Repository navigation
#34 deploy.sh: gate a deploy on the commit's CI - #36
Merged
Merged
Conversation
The plan, and the red tests: status#11's gate cases ported, plus processor's own (an intermediate commit of an FF push, a pull_request twin run, a gated rollback, GitHub timing out). Co-Authored-By: Claude Opus 5.5 <[email protected]>
status#11's gate, ported between `build=` and the build, so a refusal builds nothing: the newest push run of ci.yml on main for exactly this SHA, its conclusion and every job's `success`, lint and test as the floor. A pending run is waited for (600 s); a commit behind the tip with no run is refused at once (an FF push runs CI on its tip only); cancelled says re-run it; GitHub refusing never passes. Rollbacks are gated too (option a); --skip-ci is the logged escape. No --dev target here, and the log tag is processor-deploy. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ci.yml's comment said runs on main are never cancelled Co-Authored-By: Claude Opus 5.5 <[email protected]>
…rvice exactly as they were Co-Authored-By: Claude Opus 5.5 <[email protected]>
…NDS tick cannot flake it Co-Authored-By: Claude Opus 5.5 <[email protected]>
…e jobs answer's does Co-Authored-By: Claude Opus 5.5 <[email protected]>
…pty jobs body passed the gate jq reads an empty body as no input: it prints nothing and exits 0, so no job looked failed and a run concluded success passed. github() now accepts a JSON object only. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
…is asked Co-Authored-By: Claude Opus 5.5 <[email protected]>
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #34.
scripts/deploy.shnow asks GitHub whether the commit's CI passed before it builds anything. This is Status's gate (status#11), ported. Plan: docs/plans/2026-10-06-34-deploy-ci-gate.md.What the gate checks
pushrun ofci.ymlonmainfor exactly this SHA. Apull_requesttwin, a dispatch, or a push elsewhere doesn't count.success, withCI_JOBS=(lint test)as a floor. A test holdsci.ymlto that floor.cancelledsays to re-run it, since a re-run counts. On Spec §6: the cross-repo notices never posted (replicator charter, archiver#179, cannobserv, observo token) #23's PR a run timed out unscheduled.--skip-cihint, and builds nothing. It never passes.--skip-ciskips the gate, and is logged before the build.logger -t processor-deploy, either "CI passed for : " or "CI not checked for (--skip-ci)".Rollbacks: option (a). The gate applies to every deploy, rollbacks included, and
--skip-ciis the logged escape. A kept release proves it was built, not that its CI passed. Option (b) would need a ledger of verified deploys, which the script doesn't keep. Every deploy so far was the tip of its push, so a normal rollback passes.test_a_rollback_is_gated_toopins this.Dropped from Status:
--dev, thelive/devbranching, and the "put it on dev" remedy.Docs: DEPLOYMENT has a new § The CI gate. It covers the intermediate-commit refusal, the rollback rule and the rate limit. The variables table, the prerequisites (
curl,api.github.com), § Rollback and the AGENTS command line are updated too.Tests: 37 new, against a stubbed
curland never the real API. They cover every case in the hand-off, plus:The full suite gives 411 passed and 4 skipped.
I checked the real API's answer by hand for
fe19a2b(run 37499560960): one push run on main, with jobslintandtest, about 2.5 min.After the FF merge:
git pull --ff-only, thenscripts/deploy.shwith the new script. Evidence to collect:3d04ee9.🤖 Generated with Claude Code