config PRs: remove the hive's config-PR webhook, poll and core merge
An operator's merge on the forge deploys a config PR through
swarm-controller's DeployRequest{rev}. The hive-side path that queued a
MergeConfigPr approval and merged the PR as `core` goes:
- the `/webhook/config-pr` receiver, its HMAC secret, the WebhookRegister
boot node and the org-hook registration; the hive vhost's `/webhook/`
location
- the 5-minute config-PR poll
- ApprovalKind::MergeConfigPr, its dashboard card, and the deploy DAG it
drove (DeployWindow, MergeVerify, DeployApply, FinalizeDeploy,
DeployTail), with verify_commit, the two-phase meta deploy, rollback
refs, the PR-failure comment and forge/pr_merge.rs
- `fetched_sha`, `sha_short`/`pr_number` on approval events, and
`sha`/`tag` on HelperEvent::ApprovalResolved: only the merge path set
them
`config_repo`, `merged_pr_for_commit` and `post_pr_comment` move to
forge/pr_comment.rs for the merged-rev deploy's refusal comment.
Approvals v5 drops stored `merge_config_pr` rows; a test reopens a v4
database holding them.
Closes #4850
This commit is contained in:
parent
a5ea015bc6
commit
efbfec6d01
39 changed files with 286 additions and 3199 deletions
|
|
@ -137,8 +137,6 @@ export function applyApprovalAdded(ev) {
|
|||
id: ev.id,
|
||||
agent: ev.agent,
|
||||
kind: ev.approval_kind,
|
||||
sha_short: ev.sha_short || null,
|
||||
pr_number: ev.pr_number ?? null,
|
||||
description: ev.description || null,
|
||||
// The ApprovalAdded event carries no requested_at; a live-added
|
||||
// approval was queued just now, so client-now is accurate — and
|
||||
|
|
@ -163,7 +161,6 @@ export function applyApprovalResolved(ev) {
|
|||
id: ev.id,
|
||||
agent: ev.agent,
|
||||
kind: ev.approval_kind,
|
||||
sha_short: ev.sha_short || null,
|
||||
status: ev.status,
|
||||
resolved_at: ev.resolved_at,
|
||||
note: ev.note || null,
|
||||
|
|
@ -223,16 +220,8 @@ export function renderApprovals() {
|
|||
root.append(el("p", { class: "empty" }, "queue empty"));
|
||||
return;
|
||||
}
|
||||
// forge link base — only when the hive-forge container is up.
|
||||
const fs = window.__hyperhive_state;
|
||||
// state.forge_public_url (set from services.hyperhive.forge.publicUrl)
|
||||
// or null — never guessed from "<hostname>:3000". The PR-link builder
|
||||
// below already gates on forgeBase being truthy.
|
||||
const forgeBase = (fs && fs.forge_present && fs.forge_public_url) || null;
|
||||
|
||||
const ul = el("ul", { class: "approvals" });
|
||||
for (const a of pending) {
|
||||
const isMergePr = a.kind === "merge_config_pr";
|
||||
const isUpdateMeta = a.kind === "update_meta_inputs";
|
||||
const isSchedule = a.kind === "schedule_prompt";
|
||||
const li = el("li", { class: "approval-card" });
|
||||
|
|
@ -241,20 +230,11 @@ export function renderApprovals() {
|
|||
const head = el(
|
||||
"div",
|
||||
{ class: "approval-head" },
|
||||
el(
|
||||
"span",
|
||||
{ class: "glyph" },
|
||||
isUpdateMeta ? "↻" : isSchedule ? "⏱" : "⇒",
|
||||
),
|
||||
el("span", { class: "glyph" }, isUpdateMeta ? "↻" : "⏱"),
|
||||
el("span", { class: "id" }, "#" + a.id),
|
||||
el("span", { class: "agent" }, a.agent),
|
||||
el(
|
||||
"span",
|
||||
{ class: "kind" },
|
||||
isUpdateMeta ? "meta-update" : isSchedule ? "schedule" : "merge-pr",
|
||||
),
|
||||
el("span", { class: "kind" }, isUpdateMeta ? "meta-update" : "schedule"),
|
||||
);
|
||||
if (isMergePr && a.sha_short) head.append(el("code", {}, a.sha_short));
|
||||
// When the approval was requested — relative time, right-aligned.
|
||||
// Goes amber once it's been pending an hour so a stale request is
|
||||
// obvious at a glance (see docs/web-ui/dashboard.md::Approval card).
|
||||
|
|
@ -280,27 +260,7 @@ export function renderApprovals() {
|
|||
if (a.description) {
|
||||
body.append(el("div", { class: "approval-description" }, a.description));
|
||||
}
|
||||
if (isMergePr) {
|
||||
// PR-based config deploy: link to the reviewed PR on the forge.
|
||||
// The config diff lives on the forge PR itself.
|
||||
const drill = el("div", { class: "drill-ins" });
|
||||
if (forgeBase && a.pr_number != null) {
|
||||
drill.append(
|
||||
el(
|
||||
"a",
|
||||
{
|
||||
class: "panel-trigger",
|
||||
target: "_blank",
|
||||
rel: "noopener",
|
||||
href: `${forgeBase}/agent-configs/${a.agent}/pulls/${a.pr_number}`,
|
||||
title: "review this config PR on the hive forge",
|
||||
},
|
||||
"↳ review PR on forge ↗",
|
||||
),
|
||||
);
|
||||
}
|
||||
body.append(drill);
|
||||
} else if (isUpdateMeta) {
|
||||
if (isUpdateMeta) {
|
||||
let inputs;
|
||||
try {
|
||||
inputs = JSON.parse(a.commit_ref || "[]");
|
||||
|
|
@ -421,11 +381,7 @@ function renderApprovalHistory(root, history) {
|
|||
el(
|
||||
"span",
|
||||
{ class: "kind" },
|
||||
a.kind === "update_meta_inputs"
|
||||
? "meta-update"
|
||||
: a.kind === "schedule_prompt"
|
||||
? "schedule"
|
||||
: "merge-pr",
|
||||
a.kind === "update_meta_inputs" ? "meta-update" : "schedule",
|
||||
),
|
||||
" ",
|
||||
);
|
||||
|
|
|
|||
Loading…
Reference in a new issue