Pipeline jobs declare a timeout
pipeline/job-timeout-set@v1
Every job declares how long it may run, so a hung job is cut off rather than holding a runner until the platform's own limit.
| Id | pipeline/job-timeout-set |
| Version | v1 |
| Category | pipeline |
| Default severity | info |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | workflow |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
workflow | The pipeline definitions in the checkout, read as they are written: which triggers start them, what permissions they hand a job, which runner each job asks for, and every action a step reaches for and how tightly it is pinned. Names and shapes only, never a secret, an input value or an environment value. | pipelines |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "pipeline/job-timeout-set@v1",
"severity": "info",
"with": {
"pipelines": ".github/workflows/*.yml,.github/workflows/*.yaml,.gitlab-ci.yml,azure-pipelines*.yml,Jenkinsfile",
"maxMinutes": "60"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
pipelines | Comma separated globs naming the pipeline definitions to read. | .github/workflows/*.yml,.github/workflows/*.yaml,.gitlab-ci.yml,azure-pipelines*.yml,Jenkinsfile | GUARDRAIL_INPUT_PIPELINES |
maxMinutes | Longest timeout accepted. A job declaring more than this is treated as declaring none. | 60 | GUARDRAIL_INPUT_MAXMINUTES |
How to fix
Declare one on each job:
jobs:
build:
timeout-minutes: 15GitHub's default is six hours. A job that hangs holds a runner for all of it, which on a self hosted fleet is a queue nobody can clear and on a hosted one is a bill.
More in pipeline
pipeline/actions-pinned-by-digest. Every third party action a workflow uses is pinned to a full commit sha rather than to a tag or a branch.pipeline/least-privilege-token. Every workflow declarespermissions, and none of them takes write access to everything.pipeline/no-script-injection. Norunstep interpolates a${{ }}expression an outsider controls, such as a pull request title or a branch name, straight into the shell body.pipeline/no-untrusted-checkout. No workflow triggered bypull_request_target,issue_commentorworkflow_runchecks out a revision of its own choosing, or passes the request's revision into a command.