ci: refuse promoting the test feed branch into prod - #146
Merged
Merged
Conversation
The two feed branches differ on purpose and prod has a single writer, so merging updates-test into updates.simplerisk.com overwrites GA bundle checksums and adds hops for RCs that never shipped (#140, attempted again in #144). Add a check that fails a same-repo PR from updates-test into prod, and a README documenting the topic-branch path for one-off prod changes (#139, #145). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a check that refuses a PR from
updates-test.simplerisk.comintoupdates.simplerisk.com, plus a README documenting how to make one-off prod feed changes.Why
The two feed branches differ on purpose:
bundle_sha256for bundles the test channel no longer serves;update_feeds.shinsync_code_repo.yml) that records the real GA asset hashes.Merging the test branch into prod therefore replaces GA truth with RC truth. That happened in #140 (fixed by #141) and was attempted again in #144.
simplerisk/dockerfails closed on the resulting checksum mismatch.Validate feedcatches some of the damage after the fact; this refuses the promotion path itself.Change
.github/workflows/block-test-promotion.yml: jobBlock test-branch promotion into prod, runs on PRs intoupdates.simplerisk.comonly, fails when a same-repo PR's head isupdates-test.simplerisk.com. The failure message points to the topic-branch path. Fork branches of the same name are not affected.README.md: branch roles, "do not merge one into the other", and the steps for a one-off prod change (Updating VMs #139 and Updating VMs for SimpleRisk 20260917-001 #145 as worked examples). The S3 mirror uploads a fixed list of five manifests, so the README is not published.Verification
The script logic was exercised locally: a PR from
updates-testis refused; a PR from a topic branch passes; a fork branch with the same name passes.Follow-up (not in this PR)
Block test-branch promotion into proda required check on the prod ruleset only (it never runs on PRs into the test branch). It can't exist as a check until this merges.🤖 Generated with Claude Code