Use the existing controller PAT for branch tracking

This commit is contained in:
Ryan Hughes committed 2026-09-27 12:39:53 -04:00
1 parent 7fe542cde7
commit 13ed2e9f8d
3 files changed
+30 -41

No files matched your search

+11 -21
View File
@@ -9,11 +9,10 @@ name: Track upstream branches
# and the merge publishes the artifacts. A tip that fails to build stays an
# unmerged red PR that the next tick supersedes.
#
# The PR is opened with a GitHub App token, not GITHUB_TOKEN: a pull request
# created with the workflow token gets its CI runs held for manual approval,
# and an auto-merge it enabled would not fire the publish workflow. The App
# needs Contents: write and Pull requests: write on this repository; its id
# and private key live in the PKGS_BOT_APP_ID / PKGS_BOT_PRIVATE_KEY secrets.
# The PR and auto-merge use the PAT in PKGS_BOT_TOKEN so they trigger the
# build and publish workflows. The built-in GITHUB_TOKEN cannot drive this
# unattended chain. The PAT needs Contents: write and Pull requests: write
# on this repository, and its owner must be trusted by the build workflow.
on:
schedule:
@@ -39,13 +38,12 @@ jobs:
contents: read
steps:
- name: Require the bot App
- name: Require the tracking token
env:
PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }}
PKGS_BOT_PRIVATE_KEY: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
PKGS_BOT_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }}
run: |
if [[ -z "$PKGS_BOT_APP_ID" || -z "$PKGS_BOT_PRIVATE_KEY" ]]; then
echo "::error::Set PKGS_BOT_APP_ID and PKGS_BOT_PRIVATE_KEY for a GitHub App installed on this repository with Contents: write and Pull requests: write."
if [[ -z "$PKGS_BOT_TOKEN" ]]; then
echo "::error::Set PKGS_BOT_TOKEN to a PAT with Contents: write and Pull requests: write on this repository, owned by an account trusted to trigger builds."
exit 1
fi
@@ -103,14 +101,6 @@ jobs:
} >> "$GITHUB_STEP_SUMMARY"
fi
- name: Mint the bot token
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
id: app
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.PKGS_BOT_APP_ID }}
private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
# The PR title names what moved, so the merged history reads like a
# changelog: "Track upstream branches: omarchy-dev 4.0.0.r6520.g1a2b3c4, ...".
- name: Describe the pins
@@ -123,11 +113,11 @@ jobs:
echo "title=Track upstream branches: ${title}" >> "$GITHUB_OUTPUT"
- name: Open or update the tracking PR
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' && steps.app.outcome == 'success' }}
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
id: pr
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ steps.app.outputs.token }}
token: ${{ secrets.PKGS_BOT_TOKEN }}
commit-message: ${{ steps.describe.outputs.title }}
title: ${{ steps.describe.outputs.title }}
body: |
@@ -148,7 +138,7 @@ jobs:
- name: Enable auto-merge
if: ${{ !cancelled() && steps.pr.outputs.pull-request-number != '' }}
env:
GH_TOKEN: ${{ steps.app.outputs.token }}
GH_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }}
PR: ${{ steps.pr.outputs.pull-request-number }}
run: |
# Idempotent across re-runs of an updated PR: enabling twice errors.
+7 -7
View File
@@ -893,13 +893,13 @@ The repository includes GitHub workflows and systemd services for automated rele
2. **sync-rebuilds.yml** (Every 6 hours): Bumps pkgrel for packages whose `rebuild_on` dependencies have moved in the official repositories and opens a PR.
3. **track-branches.yml** (Every 2 hours): The unattended lane. Pins every `"auto_merge": true` package to the tip of its watched branch once its commit timestamp clears `min_release_age`, opens one PR for all of them, and enables auto-merge. Packages pinned from the same branch move together or not at all, including targeted syncs. The PR builds like any other; a tip that fails to build stays an open red PR until the next tick supersedes it.
The tracking PR is opened with a GitHub App token (`PKGS_BOT_APP_ID` and
`PKGS_BOT_PRIVATE_KEY` secrets; the App needs Contents and Pull requests
write on this repository). A PR opened with the workflow's own `GITHUB_TOKEN`
has its build and test runs held until a maintainer approves them, and an
auto-merge it enabled would land without running the publish workflow. The
tracker requires both App secrets before it runs. The reviewed sync workflows
continue to use `GITHUB_TOKEN` and require maintainer approval as before.
The tracking PR and auto-merge use the PAT stored in `PKGS_BOT_TOKEN`, with
Contents and Pull requests write access to this repository and an owner trusted
to trigger builds. The existing controller PAT can be reused. No GitHub App is
required. The built-in Actions `GITHUB_TOKEN` cannot drive the unattended
build-and-publish chain, so the tracker requires this secret before it runs.
The reviewed sync workflows continue to use `GITHUB_TOKEN` and require
maintainer approval as before. See [setup instructions](docs/upstream-sources.md#enable-unattended-branch-updates).
To approve builds for an unvouched contributor's PR, apply **`build-approved`**.
Until approval, the PR shows **Awaiting build approval** and its required
+12 -13
View File
@@ -89,21 +89,20 @@ only `omarchy-dev` also updates `omarchy-settings-dev`.
### Enable unattended branch updates
The schedule already runs in GitHub Actions; no server cron job is needed.
It needs a GitHub App identity so its PRs trigger builds and its merges trigger
publishing without manual approval:
It uses a personal access token so its PRs trigger builds and its merges trigger
publishing without manual approval. No GitHub App is required.
1. [Create an organization GitHub App](https://github.com/organizations/omacom/settings/apps/new).
Use this repository's URL as the homepage, disable webhooks, and grant only
repository **Contents: Read and write** and **Pull requests: Read and write**
(Metadata read access is automatic). Limit installation to this organization.
2. Install the App on **omacom/omarchy-pkgs** only.
3. Generate a private key from the App's settings. In the repository's
1. Use a fine-grained PAT with access to **omacom/omarchy-pkgs** and repository
**Contents: Read and write** and **Pull requests: Read and write** permissions.
Its owner must be trusted by the build workflow (for example, a collaborator).
The existing controller PAT can be reused when it has these permissions.
2. In the repository's
[Actions secrets](https://github.com/omacom/omarchy-pkgs/settings/secrets/actions),
save the App ID as `PKGS_BOT_APP_ID` and the PEM key contents as
`PKGS_BOT_PRIVATE_KEY`.
4. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and
`build-isolation` on `master`; the App does not need a protection bypass.
5. After merging the tracker, run **Track upstream branches** once from Actions
save the PAT as `PKGS_BOT_TOKEN`. Update this secret when the token is rotated
or expires. The built-in Actions `GITHUB_TOKEN` cannot run this unattended chain.
3. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and
`build-isolation` on `master`; the tracker does not request a protection bypass.
4. After merging the tracker, run **Track upstream branches** once from Actions
to verify that its PR builds, auto-merges, and starts **Publish merged packages**.
Subsequent runs happen every two hours.