[llvm] workflows: Add require-release-manager composite action (PR #194758)

Tom Stellard via llvm-commits llvm-commits at lists.llvm.org
Wed Apr 29 07:36:50 PDT 2026


https://github.com/tstellar updated https://github.com/llvm/llvm-project/pull/194758

>From 05dc342236746300a377d5d5aea1df6e4c7f218c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:16:56 -0700
Subject: [PATCH 1/5] workflows: Add require-release-manager composite action

This action checks that the workflow was started by someone in the
llvm-release-managers team.  This is meant to replace the existing
checks which use a python script and will help to consolidate the
access token generation into a single place.

Also start using it in the release-binaries workflow.
---
 .github/workflows/release-binaries.yml        | 22 +++---------
 .../require-release-manager/action.yml        | 35 +++++++++++++++++++
 2 files changed, 40 insertions(+), 17 deletions(-)
 create mode 100644 .github/workflows/require-release-manager/action.yml

diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 1ea01738d75b7..cb77a32a50195 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,6 +50,7 @@ permissions:
 jobs:
   prepare:
     name: Prepare to build binaries
+    environment: release
     runs-on: ${{ inputs.runs-on }}
     if: github.repository_owner == 'llvm'
     outputs:
@@ -65,12 +66,6 @@ jobs:
       attestation-name: ${{ steps.vars.outputs.attestation-name }}
 
     steps:
-    # It's good practice to use setup-python, but this is also required on macos-14
-    # due to https://github.com/actions/runner-images/issues/10385
-    - uses: actions/setup-python at a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
-      with:
-        python-version: '3.14'
-
     - name: Install Windows ARM64 dependencies
       if: runner.os == 'Windows' && runner.arch == 'ARM64'
       run: |
@@ -83,19 +78,12 @@ jobs:
       with:
           persist-credentials: false
 
-    - name: Install Dependencies
-      shell: bash
-      run: |
-        pip install --require-hashes -r ./llvm/utils/git/requirements.txt
-
     - name: Check Permissions
       if: github.event_name != 'pull_request'
-      env:
-        GITHUB_TOKEN: ${{ github.token }}
-        USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
-      shell: bash
-      run: |
-        ./llvm/utils/release/./github-upload-release.py --token "$GITHUB_TOKEN" --user "$GITHUB_ACTOR" --user-token "$USER_TOKEN" check-permissions
+      uses: ./.github/workflows/require-release-manager
+      with:
+        LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+        LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
 
     # The name of the Windows binaries uses the version from source, so we need
     # to fetch it here.
diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
new file mode 100644
index 0000000000000..520b2d02693a3
--- /dev/null
+++ b/.github/workflows/require-release-manager/action.yml
@@ -0,0 +1,35 @@
+name: Require Release Manager
+description: >-
+  This checks to make sure the person that initiated the workflow is a
+  release manager.
+inputs:
+  LLVM_TOKEN_GENERATOR_CLIENT_ID:
+    description: >-
+      Client ID for generating access tokens.
+    required: true
+  LLVM_TOKEN_GENERATOR_PRIVATE_KEY:
+    description: >-
+      Private key for generating access tokens
+    required: true
+
+runs:
+  using: "composite"
+  steps:
+    - id: app-token
+      uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3  # v3.1.1
+      with:
+        app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+        private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+        owner: ${{ github.repository_owner }}
+        permission-members: read
+
+    - name: Check Permissions
+      uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+      with:
+        github-token: ${{ steps.app-token.outputs.token }}
+        script: |
+          await github.rest.teams.getMembershipForUserInOrg({
+             org: context.repo.owner,
+             team_slug: "llvm-release-managers"
+             username: context.actor
+          });

>From cfbb00258931bc2789206b699f9b998dd4916cfa Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:12:46 -0700
Subject: [PATCH 2/5] fix environment

---
 .github/workflows/release-binaries.yml | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index cb77a32a50195..af25c04bdfee7 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,7 +50,9 @@ permissions:
 jobs:
   prepare:
     name: Prepare to build binaries
-    environment: release
+    environment:
+      deployment: false
+      environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
     runs-on: ${{ inputs.runs-on }}
     if: github.repository_owner == 'llvm'
     outputs:

>From 94d516309661c9c948b6e135b70c9e2456cf643c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:30:53 -0700
Subject: [PATCH 3/5] Fix name

---
 .github/workflows/release-binaries.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index af25c04bdfee7..feab47e50583a 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -52,7 +52,7 @@ jobs:
     name: Prepare to build binaries
     environment:
       deployment: false
-      environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
+      name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
     runs-on: ${{ inputs.runs-on }}
     if: github.repository_owner == 'llvm'
     outputs:

>From c7cd2d01c4f74c342174942c2669780a550e95f7 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:33:35 -0700
Subject: [PATCH 4/5] Fix secrets

---
 .github/workflows/release-binaries-all.yml | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/.github/workflows/release-binaries-all.yml b/.github/workflows/release-binaries-all.yml
index 5a775082f4586..5186aee028051 100644
--- a/.github/workflows/release-binaries-all.yml
+++ b/.github/workflows/release-binaries-all.yml
@@ -78,6 +78,9 @@ jobs:
 
   release-binaries-all:
     name: Build Release Binaries
+    environment:
+      deployment: false
+      name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
     needs:
       - setup-variables
     permissions:
@@ -102,7 +105,8 @@ jobs:
       upload: ${{ needs.setup-variables.outputs.upload == 'true'}}
       runs-on: "${{ matrix.runs-on }}"
     secrets:
-      # This will be empty for pull_request events, but that's fine, because
-      # the release-binaries workflow does not use this secret for the
+      # These will be empty for pull_request events, but that's fine, because
+      # the release-binaries workflow does not use these secrets for the
       # pull_request event.
-      RELEASE_TASKS_USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
+      LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+      LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}

>From 395ff77c17028819932cce15b4409571bca3a7b7 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:36:27 -0700
Subject: [PATCH 5/5] Remove environment from caller

---
 .github/workflows/release-binaries-all.yml | 3 ---
 1 file changed, 3 deletions(-)

diff --git a/.github/workflows/release-binaries-all.yml b/.github/workflows/release-binaries-all.yml
index 5186aee028051..d331d2699f4cb 100644
--- a/.github/workflows/release-binaries-all.yml
+++ b/.github/workflows/release-binaries-all.yml
@@ -78,9 +78,6 @@ jobs:
 
   release-binaries-all:
     name: Build Release Binaries
-    environment:
-      deployment: false
-      name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
     needs:
       - setup-variables
     permissions:



More information about the llvm-commits mailing list