOKENsecretentrosity-edge-connectorPublishing releases to Edge (the server's EDGE_RELEASE_TOKEN)
EDGE_RELEASE_APIvariableentrosity-edge-connectorThe Edge address; unset: builds are not published to Edge
RELEASE_PUBLIC_KEYsecretentrosity-sphere-connectorCompiled into the Sphere connector (verify updates); the public half of SPHERE_RELEASE_SIGNING_KEY
SPHERE_RELEASE_TOKENsecretentrosity-sphere-connectorUploading releases to Sphere (the server's SPHERE_RELEASE_TOKEN)
RELEASE_PUBLISH_ENABLEDvariableentrosity-sphere-connectortrue uploads every build to Sphere
SPHERE_RELEASE_APIvariableentrosity-sphere-connectorUpload target (optional), default https://hub.entrosity.com/sphere/api/releases/v1
DEPLOY_HOST, DEPLOY_SSH_KEY, DEPLOY_KNOWN_HOSTSsecretentrosity-infraProduction deploy
DEPLOY_ENABLED, DEPLOY_URLvariableentrosity-infratrue allows deploys (kill switch); Axis's old host for the final check (optional)