The daily long-soak workflow is currently opt-in and runs on GitHub-hosted compute, so it has never produced the trusted self-hosted evidence described by the harness contract.
Use a disposable performance host for each scheduled or manually dispatched run:
- provision a fixed-size host only after a trusted
main workflow starts;
- check out and test the exact Actions SHA;
- keep provider credentials off the test host;
- retrieve
build/perf artifacts even when the harness fails;
- delete the host on success, failure, or cancellation;
- reject durations or concurrency outside bounded operating limits;
- require
trusted_long_soak_v1 evidence from the two-hour default run;
- keep pull requests unable to access provisioning credentials.
After landing, run the normal two-hour soak once and verify both its evidence artifact and provider-side deletion before enabling the daily schedule.
The daily long-soak workflow is currently opt-in and runs on GitHub-hosted compute, so it has never produced the trusted self-hosted evidence described by the harness contract.
Use a disposable performance host for each scheduled or manually dispatched run:
mainworkflow starts;build/perfartifacts even when the harness fails;trusted_long_soak_v1evidence from the two-hour default run;After landing, run the normal two-hour soak once and verify both its evidence artifact and provider-side deletion before enabling the daily schedule.