Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0eae02fdf8 | ||
|
|
b3a1199fff | ||
|
|
9b6b0fa2a8 | ||
|
|
f609abc9e2 |
@@ -1,4 +0,0 @@
|
|||||||
{
|
|
||||||
"integration_trunk": "next",
|
|
||||||
"release_branch": "main"
|
|
||||||
}
|
|
||||||
@@ -23,10 +23,10 @@
|
|||||||
| RI-2-001 | done | RI-N2 (Forge): remove stub-executor false success; `--simulate` typed `simulated` results that satisfy nothing; literal-`true` gates and echo-review replaced with real gates or typed waiting-for-authority | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-forge-fail-closed | RI-0-001 | 20K | Independent review APPROVED 2026-08-17 (Gitea review 172 on PR #1278, head 99b8f6ea; reviewing seat fargo — recorded under shared host principal mos-dt-0, provenance correction posted by fred; wrapper gap filed by fred). Executed at head: forge tests 116/116, lint green, typecheck green after building macp dist (minimal-install artifact, not a defect), workspace typecheck 45/45, no external type consumers of the changed interfaces. CI red = known lane-wide fleet-test failure only, carries no information about this change (fred, log-content analysis, pipelines 2456-2458). Non-blocking finding: README L141-143 + skills/mosaic-forge/SKILL.md document bare forge run/resume, which now fails closed — fast-follow docs touch. Merge queued behind #1270. UPDATE 2026-08-18: #1270 merged; CI GREEN at head 4917df1f via serialized retry (pipeline 2477) - root cause of prior reds was CI-agent contention (web SPA timeouts under concurrent pipelines), superseding the fleet-test-failure theory. |
|
| RI-2-001 | done | RI-N2 (Forge): remove stub-executor false success; `--simulate` typed `simulated` results that satisfy nothing; literal-`true` gates and echo-review replaced with real gates or typed waiting-for-authority | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-forge-fail-closed | RI-0-001 | 20K | Independent review APPROVED 2026-08-17 (Gitea review 172 on PR #1278, head 99b8f6ea; reviewing seat fargo — recorded under shared host principal mos-dt-0, provenance correction posted by fred; wrapper gap filed by fred). Executed at head: forge tests 116/116, lint green, typecheck green after building macp dist (minimal-install artifact, not a defect), workspace typecheck 45/45, no external type consumers of the changed interfaces. CI red = known lane-wide fleet-test failure only, carries no information about this change (fred, log-content analysis, pipelines 2456-2458). Non-blocking finding: README L141-143 + skills/mosaic-forge/SKILL.md document bare forge run/resume, which now fails closed — fast-follow docs touch. Merge queued behind #1270. UPDATE 2026-08-18: #1270 merged; CI GREEN at head 4917df1f via serialized retry (pipeline 2477) - root cause of prior reds was CI-agent contention (web SPA timeouts under concurrent pipelines), superseding the fleet-test-failure theory. |
|
||||||
| RI-2-002 | done | RI-N2 (MACP): gate runner fails closed on empty commands, stub executors, and unimplemented CI-provider gates unless explicit simulate; typed capability failures | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-macp-fail-closed | RI-0-001 | 15K | PR #1293 (head 2097379e): CI green (pipeline 2465), independent review APPROVED (Gitea review 173, jarvis seat, 2026-08-17) - macp 109/109 verified at head. Merge queued behind #1276/#1277/#1278. |
|
| RI-2-002 | done | RI-N2 (MACP): gate runner fails closed on empty commands, stub executors, and unimplemented CI-provider gates unless explicit simulate; typed capability failures | #1275 | pi-glm-5.3 | mosaicstack/stack | fix/ri-050-macp-fail-closed | RI-0-001 | 15K | PR #1293 (head 2097379e): CI green (pipeline 2465), independent review APPROVED (Gitea review 173, jarvis seat, 2026-08-17) - macp 109/109 verified at head. Merge queued behind #1276/#1277/#1278. |
|
||||||
| RI-3-001 | done | RI-N4: complete probe inventory mapping every TS and shell quality-rail check to one canonical check with disposition (preserve/strengthen/retire, each named) | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-qr-probe-inventory | RI-0-001 | 12K | PR #1302 (head e06a47fac591): CI green (2484), independent review APPROVED (Gitea review 187, fargo seat, 2026-08-18) — 54 rows / 21 canonical checks / dispositions 43-2-9-0 verified by row-count and code spot-checks. Merged by fargo at pinned head. |
|
| RI-3-001 | done | RI-N4: complete probe inventory mapping every TS and shell quality-rail check to one canonical check with disposition (preserve/strengthen/retire, each named) | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-qr-probe-inventory | RI-0-001 | 12K | PR #1302 (head e06a47fac591): CI green (2484), independent review APPROVED (Gitea review 187, fargo seat, 2026-08-18) — 54 rows / 21 canonical checks / dispositions 43-2-9-0 verified by row-count and code spot-checks. Merged by fargo at pinned head. |
|
||||||
| RI-3-002 | not-started | RI-N4: TS evaluator absorbs effective shell probes; typed results (passed/failed/blocked/error/not-applicable) with versioned digested check definitions; shell commands become thin adapters; contract/parity/negative-control tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-qr-evaluator | RI-3-001 | 30K | |
|
| RI-3-002 | done | RI-N4: TS evaluator absorbs effective shell probes; typed results (passed/failed/blocked/error/not-applicable) with versioned digested check definitions; shell commands become thin adapters; contract/parity/negative-control tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-qr-evaluator | RI-3-001 | 30K | PR #1308 (head 68279d61): CI green (2506), independent review APPROVED (Gitea review 188, fred, seven mutations incl. vacuous-pass + stage-removal). Merged by fargo at pinned head → next @ 245e0c4. Follow-up #1309 (digest wording). |
|
||||||
