Use the existing controller PAT for branch tracking
This commit is contained in:
1 parent
7fe542cde7
commit
13ed2e9f8d
3 files changed
+30
-41
No files matched your search
@@ -9,11 +9,10 @@ name: Track upstream branches
|
||||
# and the merge publishes the artifacts. A tip that fails to build stays an
|
||||
# unmerged red PR that the next tick supersedes.
|
||||
#
|
||||
# The PR is opened with a GitHub App token, not GITHUB_TOKEN: a pull request
|
||||
# created with the workflow token gets its CI runs held for manual approval,
|
||||
# and an auto-merge it enabled would not fire the publish workflow. The App
|
||||
# needs Contents: write and Pull requests: write on this repository; its id
|
||||
# and private key live in the PKGS_BOT_APP_ID / PKGS_BOT_PRIVATE_KEY secrets.
|
||||
# The PR and auto-merge use the PAT in PKGS_BOT_TOKEN so they trigger the
|
||||
# build and publish workflows. The built-in GITHUB_TOKEN cannot drive this
|
||||
# unattended chain. The PAT needs Contents: write and Pull requests: write
|
||||
# on this repository, and its owner must be trusted by the build workflow.
|
||||
|
||||
on:
|
||||
schedule:
|
||||
@@ -39,13 +38,12 @@ jobs:
|
||||
contents: read
|
||||
|
||||
steps:
|
||||
- name: Require the bot App
|
||||
- name: Require the tracking token
|
||||
env:
|
||||
PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }}
|
||||
PKGS_BOT_PRIVATE_KEY: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
|
||||
PKGS_BOT_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }}
|
||||
run: |
|
||||
if [[ -z "$PKGS_BOT_APP_ID" || -z "$PKGS_BOT_PRIVATE_KEY" ]]; then
|
||||
echo "::error::Set PKGS_BOT_APP_ID and PKGS_BOT_PRIVATE_KEY for a GitHub App installed on this repository with Contents: write and Pull requests: write."
|
||||
if [[ -z "$PKGS_BOT_TOKEN" ]]; then
|
||||
echo "::error::Set PKGS_BOT_TOKEN to a PAT with Contents: write and Pull requests: write on this repository, owned by an account trusted to trigger builds."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -103,14 +101,6 @@ jobs:
|
||||
} >> "$GITHUB_STEP_SUMMARY"
|
||||
fi
|
||||
|
||||
- name: Mint the bot token
|
||||
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
|
||||
id: app
|
||||
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
|
||||
with:
|
||||
app-id: ${{ secrets.PKGS_BOT_APP_ID }}
|
||||
private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
|
||||
|
||||
# The PR title names what moved, so the merged history reads like a
|
||||
# changelog: "Track upstream branches: omarchy-dev 4.0.0.r6520.g1a2b3c4, ...".
|
||||
- name: Describe the pins
|
||||
@@ -123,11 +113,11 @@ jobs:
|
||||
echo "title=Track upstream branches: ${title}" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Open or update the tracking PR
|
||||
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' && steps.app.outcome == 'success' }}
|
||||
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
|
||||
id: pr
|
||||
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
|
||||
with:
|
||||
token: ${{ steps.app.outputs.token }}
|
||||
token: ${{ secrets.PKGS_BOT_TOKEN }}
|
||||
commit-message: ${{ steps.describe.outputs.title }}
|
||||
title: ${{ steps.describe.outputs.title }}
|
||||
body: |
|
||||
@@ -148,7 +138,7 @@ jobs:
|
||||
- name: Enable auto-merge
|
||||
if: ${{ !cancelled() && steps.pr.outputs.pull-request-number != '' }}
|
||||
env:
|
||||
GH_TOKEN: ${{ steps.app.outputs.token }}
|
||||
GH_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }}
|
||||
PR: ${{ steps.pr.outputs.pull-request-number }}
|
||||
run: |
|
||||
# Idempotent across re-runs of an updated PR: enabling twice errors.
|
||||
|
||||
@@ -893,13 +893,13 @@ The repository includes GitHub workflows and systemd services for automated rele
|
||||
2. **sync-rebuilds.yml** (Every 6 hours): Bumps pkgrel for packages whose `rebuild_on` dependencies have moved in the official repositories and opens a PR.
