diff --git a/.github/workflows/track-branches.yml b/.github/workflows/track-branches.yml index cf063b2..e661220 100644 --- a/.github/workflows/track-branches.yml +++ b/.github/workflows/track-branches.yml @@ -9,11 +9,10 @@ name: Track upstream branches # and the merge publishes the artifacts. A tip that fails to build stays an # unmerged red PR that the next tick supersedes. # -# The PR is opened with a GitHub App token, not GITHUB_TOKEN: a pull request -# created with the workflow token gets its CI runs held for manual approval, -# and an auto-merge it enabled would not fire the publish workflow. The App -# needs Contents: write and Pull requests: write on this repository; its id -# and private key live in the PKGS_BOT_APP_ID / PKGS_BOT_PRIVATE_KEY secrets. +# The PR and auto-merge use the PAT in PKGS_BOT_TOKEN so they trigger the +# build and publish workflows. The built-in GITHUB_TOKEN cannot drive this +# unattended chain. The PAT needs Contents: write and Pull requests: write +# on this repository, and its owner must be trusted by the build workflow. on: schedule: @@ -39,13 +38,12 @@ jobs: contents: read steps: - - name: Require the bot App + - name: Require the tracking token env: - PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }} - PKGS_BOT_PRIVATE_KEY: ${{ secrets.PKGS_BOT_PRIVATE_KEY }} + PKGS_BOT_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }} run: | - if [[ -z "$PKGS_BOT_APP_ID" || -z "$PKGS_BOT_PRIVATE_KEY" ]]; then - echo "::error::Set PKGS_BOT_APP_ID and PKGS_BOT_PRIVATE_KEY for a GitHub App installed on this repository with Contents: write and Pull requests: write." + if [[ -z "$PKGS_BOT_TOKEN" ]]; then + echo "::error::Set PKGS_BOT_TOKEN to a PAT with Contents: write and Pull requests: write on this repository, owned by an account trusted to trigger builds." exit 1 fi @@ -103,14 +101,6 @@ jobs: } >> "$GITHUB_STEP_SUMMARY" fi - - name: Mint the bot token - if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }} - id: app - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 - with: - app-id: ${{ secrets.PKGS_BOT_APP_ID }} - private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }} - # The PR title names what moved, so the merged history reads like a # changelog: "Track upstream branches: omarchy-dev 4.0.0.r6520.g1a2b3c4, ...". - name: Describe the pins @@ -123,11 +113,11 @@ jobs: echo "title=Track upstream branches: ${title}" >> "$GITHUB_OUTPUT" - name: Open or update the tracking PR - if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' && steps.app.outcome == 'success' }} + if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }} id: pr uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: - token: ${{ steps.app.outputs.token }} + token: ${{ secrets.PKGS_BOT_TOKEN }} commit-message: ${{ steps.describe.outputs.title }} title: ${{ steps.describe.outputs.title }} body: | @@ -148,7 +138,7 @@ jobs: - name: Enable auto-merge if: ${{ !cancelled() && steps.pr.outputs.pull-request-number != '' }} env: - GH_TOKEN: ${{ steps.app.outputs.token }} + GH_TOKEN: ${{ secrets.PKGS_BOT_TOKEN }} PR: ${{ steps.pr.outputs.pull-request-number }} run: | # Idempotent across re-runs of an updated PR: enabling twice errors. diff --git a/README.md b/README.md index 9742113..4f1cba0 100644 --- a/README.md +++ b/README.md @@ -893,13 +893,13 @@ The repository includes GitHub workflows and systemd services for automated rele 2. **sync-rebuilds.yml** (Every 6 hours): Bumps pkgrel for packages whose `rebuild_on` dependencies have moved in the official repositories and opens a PR. 3. **track-branches.yml** (Every 2 hours): The unattended lane. Pins every `"auto_merge": true` package to the tip of its watched branch once its commit timestamp clears `min_release_age`, opens one PR for all of them, and enables auto-merge. Packages pinned from the same branch move together or not at all, including targeted syncs. The PR builds like any other; a tip that fails to build stays an open red PR until the next tick supersedes it. -The tracking PR is opened with a GitHub App token (`PKGS_BOT_APP_ID` and -`PKGS_BOT_PRIVATE_KEY` secrets; the App needs Contents and Pull requests -write on this repository). A PR opened with the workflow's own `GITHUB_TOKEN` -has its build and test runs held until a maintainer approves them, and an -auto-merge it enabled would land without running the publish workflow. The -tracker requires both App secrets before it runs. The reviewed sync workflows -continue to use `GITHUB_TOKEN` and require maintainer approval as before. +The tracking PR and auto-merge use the PAT stored in `PKGS_BOT_TOKEN`, with +Contents and Pull requests write access to this repository and an owner trusted +to trigger builds. The existing controller PAT can be reused. No GitHub App is +required. The built-in Actions `GITHUB_TOKEN` cannot drive the unattended +build-and-publish chain, so the tracker requires this secret before it runs. +The reviewed sync workflows continue to use `GITHUB_TOKEN` and require +maintainer approval as before. See [setup instructions](docs/upstream-sources.md#enable-unattended-branch-updates). To approve builds for an unvouched contributor's PR, apply **`build-approved`**. Until approval, the PR shows **Awaiting build approval** and its required diff --git a/docs/upstream-sources.md b/docs/upstream-sources.md index 1749ee9..4397336 100644 --- a/docs/upstream-sources.md +++ b/docs/upstream-sources.md @@ -89,21 +89,20 @@ only `omarchy-dev` also updates `omarchy-settings-dev`. ### Enable unattended branch updates The schedule already runs in GitHub Actions; no server cron job is needed. -It needs a GitHub App identity so its PRs trigger builds and its merges trigger -publishing without manual approval: +It uses a personal access token so its PRs trigger builds and its merges trigger +publishing without manual approval. No GitHub App is required. -1. [Create an organization GitHub App](https://github.com/organizations/omacom/settings/apps/new). - Use this repository's URL as the homepage, disable webhooks, and grant only - repository **Contents: Read and write** and **Pull requests: Read and write** - (Metadata read access is automatic). Limit installation to this organization. -2. Install the App on **omacom/omarchy-pkgs** only. -3. Generate a private key from the App's settings. In the repository's +1. Use a fine-grained PAT with access to **omacom/omarchy-pkgs** and repository + **Contents: Read and write** and **Pull requests: Read and write** permissions. + Its owner must be trusted by the build workflow (for example, a collaborator). + The existing controller PAT can be reused when it has these permissions. +2. In the repository's [Actions secrets](https://github.com/omacom/omarchy-pkgs/settings/secrets/actions), - save the App ID as `PKGS_BOT_APP_ID` and the PEM key contents as - `PKGS_BOT_PRIVATE_KEY`. -4. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and - `build-isolation` on `master`; the App does not need a protection bypass. -5. After merging the tracker, run **Track upstream branches** once from Actions + save the PAT as `PKGS_BOT_TOKEN`. Update this secret when the token is rotated + or expires. The built-in Actions `GITHUB_TOKEN` cannot run this unattended chain. +3. Keep **Allow auto-merge** enabled and require `result`, `self-tests`, and + `build-isolation` on `master`; the tracker does not request a protection bypass. +4. After merging the tracker, run **Track upstream branches** once from Actions to verify that its PR builds, auto-merges, and starts **Publish merged packages**. Subsequent runs happen every two hours.