config PRs: remove the hive's config-PR webhook, poll and core merge
An operator's merge on the forge deploys a config PR through
swarm-controller's DeployRequest{rev}. The hive-side path that queued a
MergeConfigPr approval and merged the PR as `core` goes:
- the `/webhook/config-pr` receiver, its HMAC secret, the WebhookRegister
boot node and the org-hook registration; the hive vhost's `/webhook/`
location
- the 5-minute config-PR poll
- ApprovalKind::MergeConfigPr, its dashboard card, and the deploy DAG it
drove (DeployWindow, MergeVerify, DeployApply, FinalizeDeploy,
DeployTail), with verify_commit, the two-phase meta deploy, rollback
refs, the PR-failure comment and forge/pr_merge.rs
- `fetched_sha`, `sha_short`/`pr_number` on approval events, and
`sha`/`tag` on HelperEvent::ApprovalResolved: only the merge path set
them
`config_repo`, `merged_pr_for_commit` and `post_pr_comment` move to
forge/pr_comment.rs for the merged-rev deploy's refusal comment.
Approvals v5 drops stored `merge_config_pr` rows; a test reopens a v4
database holding them.
Closes #4850
This commit is contained in:
parent
a5ea015bc6
commit
efbfec6d01
39 changed files with 286 additions and 3199 deletions
|
|
@ -14,17 +14,10 @@ use serde::{Deserialize, Serialize};
|
|||
pub struct Approval {
|
||||
pub id: i64,
|
||||
pub agent: Ident,
|
||||
#[serde(default)]
|
||||
pub kind: ApprovalKind,
|
||||
/// Kind-specific payload (git sha / inputs array / schedule
|
||||
/// payload / empty). See the Approval struct doc.
|
||||
pub commit_ref: String,
|
||||
/// The canonical hive-c0re-vouched sha. For `MergeConfigPr`: the
|
||||
/// reviewed PR head pinned at submit; if the PR head drifts off it
|
||||
/// before merge, hive-c0re cancels the stale approval and re-queues a
|
||||
/// fresh one for re-review.
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
pub fetched_sha: Option<String>,
|
||||
pub requested_at: DateTime<Utc>,
|
||||
pub status: ApprovalStatus,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
|
|
@ -40,9 +33,7 @@ pub struct Approval {
|
|||
/// What action the approval, when granted, will trigger.
|
||||
/// Variant-specific payload encoding + flow lives in
|
||||
/// `docs/agent-lifecycle/approvals.md::Approval kinds (wire shapes)`.
|
||||
#[derive(
|
||||
Debug, Clone, Copy, Default, Serialize, Deserialize, PartialEq, Eq, strum::IntoStaticStr,
|
||||
)]
|
||||
#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq, strum::IntoStaticStr)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
#[strum(serialize_all = "snake_case")]
|
||||
pub enum ApprovalKind {
|
||||
|
|
@ -51,15 +42,6 @@ pub enum ApprovalKind {
|
|||
UpdateMetaInputs,
|
||||
/// Add a scheduled prompt to the broker queue.
|
||||
SchedulePrompt,
|
||||
/// Merge an operator-reviewed config PR: hive-c0re verifies the
|
||||
/// reviewed PR head, fast-forwards the forge config repo's `main`
|
||||
/// to it, marks the PR merged, then runs the deploy tail. This is the
|
||||
/// sole config-change flow — a manager opens a PR on its
|
||||
/// `agent-configs/<agent>` repo and the operator reviews + approves it.
|
||||
/// `commit_ref` = PR number; `fetched_sha` = the reviewed PR head
|
||||
/// pinned at submit. See `docs/agent-lifecycle/approvals.md`.
|
||||
#[default]
|
||||
MergeConfigPr,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
|
||||
|
|
|
|||
|
|
@ -55,10 +55,6 @@ pub enum HelperEvent {
|
|||
status: ApprovalStatus,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
note: Option<String>,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
sha: Option<String>,
|
||||
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||
tag: Option<String>,
|
||||
},
|
||||
/// A sub-agent's recorded flake rev is stale relative to hyperhive.
|
||||
NeedsUpdate { agent: String },
|
||||
|
|
|
|||
Loading…
Reference in a new issue