config PRs: remove the hive's config-PR webhook, poll and core merge
An operator's merge on the forge deploys a config PR through
swarm-controller's DeployRequest{rev}. The hive-side path that queued a
MergeConfigPr approval and merged the PR as `core` goes:
- the `/webhook/config-pr` receiver, its HMAC secret, the WebhookRegister
boot node and the org-hook registration; the hive vhost's `/webhook/`
location
- the 5-minute config-PR poll
- ApprovalKind::MergeConfigPr, its dashboard card, and the deploy DAG it
drove (DeployWindow, MergeVerify, DeployApply, FinalizeDeploy,
DeployTail), with verify_commit, the two-phase meta deploy, rollback
refs, the PR-failure comment and forge/pr_merge.rs
- `fetched_sha`, `sha_short`/`pr_number` on approval events, and
`sha`/`tag` on HelperEvent::ApprovalResolved: only the merge path set
them
`config_repo`, `merged_pr_for_commit` and `post_pr_comment` move to
forge/pr_comment.rs for the merged-rev deploy's refusal comment.
Approvals v5 drops stored `merge_config_pr` rows; a test reopens a v4
database holding them.
Closes #4850
This commit is contained in:
parent
a5ea015bc6
commit
efbfec6d01
39 changed files with 286 additions and 3199 deletions
|
|
@ -45,7 +45,6 @@ use crate::lifecycle;
|
|||
(name = "state_files", description = "proxied reads of allow-listed per-agent state files"),
|
||||
(name = "state_snapshot", description = "cold-load dashboard snapshot"),
|
||||
(name = "tombstones", description = "purge of retained state for destroyed agents"),
|
||||
(name = "webhook", description = "forgejo webhook receivers"),
|
||||
)
|
||||
)]
|
||||
struct ApiDoc;
|
||||
|
|
@ -67,7 +66,6 @@ mod schedules;
|
|||
mod state_files;
|
||||
mod state_snapshot;
|
||||
mod tombstones;
|
||||
mod webhook;
|
||||
|
||||
// Run after lock bumps by the job queue (`job_queue/exec.rs`); the view
|
||||
// type feeds `DashboardEvent::MetaInputsChanged` (`dashboard_events.rs`).
|
||||
|
|
@ -87,11 +85,6 @@ pub(crate) use tombstones::emit_tombstones_snapshot;
|
|||
#[derive(Clone)]
|
||||
struct AppState {
|
||||
coord: Arc<Coordinator>,
|
||||
/// HMAC-SHA256 secret shared with Forgejo webhook registrations.
|
||||
/// Verified on every incoming `/webhook/*` POST.
|
||||
/// `None` when the secret could not be loaded at startup — all
|
||||
/// `/webhook/*` requests are rejected with 503 in that case.
|
||||
webhook_secret: Option<String>,
|
||||
}
|
||||
|
||||
#[allow(
|
||||
|
|
@ -101,11 +94,7 @@ struct AppState {
|
|||
handler; splitting that exhaustive list across helpers would \
|
||||
obscure the route map for no readability gain"
|
||||
)]
|
||||
pub async fn serve(
|
||||
port: u16,
|
||||
coord: Arc<Coordinator>,
|
||||
webhook_secret: Option<String>,
|
||||
) -> Result<()> {
|
||||
pub async fn serve(port: u16, coord: Arc<Coordinator>) -> Result<()> {
|
||||
// API-only: the gateway static-serves the dashboard dist and proxies
|
||||
// non-static requests here (see `nix/host-modules/hive-gateway/vhosts.nix`).
|
||||
// Unmatched paths 404.
|
||||
|
|
@ -162,7 +151,6 @@ pub async fn serve(
|
|||
.routes(routes!(schedules::post_schedule_resume))
|
||||
.routes(routes!(schedules::post_schedule_fire_now))
|
||||
.routes(routes!(schedules::post_rebuild_queue_cancel))
|
||||
.routes(routes!(webhook::post_webhook_config_pr))
|
||||
.routes(routes!(approvals::post_approve))
|
||||
.routes(routes!(approvals::post_deny))
|
||||
.routes(routes!(lifecycle_ops::post_destroy))
|
||||
|
|
@ -191,10 +179,7 @@ pub async fn serve(
|
|||
"/api/openapi.json",
|
||||
get(move || async move { Json(api.clone()) }),
|
||||
)
|
||||
.with_state(AppState {
|
||||
coord,
|
||||
webhook_secret,
|
||||
});
|
||||
.with_state(AppState { coord });
|
||||
// Binds loopback-only; external access via gateway.
|
||||
// Rationale: docs/networking/gateway.md::Firewall posture.
|
||||
let addr = SocketAddr::from(([127, 0, 0, 1], port));
|
||||
|
|
@ -392,7 +377,6 @@ mod router_build_probe {
|
|||
.routes(routes!(schedules::post_schedule_resume))
|
||||
.routes(routes!(schedules::post_schedule_fire_now))
|
||||
.routes(routes!(schedules::post_rebuild_queue_cancel))
|
||||
.routes(routes!(webhook::post_webhook_config_pr))
|
||||
.routes(routes!(approvals::post_approve))
|
||||
.routes(routes!(approvals::post_deny))
|
||||
.routes(routes!(lifecycle_ops::post_destroy))
|
||||
|
|
|
|||
Loading…
Reference in a new issue