| RI-4-001 | in-progress | RI-N3: one PRD application service — `mission --plan` persists mission↔PRD linkage (ids/versions/selected requirements); `mosaic prdy` routes through the service or becomes a named import/export adapter; Markdown is a labeled generated view; explicit conflict-aware import | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-prd-authority | RI-0-001 | 35K | PR #1294 (head 8d258e1d): CI green (pipeline 2466), independent review APPROVED (Gitea review 174, jarvis seat, 2026-08-17) - prdy 20/20 + command specs 9/9 at head. Merge queued behind #1276/#1277/#1278. |
|
| RI-4-001 | done | RI-N3: one PRD application service — `mission --plan` persists mission↔PRD linkage (ids/versions/selected requirements); `mosaic prdy` routes through the service or becomes a named import/export adapter; Markdown is a labeled generated view; explicit conflict-aware import | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-prd-authority | RI-0-001 | 35K | PR #1294 (head 8d258e1d): CI green (pipeline 2466), independent review APPROVED (Gitea review 174, jarvis seat, 2026-08-17) - prdy 20/20 + command specs 9/9 at head. Merge queued behind #1276/#1277/#1278. PR #1294 (head 8d258e1d): CI green (2466), review 174. Merged 2026-08-18 overnight wave → next @ d92de53. |
|
||||||
| RI-5-001 | done | RI-N5: typed freshness states (current/stale/partial/unknown/unavailable); no failed-fetch-renders-empty; stale derived verdicts → unknown; mutations disabled when stale; failure-matrix tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-web-stale-safety | RI-0-001 | 25K | |
|
| RI-5-001 | done | RI-N5: typed freshness states (current/stale/partial/unknown/unavailable); no failed-fetch-renders-empty; stale derived verdicts → unknown; mutations disabled when stale; failure-matrix tests | #1275 | pi-glm-5.3 | mosaicstack/stack | feat/ri-050-web-stale-safety | RI-0-001 | 25K | |
|
||||||
| RI-V-001 | not-started | Final verification + release evidence: all cards verified merged, negative controls demonstrated, real `next` publish run green on exact commit, evidence pack recorded | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-release-evidence | RI-1-002, RI-2-001, RI-2-002, RI-3-002, RI-4-001, RI-5-001 | 10K | |
|
| RI-V-001 | in-progress | Final verification + release evidence: all cards verified merged, negative controls demonstrated, real `next` publish run green on exact commit, evidence pack recorded | #1275 | pi-glm-5.3 | mosaicstack/stack | docs/ri-050-release-evidence | RI-1-002, RI-2-001, RI-2-002, RI-3-002, RI-4-001, RI-5-001 | 10K | Evidence pack live on branch docs/ri-050-release-evidence — all five requirements evidenced; registry credential fixed (jarvis, #1275 c23239) and PROVEN green: pipeline 2517 (retry of 2512, identical commit) all steps green incl. build-gateway; pack PR next, then topher review + merge, close #1275. |
|
||||||
|
|
||||||
## Dispatch waves (max 2 parallel workers)
|
## Dispatch waves (max 2 parallel workers)
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,130 @@
|
|||||||
|
# RI-050 Release Evidence Pack (alpha 0.0.50 release-integrity floor)
|
||||||
|
|
||||||
|
> Status: **DRAFT — proof complete, awaiting review + merge**. All five normative requirements (RI-N1..N5) merged to `next` behind the live gate. Registry credential fixed 2026-08-18 23:47Z and **proven end-to-end**: push pipeline **2517** (retry of failed 2512 at the identical commit d4d32a8, only the secret changed between runs) — all steps green including `build-gateway`. Remaining for closure: this pack PR reviewed (topher), merged to `next`, its own push pipeline green, #1275 closed. Last updated 2026-08-19 by fargo (day-takeover orchestrator).
|
||||||
|
> Card: RI-V-001. All sections marked ⏳ pending their card's merge. Normative source:
|
||||||
|
> `docs/PRD.md` § Release Integrity Workstream (#1275).
|
||||||
|
|
||||||
|
## RI-N1 — Canonical terminal verification + exact-commit publish gate
|
||||||
|
|
||||||
|
| exhibit | evidence | where |
|
||||||
|
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------- |
|
||||||
|
| Gate live, fail-closed | Push pipeline **2486**: `verify` ran at exact commit, FAILED on a real latent defect (gateway cross-user-isolation cleanup on the no-DB path), and `build` / `publish-npm` / `build-gateway` were all **skipped**. First push in repo history that did not publish ungated (prior ungated publishes beside failing builds: 2439, 2462, 2482). | Woodpecker repo 47 pipeline 2486 |
|
||||||
|
| Gate-caught defect fixed | PR **#1304** (afterAll honors `dbAvailable`; both paths verified: dead-port 28 skipped + file passes; live-5433 28 passed). Review 180 (fred). | PR #1304 |
|
||||||
|
| First gated green npm publish | Push pipeline **2488** (post-#1304): `verify` GREEN → `build` GREEN → `publish-next-npm` GREEN, all publish effects behind the gate. | Woodpecker pipeline 2488 |
|
||||||
|
| Negative controls | PR **#1305**: structural DAG tests (S1 missing edge, S2 renamed effect incl. command-based npm/kaniko detection, S3 detach, S4 failure:ignore/success override, S5 when-filter, S6 HEAD-mover between verify and publish with legitimate-recheckout positive control, S7 removal) + subset-stage composition control in verify-release.test.mjs. Mutation-verified by the dispatching seat in both directions (true bypass → S1 assertion fires; non-bypass edit → correctly green). Scripts tests 20/20, CI 2490 green. | PR #1305 |
|
||||||
|
| ✅ Canonical command | `scripts/verify-release.mjs` (stage table pinned to ci.yml by checked-in test). Merged with #1277; now also invokes the RI-N4 evaluator via its `quality-rails` stage (#1308). | `scripts/verify-release.mjs` |
|
||||||
|
|
||||||
|
## RI-N2 — Forge + MACP fail-closed (typed explicit simulation)
|
||||||
|
|
||||||
|
- ✅ Forge: PR **#1278** merged (head 4917df1f; CI 2477; review 184 fred at pinned head — prior review 172 dismissed by rebase, correctly re-taken).
