summaryrefslogtreecommitdiff
path: root/.github/workflows/pr-mirror-repo-sync.yml
AgeCommit message (Collapse)Author
2026-05-31T8943: feat(mirror-rollout-2): adopt uniform wrapper stub (#35)Yuriy Andamasov
Per Mirror Pipeline Redesign Rollout 2: standardize the wrapper to the canonical stub. Inclusion + kill-switch logic moves into the central workflow + consumers.yaml; this wrapper is now a thin pass-through. Changes from post-1b wrapper: - branches: [rolling] -> [rolling, production] (heterogeneous fleet) - permissions: contents:write/pull-requests:write/issues:write -> contents:read (no side effects in wrapper; central workflow holds write perms via App tokens — see vyos/.github canonical stub permissions fix vyos/.github#133) - Remove 'vars.MIRROR_ENABLED != false' gate from wrapper if: clause (kill-switch enforced in central workflow's check-consumer-inclusion + per-side-effect re-checks) Spec: /Users/syncer/.claude/specs/2026-05-16-mirror-pipeline-redesign-design.md §4.2.3 Permissions fix spec: /Users/syncer/.claude/specs/2026-05-30-canonical-stub-permissions-fix-design.md Plan: /Users/syncer/.claude/plans/2026-05-17-mirror-pipeline-rollout-2-inclusion-mechanism.md Task 6 Permissions fix plan: /Users/syncer/.claude/plans/2026-05-30-canonical-stub-permissions-fix.md 🤖 Generated by [robots](https://vyos.io)
2026-05-30T8943: revert(mirror-rollout-2): restore post-1b wrapper on ipaddrcheck (#34)Yuriy Andamasov
PR #33 broke this consumer's mirror with startup_failure. Root cause: GitHub's reusable-workflow permissions model. The canonical stub set permissions: contents:read but the central reusable workflow declares contents:write/pull-requests:write/issues:write at top level. Per docs: 'If you specify the access for any of these scopes at a level less than the permissions defined by the called workflow, the entire workflow will fail.' Restoring the post-1b wrapper while we update the canonical stub design (either drop central's top-level permissions block, or keep write perms in the wrapper). 🤖 Generated by [robots](https://vyos.io)
2026-05-30T8943: feat(mirror-rollout-2): adopt uniform wrapper stub (#33)Yuriy Andamasov
Per Mirror Pipeline Redesign Rollout 2: standardize the wrapper to the canonical stub. Inclusion + kill-switch logic moves into the central workflow + consumers.yaml; this wrapper is now a thin pass-through. Changes from post-1b wrapper: - branches: [rolling] -> [rolling, production] (broaden trigger for heterogeneous default-branch fleet; central + consumers.yaml gate the actual mirror) - permissions: contents:write/pull-requests:write/issues:write -> contents:read (no side effects in wrapper; central workflow holds write perms via App tokens) - Remove 'vars.MIRROR_ENABLED != false' gate from wrapper if: clause (kill-switch now enforced inside check-consumer-inclusion job + per-side-effect re-checks in process-unmirrored-PR) Spec: ~/.claude/specs/2026-05-16-mirror-pipeline-redesign-design.md §4.2.3 Plan: ~/.claude/plans/2026-05-17-mirror-pipeline-rollout-2-inclusion-mechanism.md Task 6 🤖 Generated by [robots](https://vyos.io)
2026-05-30ci: T8943: migrate branch-name refs current->rolling (rollout 1c) (#32)Yuriy Andamasov
Rollout 1c reference migration on vyos/ipaddrcheck prior to the default- branch rename. Updates this repo's own trunk references current->rolling: pr-mirror trigger branches, trigger-rebuild trigger branches (LTS entries kept), and the AGENTS.md branch-model note. HIGH-producer pins were already swept to @production in Task 2. Tracking: T8943
2026-05-30ci: T8943: sweep HIGH-producer pins to renamed branches (rollout 1c) (#31)Yuriy Andamasov
Rewrites uses: pins to the three HIGH-fanout producers (vyos/.github, vyos/vyos-cla-signatures, VyOS-Networks/vyos-reusable-workflows) from their old default branch to the new production compat branch staged in Task 1. No functional change; pin-ref rewrite only. Tracking: T8943
2026-05-30T8943: migrate mirror wrapper to App-ready uniform stub (rollout 1b Task 5 ↵HEADcurrentYuriy Andamasov
canary) (#30) Switch from explicit `secrets: PAT/REMOTE_OWNER` pass-through to `secrets: inherit`, and adopt the uniform stub shape. Behavior-neutral against the current PAT-using central workflow (`inherit` populates `PAT`/`REMOTE_OWNER` by name from org-level secrets); prepares for the App-token central-workflow update (Task 7). First (canary) consumer of the 25-repo Task 5 migration. Plan: ~/.claude/plans/2026-05-26-mirror-rollout-1b-revised.md Task 5
2026-03-18T8403: enabled PR mirroringkumvijaya