docs: config changes are operator merges on the forge
Rewrites the config-change flow around the forge merge and the
DeployRequest{rev} deploy, drops the MergeConfigPr approval, its deploy
DAG, the hive's `/webhook/` route and the `core` merge allowlist from
the docs, and states that operators join the `operators` team by hand.
Refs #4850
This commit is contained in:
parent
0cee0382e9
commit
a88ed9f24e
14 changed files with 195 additions and 396 deletions
|
|
@ -67,22 +67,15 @@ Two things live in the `agent-configs` Forgejo organization:
|
|||
|
||||
- A config repo per agent (`agent-configs/<name>`). The
|
||||
agent is a **write collaborator on its own** repo — it can push
|
||||
config-change branches and open config PRs (Forgejo `pull_request`
|
||||
webhook at `/webhook/config-pr` queues a `MergeConfigPr` approval;
|
||||
`hive-c0re/src/forge/config_pr_poll.rs` re-scans every 5 minutes as a
|
||||
fault-tolerance backstop) — but
|
||||
`main` is branch-protected: the merge whitelist is the `core` user
|
||||
(hive-c0re's merge of an approved `MergeConfigPr`) and the `operators`
|
||||
team (an operator merging in the Forgejo UI, which deploys the merged
|
||||
commit — see
|
||||
[approvals.md § Operator merge in the forge UI](../agent-lifecycle/approvals.md#operator-merge-in-the-forge-ui)),
|
||||
the approval whitelist is the `operators` team, and the agent can neither
|
||||
push `main` directly nor self-merge. hive-c0re's own merge is
|
||||
fast-forward-only, and hive-c0re never force-pushes (the
|
||||
`push_config` mirror pushes `main` + the add-only
|
||||
status tags without force, and treats a non-fast-forward rejection of
|
||||
`main` after a rolled-back deploy as expected — the forge keeps the
|
||||
approved history, the `failed/<id>` tag records the divergence).
|
||||
config-change branches and open config PRs — but `main` is
|
||||
branch-protected by swarm-controller: the merge and approval
|
||||
allowlists are the `operators` team, and the agent can neither push
|
||||
`main` directly nor self-merge. An operator's merge in the Forgejo UI
|
||||
deploys the merged commit (see
|
||||
[approvals.md § Config changes](../agent-lifecycle/approvals.md#config-changes)).
|
||||
hive-c0re never force-pushes: the `push_config` mirror pushes the
|
||||
add-only status tags and `main` without force, and treats a refused
|
||||
`main` push as expected.
|
||||
Repos stay private, so an agent can't read another
|
||||
agent's config. (Agents remain read-only collaborators on `core/meta`.)
|
||||
hive-c0re also references this repo as the agent's **persistent meta
|
||||
|
|
|
|||
Loading…
Reference in a new issue