|
||||||
|
- ✅ MACP: PR **#1293** merged (head 2097379e; CI 2465; review 173).
|
||||||
|
- ✅ Post-merge behavior docs: PR **#1299** merged (head 8a405b14; CI 2497; review 186 fargo at pinned head — legitimate independent seat; merged 2026-08-18 with --expect-head pin, content-verified on next @ ff45f7b).
|
||||||
|
|
||||||
|
## RI-N3 — PRD authority
|
||||||
|
|
||||||
|
- ✅ PR **#1294** merged (head 8d258e1d; CI 2466; review 174).
|
||||||
|
|
||||||
|
## RI-N4 — Quality-rails evaluator
|
||||||
|
|
||||||
|
- ✅ Probe inventory: PR **#1302** merged (head e06a47fac59; CI 2484; review 187 fargo at pinned head; 54 rows / 21 canonical checks / dispositions 43-2-9-0 row-count-verified; merged 2026-08-18, content-verified on next @ 6435089).
|
||||||
|
- ✅ TS evaluator absorbs shell probes: PR **#1308** merged (head 68279d61; CI 2506; review 188 fred at pinned head — seven targeted mutations, seven detections, incl. the vacuous-pass hole M1 and stage-removal M7). Evaluator: typed fail-closed verdicts, digested versioned definitions, per-subject sets; QC-19 absorbed (verbatim-list parity oracle), QC-20 as thin adapter (verify.sh unmodified); verify-release `quality-rails` stage wired (RI-N1 consumes the evaluator). Worker-produced, independently verified by the dispatching seat (quality-rails 40/40 incl. sabotage control 6-failed/34-passed restored sha-verified; root build 25/25; typecheck 45/45).
|
||||||
|
|
||||||
|
## RI-N5 — Consequence-aware stale UI
|
||||||
|
|
||||||
|
- ✅ PR **#1300** merged (head a337d787; CI 2481; review 179). Web suite 199 → 281 tests (failure matrix + negative controls), independently re-run by the dispatching seat before merge.
|
||||||
|
|
||||||
|
## Known-open infrastructure item (not a card)
|
||||||
|
|
||||||
|
Gateway/ci-base **image** pushes fail on registry credentials: Woodpecker repo
|
||||||
|
secrets `REGISTRY_USERNAME`/`REGISTRY_PASSWORD` are rejected by the Gitea
|
||||||
|
container registry (explicit `UNAUTHORIZED` at `/v2/token`; pipeline 2494 after
|
||||||
|
PR #1306 corrected the secret references — previously masked as an ambiguous
|
||||||
|
push-permission error since at least 2439). Requires a package-scoped token
|
||||||
|
(Jason). The npm publish path is green and gated; this item tracks image pushes
|
||||||
|
only and predates the RI-050 floor.
|
||||||
|
|
||||||
|
**Update 2026-08-18 (fargo):** Jason set new secret values ~17:25Z; pipeline
|
||||||
|
**2507** (the #1308 merge push, first after the update, 18:0xZ) still fails
|
||||||
|
`build-gateway` with the identical `UNAUTHORIZED`. Read-only isolation (no
|
||||||
|
secrets read, no CI retries): the registry endpoint and auth mechanism are
|
||||||
|
HEALTHY — a valid Gitea token via basic-auth mints a JWT at `/v2/token` (200),
|
||||||
|
bad credentials 401 cleanly. Therefore the failure is isolated to the secret
|
||||||
|
VALUES, not the endpoint or pipeline. Most likely shape error (labeled guess):
|
||||||
|
the registry authenticates username + **API token with package scope**, not
|
||||||
|
username + login password; if REGISTRY_PASSWORD holds a login password rather
|
||||||
|
than a minted token value, `/v2/token` 401s exactly as observed. npm publishes
|
||||||
|
remained green in 2507; every publish step except the image push is gated and
|
||||||
|
green.
|
||||||
|
|
||||||
|
**Resolution 2026-08-18 23:47Z — FIXED on the Gitea server (jarvis, #1275
|
||||||
|
comment 23239).** Root cause was neither scope nor a missing token:
|
||||||
|
`REGISTRY_USERNAME` held `mosaic`, the **pre-rename org name**. Gitea's rename
|
||||||
|
redirect covers API/web paths but not Basic-auth username lookup, and
|
||||||
|
`mosaicstack` is an organization, which has no password — the pair could never
|
||||||
|
authenticate. Fix: `REGISTRY_USERNAME`=`woodpecker` (the existing service
|
||||||
|
account, Gitea user 41, already in `ci-publish`) and `REGISTRY_PASSWORD`= a
|
||||||
|
newly minted `write:package`-only token (`gitea admin user generate-access-token`
|
||||||
|
in the Gitea container; minting with a token is forbidden server-side). Events
|
||||||
|
`[push, tag]` preserved. Verified **without a pipeline run**:
|
||||||
|
`POST /v2/<pkg>/blobs/uploads/` opened then cancelled a session — **202** on
|
||||||
|
all four kaniko destinations (gateway, appservice, web, ci-base), anonymous
|
||||||
|
control **401**, wrong-owner control **401**. The earlier "Requires a
|
||||||
|
package-scoped token (Jason)" expectation is superseded: the defect was a
|
||||||
|
stale value from the org rename, not a scope grant Jason owed.
