Skip to content

ci: refuse promoting the test feed branch into prod - #146

Merged
jsokol merged 1 commit into
updates.simplerisk.comfrom
guard-test-promotion
Sep 30, 2026
Merged

jsokol merged 1 commit into
updates.simplerisk.comfrom
guard-test-promotion

Conversation

@jsokol

@jsokol jsokol commented Sep 30, 2026

Copy link
Copy Markdown
Member

Adds a check that refuses a PR from updates-test.simplerisk.com into updates.simplerisk.com, plus a README documenting how to make one-off prod feed changes.

Why

The two feed branches differ on purpose:

  • the testing pipeline retracts unpromoted RCs, keeps their upgrade hops, and blanks bundle_sha256 for bundles the test channel no longer serves;
  • the prod feed has a single writer (update_feeds.sh in sync_code_repo.yml) that records the real GA asset hashes.

Merging the test branch into prod therefore replaces GA truth with RC truth. That happened in #140 (fixed by #141) and was attempted again in #144. simplerisk/docker fails closed on the resulting checksum mismatch. Validate feed catches some of the damage after the fact; this refuses the promotion path itself.

Change

  • .github/workflows/block-test-promotion.yml: job Block test-branch promotion into prod, runs on PRs into updates.simplerisk.com only, fails when a same-repo PR's head is updates-test.simplerisk.com. The failure message points to the topic-branch path. Fork branches of the same name are not affected.
  • README.md: branch roles, "do not merge one into the other", and the steps for a one-off prod change (Updating VMs #139 and Updating VMs for SimpleRisk 20260917-001 #145 as worked examples). The S3 mirror uploads a fixed list of five manifests, so the README is not published.

Verification

The script logic was exercised locally: a PR from updates-test is refused; a PR from a topic branch passes; a fork branch with the same name passes.

Follow-up (not in this PR)

  • Make Block test-branch promotion into prod a required check on the prod ruleset only (it never runs on PRs into the test branch). It can't exist as a check until this merges.
  • Admins have "always" bypass on both rulesets, so this makes a promotion a conscious act rather than preventing it. The durable fix is the VM-digest script writing to a topic branch off prod.

🤖 Generated with Claude Code

The two feed branches differ on purpose and prod has a single writer, so merging
updates-test into updates.simplerisk.com overwrites GA bundle checksums and adds
hops for RCs that never shipped (#140, attempted again in #144). Add a check that
fails a same-repo PR from updates-test into prod, and a README documenting the
topic-branch path for one-off prod changes (#139, #145).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@jsokol
jsokol marked this pull request as ready for review September 30, 2026 20:28
@jsokol
jsokol merged commit 9b69b69 into updates.simplerisk.com Sep 30, 2026
2 checks passed
@jsokol
jsokol deleted the guard-test-promotion branch September 30, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant