Auto-merge #1353
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Auto-merge — nobody is in the merge loop. | |
| # | |
| # Green, ready PRs merge themselves and deploy themselves. The policy lives in | |
| # ONE place for the whole fleet — bitbaum/dotfiles, | |
| # scripts/ci/auto-merge-sweep.sh — and this file only says "run it, with these | |
| # settings". | |
| # | |
| # It used to be a copy of that script. Twenty-two repos held such a copy and | |
| # they drifted into EIGHT versions: fixes written for real outages (a cancelled | |
| # CI run stranding the queue; a red base trapping the very PR that repairs it) | |
| # reached only the repo that wrote them, because nothing could carry them | |
| # across. That is what a copy costs. | |
| # | |
| # The triggers stay here on purpose — they are genuinely per-repo: workflow_run | |
| # must name the CI workflow exactly, and that name differs across the fleet. | |
| # | |
| # To stop all of this: delete this file, or add a `hold` label to a PR. | |
| name: Auto-merge | |
| on: | |
| workflow_run: | |
| workflows: ['CI'] | |
| types: [completed] | |
| schedule: | |
| - cron: '*/10 * * * *' | |
| workflow_dispatch: {} | |
| # Declared on the CALLER as well as inside the reusable workflow: a called | |
| # workflow's token is capped by what the caller grants, so relying on the | |
| # callee's block alone can hand it a read-only token — and the sweep would then | |
| # merge nothing while still exiting 0, which is indistinguishable from having | |
| # nothing to merge. | |
| permissions: | |
| contents: write # merge the PR | |
| pull-requests: write # read PR state, delete the branch | |
| actions: write # dispatch the re-arm workflows | |
| checks: read # statusCheckRollup — only load-bearing on private repos | |
| statuses: read | |
| jobs: | |
| sweep: | |
| uses: bitbaum/fleet/.github/workflows/auto-merge-sweep.yml@main | |
| with: | |
| base_branch: main | |
| ci_workflow: ci.yml | |
| # SPACE-separated: the sweep word-splits this. A comma would become one | |
| # bogus token, every dispatch would fail, and the only symptom would be | |
| # that nothing deploys — while the sweep still reported success. | |
| rearm_workflows: 'ci.yml deploy.yml' |