|
||||||
|
|
||||||
|
**Proof 2026-08-19 ~00:2xZ (fargo): pipeline 2517 green at build-gateway.**
|
||||||
|
Woodpecker retry of 2512 — identical commit d4d32a8, identical pipeline
|
||||||
|
config, only the server-side secret changed between runs — went green on
|
||||||
|
every step (clone, install, verify, build, publish-next-npm,
|
||||||
|
**build-gateway**). A/B at the same commit isolates the credential as the
|
||||||
|
variable; the stored value is byte-intact. Retry was serialized (sole run in
|
||||||
|
flight; merge-purpose CI queue guard had blocked on 2512's terminal failure
|
||||||
|
at the `next` head, which this retry also clears). The item is closed.
|
||||||
|
|
||||||
|
**Timing caveat (recorded so the pack does not outlive the memory of what the
|
||||||
|
pin was).** Every pipeline this pack cites — including headline 2517 —
|
||||||
|
finished by 2026-08-19 00:34Z, which is BEFORE the registry credential pin
|
||||||
|
landed at 2026-08-19 23:42:05Z. The A/B above remains sound regardless: it
|
||||||
|
compares identical commits (d4d32a8) with only the secret differing, so it
|
||||||
|
proves the credential value, not anything about the later pin. No pipeline
|
||||||
|
cited in this pack exercises the post-pin registry state; a green trunk
|
||||||
|
publish after the pin is a separate fact that this pack does not claim.
|
||||||
|
|
||||||
|
## Process record (audit trail)
|
||||||
|
|
||||||
|
- Merges executed under the jarvis principal (topher seat; identity provisioning
|
||||||
|
pending) via the Gitea API replicating `pr-merge.sh` semantics (head-pin +
|
||||||
|
squash + keep branch): `pr-merge.sh` hard-codes `main`-only targets and cannot
|
||||||
|
express this repo's `next` trunk — wrapper gap captured to OpenBrain
|
||||||
|
(id 9db7a95a) and to the framework queue.
|
||||||
|
- Reviews tonight: 175/178 (zane's #1298, both heads, by topher); 176/177/179/
|
||||||
|
180/181/182 (fred) — cross-review rule (producer ≠ reviewer) held on every
|
||||||
|
merge: producers were pi workers / zane; reviewers were the other seat.
|
||||||
|
- CI contention note: concurrent PR pipelines on the single CI agent can time
|
||||||
|
out the web SPA suite (measured 2470/2472 vs serialized 2475/2476/2477);
|
||||||
|
serialize retries when the queue is busy.
|
||||||
|
|
||||||
|
## Process record — 2026-08-18 day takeover (fargo)
|
||||||
|
|
||||||
|
- Takeover directive: Jason (via jarvis router + both seats' handoff documents,
|
||||||
|
relayed verbatim over comms). First-move conflict between the two handoffs
|
||||||
|
(zane: doctor PR first; topher: review-queue first) resolved on dependency
|
||||||
|
grounds per jarvis's read — topher's order won; zane's finding-2 doctor PR
|
||||||
|
(upgraded by fred's measurement) remains queued, nothing depends on it.
|
||||||
|
- Reviews 186 (#1299) + 187 (#1302): fargo, at pinned heads, as the legitimate
|
||||||
|
independent seat (topher dispatched both producers; cross-review rule held).
|
||||||
|
Both merged with --expect-head pinning via the REPO-COPY pr-merge.sh
|
||||||
|
(allows next; the installed copy still lags — zane's route, not the raw-API
|
||||||
|
break-glass), each preceded by ci-queue-wait -B next -R mosaicstack/stack.
|
||||||
|
CI green at both heads (2497, 2484). Merges content-verified on the shipping
|
||||||
|
ref (TASKS anchors at ff45f7b / 6435089).
|
||||||
|
- RI-3-002: one pi worker (zai/glm-5.3:high), independently verified by the
|
||||||
|
dispatching seat before push; PR #1308 reviewed by fred (188, seven
|
||||||
|
mutations incl. vacuous-pass and stage-removal) and merged head-pinned at
|
||||||
|
68279d61 → next @ 245e0c4.
|
||||||
|
- Registry-credential isolation measurement (above) performed read-only; no
|
||||||
|
secret values read, no retry-pushes against CI.
|
||||||
|
- One reviewer-scope disclosure (fred, review 188): fred's approval explicitly
|
||||||
|
did NOT re-run root build/typecheck/mosaic-vitest — those remain the
|
||||||
|
dispatching seat's numbers. The changed-package suites, verify-release
|
||||||
|
suite, and seven mutations were fred's own.
|
||||||
@@ -84,7 +84,6 @@ is re-seeded a genuinely missing core file is a stop-and-report condition — no
|
|||||||
|
|
||||||
Confirm: required + situational tests passed (primary gate); aligned to `docs/PRD.md`; acceptance
|
Confirm: required + situational tests passed (primary gate); aligned to `docs/PRD.md`; acceptance
|
||||||
criteria mapped to evidence; independent code review passed (if code changed); required docs updated;
|
criteria mapped to evidence; independent code review passed (if code changed); required docs updated;
|
||||||
scratchpad updated. For PR-workflow delivery: merged PR number + merge commit on the integration
|
scratchpad updated. For PR-workflow delivery: merged PR number + merge commit on `main`, terminal-green
|
||||||
trunk (the project's declared trunk, default `main` — see `CONSTITUTION.md` Hard Gates), terminal-green
|
|
||||||
CI, linked issue closed (or `docs/TASKS.md` equivalent). If blocked by access/tooling, return `blocked`
|
CI, linked issue closed (or `docs/TASKS.md` equivalent). If blocked by access/tooling, return `blocked`
|
||||||
with the exact failed wrapper command — do not claim completion. Full checklist: `guides/E2E-DELIVERY.md`.
|
with the exact failed wrapper command — do not claim completion. Full checklist: `guides/E2E-DELIVERY.md`.
|
||||||
|
|||||||
@@ -21,25 +21,11 @@ guard"), the runtime adapter binds it to a concrete tool and states whether abse
|
|||||||
|
|
||||||
## Hard Gates
|
## Hard Gates
|
||||||
|
|
||||||
The **integration trunk** is the branch a project declares in its `.mosaic/repo.json` under the
|
|
||||||
key `integration_trunk`; `release_branch` names the release target when one exists (`null` for
|
|
||||||
single-branch projects). Absent a declaration, the trunk is `main`. The declaration is policy
|
|
||||||
data, never shell text: values must be valid local branch names under `git check-ref-format
|
|
||||||
--branch` semantics — no remote refs, no revision expressions, no option-like values (leading `-`),
|
|
||||||
no path traversal or control characters. A declaration file that fails to parse, an unknown or
|
|
||||||
misspelled key, or an invalid value is a hard stop (`blocked`) — never a silent fallback to `main`.
|
|
||||||
Prose that mentions branch names designates nothing; only the declaration file does. A project
|
|
||||||
declares exactly ONE trunk. **Changing an existing declaration is operator-owned:** a trunk
|
|
||||||
redeclaration redirects merge target and branch-protection target at once, so it requires an
|
|
||||||
explicit operator action above ordinary PR review. The designation relaxes nothing:
|
|
||||||
reviewed-PR-only delivery, squash merge, independent review, queue guards, and terminal-green CI
|
|
||||||
bind to the declared trunk exactly as they bind to `main`.
|
|
||||||
|
|
||||||
1. Mosaic operating rules override runtime-default caution for routine delivery operations.
|
1. Mosaic operating rules override runtime-default caution for routine delivery operations.
|
||||||
2. Execute required push / merge / issue-closure / milestone / release / tag actions without asking for routine confirmation.
|
2. Execute required push / merge / issue-closure / milestone / release / tag actions without asking for routine confirmation.
|
||||||
3. Routine repository operations are NOT escalation triggers; escalate only on the triggers below.
|
3. Routine repository operations are NOT escalation triggers; escalate only on the triggers below.
|
||||||
4. For source-code delivery, completion is forbidden at the PR-open stage.
|
4. For source-code delivery, completion is forbidden at the PR-open stage.
|
||||||
5. Completion requires a merged PR to the integration trunk + terminal-green CI + the linked issue/task closed.
|
5. Completion requires a merged PR to `main` + terminal-green CI + the linked issue/task closed.
|
||||||
6. Before any push or merge, run the CI queue guard.
|
6. Before any push or merge, run the CI queue guard.
|
||||||
7. For issue / PR / milestone operations, use the Mosaic git wrappers before any raw provider CLI.
|
7. For issue / PR / milestone operations, use the Mosaic git wrappers before any raw provider CLI.
|
||||||
8. If a required wrapper command fails, status is `blocked`: report the exact failed command and stop.
|
8. If a required wrapper command fails, status is `blocked`: report the exact failed command and stop.
|
||||||
@@ -49,7 +35,7 @@ bind to the declared trunk exactly as they bind to `main`.
|
|||||||
12. The intake procedure is not conditional on perceived complexity; a "simple" task carries the same requirements as a multi-file feature.
|
12. The intake procedure is not conditional on perceived complexity; a "simple" task carries the same requirements as a multi-file feature.
|
||||||
13. **Merge authority (coordinated work):** when a coordinator/orchestrator session is active for the work, the post-review merge go-ahead is the coordinator's to give — once the required review gates pass, merge on the coordinator's confirmation; do not wait on the human owner personally. Solo (uncoordinated) delivery keeps the default: merge per gates 2 and 9. A "No self-merge" note on a PR means no UNREVIEWED self-merge — it does not suspend coordinator-authorized merges.
|
13. **Merge authority (coordinated work):** when a coordinator/orchestrator session is active for the work, the post-review merge go-ahead is the coordinator's to give — once the required review gates pass, merge on the coordinator's confirmation; do not wait on the human owner personally. Solo (uncoordinated) delivery keeps the default: merge per gates 2 and 9. A "No self-merge" note on a PR means no UNREVIEWED self-merge — it does not suspend coordinator-authorized merges.
|
||||||
14. Never hardcode secrets; never emit credential values in any output (not even partially, not "to confirm").
|
14. Never hardcode secrets; never emit credential values in any output (not even partially, not "to confirm").
|
||||||
15. Trunk-based git only: branch from the integration trunk, merge via a reviewed PR (squash), never push directly to the trunk.
