From a1736d174ee31a1ff3bd34b2c1dd3ef0b44c4ab9 Mon Sep 17 00:00:00 2001 From: Wenbo Ji <36562829+fusheng-ji@users.noreply.github.com> Date: Thu, 1 Oct 2026 21:14:07 +0000 Subject: [PATCH] fix(ci): pin runpodctl v2.9.0 and authenticate via RUNPOD_API_KEY ws1-gtest-gpu and ws1-chain-gpu fail at "Configure runpodctl" before any test runs. They install releases/latest (v2.14.0 since 2026-09-10), whose deprecated `config --apiKey` aborts with `Config File ".runpod.yaml" Not Found` when it is the first runpodctl call on a fresh HOME. It only succeeds once an earlier call has created ~/.runpod/config.toml, which is why gpu-ci, whose install step happens to run `runpodctl version` first, got past the same command. Drop the config step in all three workflows. runpodctl v2 reads RUNPOD_API_KEY from the environment, and every step that runs ci/run_gpu_ci.sh already exports it, including the cleanup trap that calls `pod remove`. Verified for v2.9.0 inside `unshare -rn`, from a fresh HOME after `runpodctl version`: without the variable `pod list` fails locally with no_credentials, with RUNPOD_API_KEY=dummy it gets past the credential check to a network_error, and config.toml keeps `apikey = ''` throughout. v2.14.0 behaves the same. Pin the download to v2.9.0, the version gpu-ci run 31455127310 exercised end to end (pod create with sold-out fallback, pod id parsing, pod get polling, SSH, cleanup), and verify it with sha256sum -c against the runpodctl-linux-amd64 line of checksums_2.9.0_sha256.txt (06e6f54957db79d5cd9f1909a7f1d365076826751ba2f5df65d75dde43a64148), which matches GitHub's asset digest. Signed-off-by: Wenbo Ji <36562829+fusheng-ji@users.noreply.github.com> --- .github/workflows/gpu-ci.yml | 13 +++++++++---- .github/workflows/ws1-chain-gpu.yml | 14 ++++++++++---- .github/workflows/ws1-gtest-gpu.yml | 14 ++++++++++---- 3 files changed, 29 insertions(+), 12 deletions(-) diff --git a/.github/workflows/gpu-ci.yml b/.github/workflows/gpu-ci.yml index 277e4980f..7681746de 100644 --- a/.github/workflows/gpu-ci.yml +++ b/.github/workflows/gpu-ci.yml @@ -40,15 +40,20 @@ jobs: ref: ${{ github.event.pull_request.base.sha }} - name: Install runpodctl + # Pinned with its published checksum: a moving "latest" changes CLI + # behavior under CI without a commit here. To upgrade, set both values: + # sha256 = the runpodctl-linux-amd64 line of checksums__sha256.txt + # in the release. + env: + RUNPODCTL_VERSION: v2.9.0 + RUNPODCTL_SHA256: 06e6f54957db79d5cd9f1909a7f1d365076826751ba2f5df65d75dde43a64148 run: | - wget -qO runpodctl https://github.com/runpod/runpodctl/releases/latest/download/runpodctl-linux-amd64 + wget -qO runpodctl "https://github.com/runpod/runpodctl/releases/download/${RUNPODCTL_VERSION}/runpodctl-linux-amd64" + echo "${RUNPODCTL_SHA256} runpodctl" | sha256sum -c - chmod +x runpodctl sudo mv runpodctl /usr/local/bin/runpodctl runpodctl version - - name: Configure runpodctl - run: runpodctl config --apiKey "${{ secrets.RUNPOD_API_KEY }}" - - name: Setup SSH key run: | mkdir -p ~/.ssh && chmod 700 ~/.ssh diff --git a/.github/workflows/ws1-chain-gpu.yml b/.github/workflows/ws1-chain-gpu.yml index 85caab6b9..b9e552a53 100644 --- a/.github/workflows/ws1-chain-gpu.yml +++ b/.github/workflows/ws1-chain-gpu.yml @@ -68,13 +68,19 @@ jobs: persist-credentials: false - name: Install runpodctl + # Pinned with its published checksum: a moving "latest" changes CLI + # behavior under CI without a commit here. To upgrade, set both values: + # sha256 = the runpodctl-linux-amd64 line of checksums__sha256.txt + # in the release. + env: + RUNPODCTL_VERSION: v2.9.0 + RUNPODCTL_SHA256: 06e6f54957db79d5cd9f1909a7f1d365076826751ba2f5df65d75dde43a64148 run: | - wget -qO runpodctl https://github.com/runpod/runpodctl/releases/latest/download/runpodctl-linux-amd64 + wget -qO runpodctl "https://github.com/runpod/runpodctl/releases/download/${RUNPODCTL_VERSION}/runpodctl-linux-amd64" + echo "${RUNPODCTL_SHA256} runpodctl" | sha256sum -c - chmod +x runpodctl sudo mv runpodctl /usr/local/bin/runpodctl - - - name: Configure runpodctl - run: runpodctl config --apiKey "${{ secrets.RUNPOD_API_KEY }}" + runpodctl version - name: Setup SSH key run: | diff --git a/.github/workflows/ws1-gtest-gpu.yml b/.github/workflows/ws1-gtest-gpu.yml index 646d80bdf..516463ef8 100644 --- a/.github/workflows/ws1-gtest-gpu.yml +++ b/.github/workflows/ws1-gtest-gpu.yml @@ -73,13 +73,19 @@ jobs: persist-credentials: false - name: Install runpodctl + # Pinned with its published checksum: a moving "latest" changes CLI + # behavior under CI without a commit here. To upgrade, set both values: + # sha256 = the runpodctl-linux-amd64 line of checksums__sha256.txt + # in the release. + env: + RUNPODCTL_VERSION: v2.9.0 + RUNPODCTL_SHA256: 06e6f54957db79d5cd9f1909a7f1d365076826751ba2f5df65d75dde43a64148 run: | - wget -qO runpodctl https://github.com/runpod/runpodctl/releases/latest/download/runpodctl-linux-amd64 + wget -qO runpodctl "https://github.com/runpod/runpodctl/releases/download/${RUNPODCTL_VERSION}/runpodctl-linux-amd64" + echo "${RUNPODCTL_SHA256} runpodctl" | sha256sum -c - chmod +x runpodctl sudo mv runpodctl /usr/local/bin/runpodctl - - - name: Configure runpodctl - run: runpodctl config --apiKey "${{ secrets.RUNPOD_API_KEY }}" + runpodctl version - name: Setup SSH key run: |