fix(forge): config-repo main is fast-forward-only (no auto force-push)

Per operator directive: a silent automatic force-push is a bug. The
config-repo merge path already never force-pushes (run_merge_config_pr
lands via ff_push_to_main, a non-force git push). So set the branch
protection's enable_force_push to false — main only ever advances by
fast-forward.

The legacy push_config mirror does force-push (it re-points the status
tags and rewinds main on a failed-build rollback); the protection now
rejects those non-ff updates, so the mirror runs best-effort until the
agent-opened PR-merge flow retires it. Docs + comments updated to match.
This commit is contained in:
atlas 2026-06-23 22:24:23 +02:00 committed by mara
commit 5caec9c1a9
2 changed files with 18 additions and 16 deletions

View file

@ -56,10 +56,11 @@ Two things live in the `agent-configs` Forgejo organization:
config-change branches and (once #1838 P2 lands) open config PRs — but
`main` is branch-protected core-only: only hive-c0re's verify-and-ff-push
merge handler lands on `main`, an operator-team approval is required, and
the agent can neither push `main` directly nor self-merge. During the
transition c0re still force-mirrors the agent's applied config repo here
on each `↻ R3BU1LD` (the `enable_force_push` allowance), until the PR
flow replaces that. Repos stay private, so an agent can't read another
the agent can neither push `main` directly nor self-merge. `main` is
fast-forward-only — no auto force-push (the merge handler's ff push lands
fine; the legacy `push_config` mirror, which force-pushes to re-point status
tags and rewind on rollback, runs best-effort until the PR flow retires it).
Repos stay private, so an agent can't read another
agent's config. (Agents remain read-only collaborators on `core/meta`.)
- The dashboard links each container's "config" anchor to this
config repo, so operators can click straight from the SW4RM tab into