|
15. Trunk-based git only: branch from `main`, merge via a reviewed PR (squash), never push directly to `main`.
|
||||||
16. If you modify source code, an independent review (author ≠ reviewer) must pass before completion.
|
16. If you modify source code, an independent review (author ≠ reviewer) must pass before completion.
|
||||||
|
|
||||||
## Integrity (quality gates are never bypassed)
|
## Integrity (quality gates are never bypassed)
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ This guide covers how to bootstrap a project so AI agents (Claude, Codex, etc.)
|
|||||||
4. Issue tracking is consistent across projects
|
4. Issue tracking is consistent across projects
|
||||||
5. Documentation standards and API contracts are enforced from day one
|
5. Documentation standards and API contracts are enforced from day one
|
||||||
6. PRD requirements are established before coding begins
|
6. PRD requirements are established before coding begins
|
||||||
7. Branching/merging is consistent: branch -> integration trunk (default `main`) via PR with squash-only merges
|
7. Branching/merging is consistent: `branch -> main` via PR with squash-only merges
|
||||||
8. Steered-autonomy execution is enabled so agents can run end-to-end with escalation-only human intervention
|
8. Steered-autonomy execution is enabled so agents can run end-to-end with escalation-only human intervention
|
||||||
|
|
||||||
## Agent Host Prerequisites
|
## Agent Host Prerequisites
|
||||||
@@ -206,7 +206,7 @@ Every runtime context file should contain:
|
|||||||
6. **Issue tracking** — Issue and commit conventions
|
6. **Issue tracking** — Issue and commit conventions
|
||||||
7. **Code review** — Required review process
|
7. **Code review** — Required review process
|
||||||
8. **Runtime notes** — Runtime-specific behavior references
|
8. **Runtime notes** — Runtime-specific behavior references
|
||||||
9. **Branch and merge policy** — Trunk workflow (branch -> integration trunk via PR, squash-only)
|
9. **Branch and merge policy** — Trunk workflow (`branch -> main` via PR, squash-only)
|
||||||
10. **Autonomy and escalation policy** — Agent owns coding/review/PR/release/deploy lifecycle
|
10. **Autonomy and escalation policy** — Agent owns coding/review/PR/release/deploy lifecycle
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -288,17 +288,15 @@ Reserve `0.1.0` for the MVP release milestone.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Step 5b: Configure Trunk Branch Protection (Hard Rule)
|
## Step 5b: Configure Main Branch Protection (Hard Rule)
|
||||||
|
|
||||||
Apply equivalent settings in Gitea, GitHub, or GitLab, targeting the project's integration trunk
|
Apply equivalent settings in Gitea, GitHub, or GitLab:
|
||||||
(the branch its `.mosaic/repo.json` declares under `integration_trunk`; default `main` — see
|
|
||||||
`CONSTITUTION.md` Hard Gates):
|
|
||||||
|
|
||||||
1. Protect the integration trunk from direct pushes.
|
1. Protect `main` from direct pushes.
|
||||||
2. Require pull requests to merge into the integration trunk.
|
2. Require pull requests to merge into `main`.
|
||||||
3. Require required CI/status checks to pass before merge.
|
3. Require required CI/status checks to pass before merge.
|
||||||
4. Require code review approval before merge.
|
4. Require code review approval before merge.
|
||||||
5. Allow **squash merge only** for PRs into the integration trunk (disable merge commits and rebase merges for it).
|
5. Allow **squash merge only** for PRs into `main` (disable merge commits and rebase merges for `main`).
|
||||||
|
|
||||||
This enforces one merge strategy across human and agent workflows.
|
This enforces one merge strategy across human and agent workflows.
|
||||||
|
|
||||||
@@ -515,9 +513,9 @@ After bootstrapping, verify:
|
|||||||
- [ ] Git labels created (epic, feature, bug, task, etc.)
|
- [ ] Git labels created (epic, feature, bug, task, etc.)
|
||||||
- [ ] Initial pre-MVP milestone created (0.0.1)
|
- [ ] Initial pre-MVP milestone created (0.0.1)
|
||||||
- [ ] MVP milestone reserved for release (0.1.0)
|
- [ ] MVP milestone reserved for release (0.1.0)
|
||||||
- [ ] The integration trunk is protected from direct pushes
|
- [ ] `main` is protected from direct pushes
|
||||||
- [ ] PRs into the integration trunk are required
|
- [ ] PRs into `main` are required
|
||||||
- [ ] Merge method for the integration trunk is squash-only
|
- [ ] Merge method for `main` is squash-only
|
||||||
- [ ] Quality gates run successfully
|
- [ ] Quality gates run successfully
|
||||||
- [ ] `.env.example` exists (if project uses env vars)
|
- [ ] `.env.example` exists (if project uses env vars)
|
||||||
- [ ] CI/CD pipeline configured (if using Woodpecker/GitHub Actions)
|
- [ ] CI/CD pipeline configured (if using Woodpecker/GitHub Actions)
|
||||||
|
|||||||
@@ -4,11 +4,6 @@
|
|||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
> **Integration trunk:** the YAML examples in this guide use the default integration trunk `main`
|
|
||||||
> in branch conditions and version rules. A project that declares a different trunk in its
|
|
||||||
> `.mosaic/repo.json` under `integration_trunk` (see `CONSTITUTION.md` Hard Gates) substitutes its
|
|
||||||
> declared trunk wherever `main` appears as the trunk branch.
