keycloak-tests.yml cannot be run manually. Attempting it fails:
$ gh workflow run keycloak-tests.yml --repo CivicDataLab/CivicDataSpace-test --ref CI
HTTP 404: workflow keycloak-tests.yml not found on the default branch
Mechanism
GitHub only surfaces workflow_dispatch for workflows present on the default branch. This repo's default is main, which carries only run-smoke.yml:
| Branch |
Workflows |
main (default) |
run-smoke.yml |
CI |
run-smoke.yml, keycloak-tests.yml |
The workflow declares workflow_dispatch:, so it looks dispatchable in the file — it just isn't, and the failure only appears when someone tries.
What still works
Nothing is broken. workflow_call resolves by ref, so keycloak-tests.yml@CI works when DataSpaceKeycloakTheme calls it — proven on its first real run (12 passed, 1 skipped, since fixed in #29).
The only loss is manual invocation, which matters for:
- verifying a change to the workflow without waiting for a theme deploy
- re-running the Keycloak checks after a Keycloak-side change that did not come from a theme deploy
Right now the only way to exercise it is to redeploy the staging Keycloak, which every product's dev environment depends on — too heavy an action to take just to test a workflow.
Suggested
Land keycloak-tests.yml on main. run-smoke.yml is already there, so this follows existing practice rather than introducing a new one.
Worth deciding at the same time whether main or CI is meant to be the executing branch here. The current split — triggers and callers pinned to CI while main is the default — is what produced this, and also produced the pinned-checkout problems fixed in #27.
Same defect elsewhere
ParakhAI-Backend#109 records the identical pattern: deploy-parakh-api-dev.yml exists only on dev, so its workflow_dispatch — including a force_smoke_failure test path — has never been usable.
keycloak-tests.ymlcannot be run manually. Attempting it fails:Mechanism
GitHub only surfaces
workflow_dispatchfor workflows present on the default branch. This repo's default ismain, which carries onlyrun-smoke.yml:main(default)run-smoke.ymlCIrun-smoke.yml,keycloak-tests.ymlThe workflow declares
workflow_dispatch:, so it looks dispatchable in the file — it just isn't, and the failure only appears when someone tries.What still works
Nothing is broken.
workflow_callresolves by ref, sokeycloak-tests.yml@CIworks when DataSpaceKeycloakTheme calls it — proven on its first real run (12 passed, 1 skipped, since fixed in #29).The only loss is manual invocation, which matters for:
Right now the only way to exercise it is to redeploy the staging Keycloak, which every product's dev environment depends on — too heavy an action to take just to test a workflow.
Suggested
Land
keycloak-tests.ymlonmain.run-smoke.ymlis already there, so this follows existing practice rather than introducing a new one.Worth deciding at the same time whether
mainorCIis meant to be the executing branch here. The current split — triggers and callers pinned toCIwhilemainis the default — is what produced this, and also produced the pinned-checkout problems fixed in #27.Same defect elsewhere
ParakhAI-Backend#109records the identical pattern:deploy-parakh-api-dev.ymlexists only ondev, so itsworkflow_dispatch— including aforce_smoke_failuretest path — has never been usable.