|
||||
3. **track-branches.yml** (Every 2 hours): The unattended lane. Pins every `"auto_merge": true` package to the tip of its watched branch once its commit timestamp clears `min_release_age`, opens one PR for all of them, and enables auto-merge. Packages pinned from the same branch move together or not at all, including targeted syncs. The PR builds like any other; a tip that fails to build stays an open red PR until the next tick supersedes it.
|
||||
|
||||
The tracking PR is opened with a GitHub App token (`PKGS_BOT_APP_ID` and
|
||||
`PKGS_BOT_PRIVATE_KEY` secrets; the App needs Contents and Pull requests
|
||||
write on this repository). A PR opened with the workflow's own `GITHUB_TOKEN`
|
||||
has its build and test runs held until a maintainer approves them, and an
|
||||
auto-merge it enabled would land without running the publish workflow. The
|
||||
tracker requires both App secrets before it runs. The reviewed sync workflows
|
||||
continue to use `GITHUB_TOKEN` and require maintainer approval as before.
|
||||
The tracking PR and auto-merge use the PAT stored in `PKGS_BOT_TOKEN`, with
|
||||
Contents and Pull requests write access to this repository and an owner trusted
|
||||
to trigger builds. The existing controller PAT can be reused. No GitHub App is
|
||||
required. The built-in Actions `GITHUB_TOKEN` cannot drive the unattended
|
||||
build-and-publish chain, so the tracker requires this secret before it runs.
|
||||
The reviewed sync workflows continue to use `GITHUB_TOKEN` and require
|
||||
maintainer approval as before. See [setup instructions](docs/upstream-sources.md#enable-unattended-branch-updates).
|
||||
|
||||
To approve builds for an unvouched contributor's PR, apply **`build-approved`**.
|
||||
Until approval, the PR shows **Awaiting build approval** and its required
|
||||
|
||||
+12
-13
@@ -89,21 +89,20 @@ only `omarchy-dev` also updates `omarchy-settings-dev`.
|
||||
### Enable unattended branch updates
|
||||
|
||||
The schedule already runs in GitHub Actions; no server cron job is needed.
|
||||
It needs a GitHub App identity so its PRs trigger builds and its merges trigger
|
||||
publishing without manual approval:
|
||||
It uses a personal access token so its PRs trigger builds and its merges trigger
|
||||
publishing without manual approval. No GitHub App is required.
|
||||
|
||||
1. [Create an organization GitHub App](https://github.com/organizations/omacom/settings/apps/new).
|
||||
Use this repository's URL as the homepage, disable webhooks, and grant only
|
||||
repository **Contents: Read and write** and **Pull requests: Read and write**
|
||||
(Metadata read access is automatic). Limit installation to this organization.
|
||||
2. Install the App on **omacom/omarchy-pkgs** only.
|
||||
3. Generate a private key from the App's settings. In the repository's
|
||||
1. Use a fine-grained PAT with access to **omacom/omarchy-pkgs** and repository
|
||||
**Contents: Read and write** and **Pull requests: Read and write** permissions.
|
||||
Its owner must be trusted by the build workflow (for example, a collaborator).
|
||||
The existing controller PAT can be reused when it has these permissions.
|
||||
2. In the repository's
|
||||
[Actions secrets](https://github.com/omacom/omarchy-pkgs/settings/secrets/actions),
|
||||
save the App ID as `PKGS_BOT_APP_ID` and the PEM key contents as
|
||||
`PKGS_BOT_PRIVATE_KEY`.
|
||||
4. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and
|
||||
`build-isolation` on `master`; the App does not need a protection bypass.
|
||||
5. After merging the tracker, run **Track upstream branches** once from Actions
|
||||
save the PAT as `PKGS_BOT_TOKEN`. Update this secret when the token is rotated
|
||||
or expires. The built-in Actions `GITHUB_TOKEN` cannot run this unattended chain.
|
||||
3. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and
|
||||
`build-isolation` on `master`; the tracker does not request a protection bypass.
|
||||
4. After merging the tracker, run **Track upstream branches** once from Actions
|
||||
to verify that its PR builds, auto-merges, and starts **Publish merged packages**.
|
||||
Subsequent runs happen every two hours.
|
||||
|
||||
|
||||
Reference in new issue
Block a user