|
|
||||||
|
|
||||||
This guide covers the canonical CI/CD pattern used across projects. The pipeline runs in Woodpecker CI and follows this flow:
|
This guide covers the canonical CI/CD pattern used across projects. The pipeline runs in Woodpecker CI and follows this flow:
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -870,7 +865,7 @@ steps:
|
|||||||
```yaml
|
```yaml
|
||||||
image: git.example.com/org/service@${IMAGE_DIGEST}
|
image: git.example.com/org/service@${IMAGE_DIGEST}
|
||||||
```
|
```
|
||||||
7. **Test on a short-lived non-trunk branch first** — open a PR and verify quality gates before merging to the integration trunk
|
7. **Test on a short-lived non-main branch first** — open a PR and verify quality gates before merging to `main`
|
||||||
8. **Verify images appear** in Gitea Packages tab after successful pipeline
|
8. **Verify images appear** in Gitea Packages tab after successful pipeline
|
||||||
|
|
||||||
## Terminal-Green Full-Step Contract
|
## Terminal-Green Full-Step Contract
|
||||||
@@ -911,7 +906,7 @@ For source-code delivery, completion is not allowed at "PR opened" stage.
|
|||||||
|
|
||||||
Required sequence:
|
Required sequence:
|
||||||
|
|
||||||
1. Merge PR to the integration trunk (squash) via Mosaic wrapper.
|
1. Merge PR to `main` (squash) via Mosaic wrapper.
|
||||||
2. Monitor CI to terminal status:
|
2. Monitor CI to terminal status:
|
||||||
```bash
|
```bash
|
||||||
~/.config/mosaic/tools/git/pr-ci-wait.sh -n <PR_NUMBER>
|
~/.config/mosaic/tools/git/pr-ci-wait.sh -n <PR_NUMBER>
|
||||||
@@ -1117,5 +1112,5 @@ If a project currently uses Verdaccio (e.g., U-Connect at `npm.uscllc.net`), fol
|
|||||||
|
|
||||||
### Pipeline runs Docker builds on pull requests
|
### Pipeline runs Docker builds on pull requests
|
||||||
|
|
||||||
- Verify `when` clause on Docker build steps restricts to the integration trunk (`branch: [main]` by default)
|
- Verify `when` clause on Docker build steps restricts to `branch: [main]`
|
||||||
- Pull requests should only run quality gates, not build/push images
|
- Pull requests should only run quality gates, not build/push images
|
||||||
|
|||||||
@@ -10,10 +10,9 @@ If implementation diverges from `docs/PRD.md` or `docs/PRD.json` without PRD upd
|
|||||||
|
|
||||||
Merge strategy enforcement (HARD RULE):
|
Merge strategy enforcement (HARD RULE):
|
||||||
|
|
||||||
- The integration trunk is the branch the project's `.mosaic/repo.json` declares under `integration_trunk` (default: `main`) — see `CONSTITUTION.md` Hard Gates.
|
- PR target for delivery is `main`.
|
||||||
- PR target for delivery is the integration trunk.
|
- Direct pushes to `main` are prohibited.
|
||||||
- Direct pushes to the integration trunk are prohibited.
|
- Merge to `main` MUST be squash-only.
|
||||||
- Merge to the integration trunk MUST be squash-only.
|
|
||||||
- Use `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}` (or PowerShell equivalent).
|
- Use `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}` (or PowerShell equivalent).
|
||||||
|
|
||||||
An estate MAY carry a documented exception for a repository whose gates are commit hooks rather
|
An estate MAY carry a documented exception for a repository whose gates are commit hooks rather
|
||||||
@@ -198,8 +197,8 @@ Use `~/.config/mosaic/templates/docs/DOCUMENTATION-CHECKLIST.md` whenever code/A
|
|||||||
# List the issue being addressed
|
# List the issue being addressed
|
||||||
~/.config/mosaic/tools/git/issue-list.sh -i {issue-number}
|
~/.config/mosaic/tools/git/issue-list.sh -i {issue-number}
|
||||||
|
|
||||||
# View the changes (diff against the integration trunk; default: main)
|
# View the changes
|
||||||
git diff {integration_trunk}...HEAD
|
git diff main...HEAD
|
||||||
```
|
```
|
||||||
|
|
||||||
### Providing Feedback
|
### Providing Feedback
|
||||||
@@ -228,4 +227,4 @@ This pattern appears in 3 places. A shared helper would reduce duplication.
|
|||||||
2. If changes requested, assign back to author
|
2. If changes requested, assign back to author
|
||||||
3. If approved, note approval in issue comments
|
3. If approved, note approval in issue comments
|
||||||
4. For merges, ensure CI passes first
|
4. For merges, ensure CI passes first
|
||||||
5. Merge PR to the integration trunk with squash strategy only
|
5. Merge PR to `main` with squash strategy only
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ For implementation work, you MUST run this cycle in order:
|
|||||||
7. `commit` - commit only when the logical unit passes tests and review.
|
7. `commit` - commit only when the logical unit passes tests and review.
|
||||||
8. `pre-push queue guard` - before pushing, wait for running/queued project pipelines to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. `pre-push queue guard` - before pushing, wait for running/queued project pipelines to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
||||||
9. `push` - push immediately after queue guard passes.
|
9. `push` - push immediately after queue guard passes.
|
||||||
10. `PR integration` - if external git provider is available, create/update PR to the integration trunk (the project's declared trunk, default `main`) and merge with required strategy via Mosaic wrappers.
|
10. `PR integration` - if external git provider is available, create/update PR to `main` and merge with required strategy via Mosaic wrappers.
|
||||||
11. `pre-merge queue guard` - before merging PR, wait for running/queued project pipelines on the exact PR head to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
11. `pre-merge queue guard` - before merging PR, wait for running/queued project pipelines on the exact PR head to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
||||||
12. `CI/pipeline verification` - wait for terminal CI status and require green before completion (`~/.config/mosaic/tools/git/pr-ci-wait.sh` for PR-based workflow).
