Prepared Docs

Prepared Docs

⌘K

    Loading navigation…

User

  1. Ci Cd
  2. Pr Checks

PR Checks

Every check that runs on a pull request, whether it blocks merge, and why it exists.

Every workflow below runs somewhere between opening a PR and merging to trunk. Blocking means the check must pass (or merge-gatekeeper won't let the PR merge). Advisory means it reports information — a comment, a label, a status — but merge-gatekeeper is explicitly configured to ignore it.

Blocking status here reflects the --ignored list in merge-gatekeeper.yaml at the time of writing. That list changes; treat the YAML file as the source of truth and this table as a snapshot.

The gate itself

merge-gatekeeper

  • Runs on: every PR targeting trunk, plus merge_group events.
  • What it does: polls the GitHub Checks/Statuses API for the PR's head commit every 30s (up to 35 minutes) and fails unless every check not in its ignore list has succeeded.
  • Why: branch protection only needs to require this one check. Adding, renaming, or removing an underlying CI job doesn't require touching branch protection settings — just this workflow's ignore list.
  • Blocking: it is the blocking mechanism.

Repo-wide gates (apply to any PR, including Dispatch)

WorkflowTriggerWhat it checksBlocking?
check-haltedPR opened/edited/reopened/synchronize to trunk, and merge_groupReads the LaunchDarkly halt-releases flag. Fails (with a message pointing to #eng-releases) unless the PR is a [HF], Revert, or [CHE] title.Blocking — an org-wide kill switch for incidents; halting stops all normal merges without touching individual PRs.
pr-lintPR opened/edited/reopened/synchronize/ready_for_review to trunkValidates the PR title matches \[TICKET-123\], [HF], [BUMP], or Bump, and requests changes if not.Advisory to merge-gatekeeper (listed as pr-lint), but a "request changes" review can still block merge depending on required-reviewer settings.
codeql-prPR to trunkDiffs the PR to build a per-language CodeQL matrix (only for languages that actually changed), then runs security analysis for each.The Go leg (CodeQL analysis (go)) is advisory. The javascript-typescript leg — the one that fires for Dispatch changes — is blocking.
check-eslint-suppressionsPR touching any turbo/**/eslint-suppressions.jsonDiffs the total suppression count before/after; if it grew, requires an approval from the ux-core GitHub team before passing.Blocking, whenever it runs — exists so growing lint-suppression debt gets an explicit sign-off instead of slipping through in a normal review.
check-high-risk-changesPR opened/synchronize/reopened/ready_for_review to trunk, and PR review submittedDetects high-risk backend changes via .github/scripts/check_high_risk.py; if detected, requires approval from one of a small named set of senior approvers.Blocking when high-risk changes are detected. Rarely fires for a pure Dispatch PR (it targets backend risk heuristics).
codeowners-prPR opened/synchronize/reopened/ready_for_review to trunkValidates CODEOWNERS has no gaps or duplicate patterns for files touched in the PR.Advisory (codeowners-gap-checks is ignored).
pr-labelAny PR eventAuto-labels the PR by changed paths (.github/labeler.yaml), plus a Go-dependency labeler when .go/go.mod/go.sum changed.Advisory (triage job is ignored).

Dispatch-specific checks

These are scoped (via turbo --affected or explicit path filters) to changes that actually touch turbo/apps/dispatch, though some trigger on the broader turbo/** path and then decide internally whether Dispatch is affected.

WorkflowTriggerWhat it checksBlocking?
dispatch-ciPush to trunk, PR, merge_group, and a nightly schedule — path-filtered to turbo/** and related scripts/actionsDispatch's main pipeline: Biome lint/format, ESLint + circular-dependency check, strict TS typecheck (reported to Datadog), a 12-way sharded Vitest run with coverage, and a bundle/sourcemap upload step. Gated on turbo ls --affected actually including dispatch.Blocking for lint, dep-check, typecheck, and each Vitest shard. merge-coverage (the coverage-diff PR comment job) is advisory.
dispatch-bundle-size-alertPR touching turbo/** or bundle-alert scripts, gated on Dispatch being affectedBuilds the head bundle, compares against a cached S3 baseline for the base branch, and comments the size delta (5% threshold) on the PR.Blocking — not in the gatekeeper's ignore list.
frontend-lint-and-testPush/PR touching turbo/**Runs turbo run lint --affected (ESLint) and biome ci --changed across whatever turbo packages changed — broader than dispatch-ci's own lint jobs (whole workspace, not Dispatch-filtered).Blocking.
playwright-testsPush to trunk touching turbo/apps/dispatch/** or turbo/apps/automation/**, and workflow_run completion of build.yaml ("Docker Build")Runs Dispatch's Playwright integration and E2E suites against the already-built live-dispatch image (so it doesn't rebuild). Reports as commit statuses named Run Integration Tests / Run E2E Tests.Advisory — both Playwright Tests and Run E2E Tests are explicitly in the gatekeeper's ignore list. This is worth knowing: the most thorough tests Dispatch gets do not block merge.
Vercel – dispatch_viteEvery PR, automatically (skipped if turbo/apps/dispatch didn't change)Vercel's GitHub integration builds Dispatch as a static Vite app (vercel.json in turbo/apps/dispatch) against CONFIG_ENV=development, so it talks to the real shared dev API. No label required — this is the default, fast way to see a Dispatch PR's frontend changes live.Advisory (all Vercel checks are in the gatekeeper's ignore list).
preview-argo-link / kill-old-pr-envsPR labeled/unlabeled/synchronize (preview-argo-link); daily schedule (kill-old-pr-envs)Opt-in via the preview label: spins up a full, isolated environment in its own ArgoCD namespace (pr-env-<PR#>) — its own backend stack, not just the frontend — and posts/updates a PR comment with the link. kill-old-pr-envs strips stale preview/fe-preview labels after 7 days of inactivity, tearing the environment down.Advisory (cleanup-argo-link, sync-preview-env, wait-for-preview-env are all ignored).

See Deployment for how to actually reach these preview links.

A naming gotcha

build.yaml is the workflow (its name: field is literally Docker Build) that builds and pushes the live-dispatch image PRs and Playwright tests depend on. There is a separate, differently-scoped reusable workflow file called docker-build.yaml (on: workflow_call only) used by dg-engine-ci, livekit-ingress-ci, and sip-proxy-kamailio-ci — Dispatch never invokes it. The similar filenames are easy to confuse when debugging a failed image build.

Previous

CI/CD & deployment / CI/CD Overview

Next

CI/CD & deployment / Deployment

On this page

The gate itself
merge-gatekeeper
Repo-wide gates (apply to any PR, including Dispatch)
Dispatch-specific checks
A naming gotcha