Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/auto-ff-matrix-pilot-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ on:
- completed

permissions:
actions: write
contents: write
pull-requests: write

Expand Down Expand Up @@ -126,3 +127,10 @@ jobs:
fi

git push origin "${actual_head}:refs/heads/${BASE_BRANCH}"

- name: Dispatch deployment mirror
if: steps.checks.outputs.ready == 'true'
env:
GH_TOKEN: ${{ github.token }}
run: |
gh workflow run mirror-to-deployment-target.yml --ref "${BASE_BRANCH}"
1 change: 1 addition & 0 deletions .github/workflows/mirror-to-deployment-target.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
name: Mirror to deployment target

on:
workflow_dispatch:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Guard deployment mirror dispatch to pilot refs

Adding workflow_dispatch makes this workflow runnable on any branch selected for the manual/API dispatch; GitHub documents that manual runs choose a branch/ref and GITHUB_SHA comes from that dispatched ref. Because the job has no github.ref_name == 'native-matrix-channel-pilot' guard before it checks out and mirrors the tree with the deployment App credentials, a manual dispatch on main or a feature branch can create/update the deployment mirror PR from source that did not pass the existing pilot fast-forward gate. Please reject non-pilot refs before generating the mirror token or performing the mirror.

Useful? React with 👍 / 👎.

push:
branches:
- native-matrix-channel-pilot
Expand Down
41 changes: 41 additions & 0 deletions scripts/test-auto-ff-matrix-pilot-sync-workflow.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
#!/usr/bin/env bash
set -euo pipefail

cd "$(dirname "$0")/.."

workflow=".github/workflows/auto-ff-matrix-pilot-sync.yml"
mirror_workflow=".github/workflows/mirror-to-deployment-target.yml"

if [[ ! -f "${workflow}" ]]; then
echo "missing ${workflow}"
exit 1
fi

if [[ ! -f "${mirror_workflow}" ]]; then
echo "missing ${mirror_workflow}"
exit 1
fi

require_in() {
local file="$1"
local pattern="$2"
local description="$3"
if ! grep -Eq -- "${pattern}" "${file}"; then
echo "missing ${description}: ${pattern}"
exit 1
fi
}

require_in "${workflow}" 'name:[[:space:]]*Auto fast-forward Matrix pilot sync' "workflow name"
require_in "${workflow}" 'workflow_run:' "workflow-run trigger"
require_in "${workflow}" 'actions:[[:space:]]*write' "Actions write permission for workflow dispatch"
require_in "${workflow}" 'BASE_BRANCH:[[:space:]]*native-matrix-channel-pilot' "Matrix pilot branch"
require_in "${workflow}" 'git push origin "\$\{actual_head\}:refs/heads/\$\{BASE_BRANCH\}"' "pilot branch fast-forward"
require_in "${workflow}" 'name:[[:space:]]*Dispatch deployment mirror' "post-fast-forward mirror dispatch step"
require_in "${workflow}" 'GH_TOKEN:[[:space:]]*\$\{\{ github\.token \}\}' "dispatch token"
require_in "${workflow}" 'gh workflow run mirror-to-deployment-target\.yml --ref "\$\{BASE_BRANCH\}"' "explicit deployment mirror dispatch"
require_in "${mirror_workflow}" 'workflow_dispatch:' "manual mirror dispatch trigger"
require_in "${mirror_workflow}" 'branches:' "push trigger branch restriction"
require_in "${mirror_workflow}" 'native-matrix-channel-pilot' "Matrix pilot push trigger"

echo "auto-ff Matrix pilot workflow contract OK"
Loading