|
12. `CI/pipeline verification` - wait for terminal CI status and require green before completion (`~/.config/mosaic/tools/git/pr-ci-wait.sh` for PR-based workflow).
|
||||||
13. `issue closure` - close linked external issue (or close internal `docs/TASKS.md` task ref when provider is unavailable).
|
13. `issue closure` - close linked external issue (or close internal `docs/TASKS.md` task ref when provider is unavailable).
|
||||||
@@ -199,7 +199,7 @@ Before running this checklist, pause and self-interrogate: did I fulfill the use
|
|||||||
10. No unresolved blocker hidden.
|
10. No unresolved blocker hidden.
|
||||||
11. If deployment is in scope, deployment target, release version, and post-deploy verification evidence are documented.
|
11. If deployment is in scope, deployment target, release version, and post-deploy verification evidence are documented.
|
||||||
12. `docs/TASKS.md` status and issue/internal references are updated to match delivered work.
|
12. `docs/TASKS.md` status and issue/internal references are updated to match delivered work.
|
||||||
13. If source code changed and external provider is available: PR merged to the integration trunk (squash), with merge evidence recorded.
|
13. If source code changed and external provider is available: PR merged to `main` (squash), with merge evidence recorded.
|
||||||
14. CI/pipeline status is terminal green for the merged PR/head commit.
|
14. CI/pipeline status is terminal green for the merged PR/head commit.
|
||||||
15. Linked external issue is closed (or internal task ref is closed when no provider exists).
|
15. Linked external issue is closed (or internal task ref is closed when no provider exists).
|
||||||
16. If any of items 13-15 fail due access/tooling, report `blocked` with exact failed wrapper command and do not claim completion.
|
16. If any of items 13-15 fail due access/tooling, report `blocked` with exact failed wrapper command and do not claim completion.
|
||||||
|
|||||||
@@ -253,7 +253,7 @@ status → mission → run → repeat
|
|||||||
|
|
||||||
- [ ] All milestone tasks in TASKS.md are `done`
|
- [ ] All milestone tasks in TASKS.md are `done`
|
||||||
- [ ] CI/pipeline green
|
- [ ] CI/pipeline green
|
||||||
- [ ] PR merged to the integration trunk
|
- [ ] PR merged to `main`
|
||||||
- [ ] Issues closed
|
- [ ] Issues closed
|
||||||
- [ ] Update manifest: milestone status → completed
|
- [ ] Update manifest: milestone status → completed
|
||||||
- [ ] Update scratchpad: session log entry
|
- [ ] Update scratchpad: session log entry
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ mosaic claude -p "Read ~/.config/mosaic/skills/nestjs-best-practices/SKILL.md th
|
|||||||
- You MUST keep the TASKS.md file updated with agent and tasks statuses.
|
- You MUST keep the TASKS.md file updated with agent and tasks statuses.
|
||||||
- You MUST keep `docs/` root clean. Reports and working artifacts MUST be stored in scoped folders (`docs/reports/`, `docs/tasks/`, `docs/releases/`, `docs/scratchpads/`).
|
- You MUST keep `docs/` root clean. Reports and working artifacts MUST be stored in scoped folders (`docs/reports/`, `docs/tasks/`, `docs/releases/`, `docs/scratchpads/`).
|
||||||
- You MUST enforce plan/token usage budgets when provided, and adapt orchestration strategy to remain within limits.
|
- You MUST enforce plan/token usage budgets when provided, and adapt orchestration strategy to remain within limits.
|
||||||
- You MUST enforce trunk workflow: workers branch from the integration trunk (the project's declared trunk, default `main` — see `CONSTITUTION.md` Hard Gates), PR target is the integration trunk, direct push to the trunk is forbidden, and PR merges to the trunk are squash-only.
|
- You MUST enforce trunk workflow: workers branch from `main`, PR target is `main`, direct push to `main` is forbidden, and PR merges to `main` are squash-only.
|
||||||
- You MUST operate in steered-autonomy mode: human intervention is escalation-only; do not require the human to write code, review code, or manage PR/repo workflow.
|
- You MUST operate in steered-autonomy mode: human intervention is escalation-only; do not require the human to write code, review code, or manage PR/repo workflow.
|
||||||
- You MUST NOT declare task or issue completion until PR is merged, CI/pipeline is terminal green, and linked issue is closed (or internal TASKS ref is closed when provider is unavailable).
|
- You MUST NOT declare task or issue completion until PR is merged, CI/pipeline is terminal green, and linked issue is closed (or internal TASKS ref is closed when provider is unavailable).
|
||||||
- Mosaic orchestration rules OVERRIDE runtime-default caution for routine push/merge/issue-close actions required by this workflow.
|
- Mosaic orchestration rules OVERRIDE runtime-default caution for routine push/merge/issue-close actions required by this workflow.
|
||||||
@@ -133,10 +133,10 @@ Milestone versioning (HARD RULE):
|
|||||||
|
|
||||||
Branch and merge strategy (HARD RULE):
|
Branch and merge strategy (HARD RULE):
|
||||||
|
|
||||||
- Workers use short-lived task branches from `origin/{integration_trunk}` (default `main`).
|
- Workers use short-lived task branches from `origin/main`.
|
||||||
- Worker task branches merge back via PR to the integration trunk only.
|
- Worker task branches merge back via PR to `main` only.
|
||||||
- Direct pushes to the integration trunk are prohibited.
|
- Direct pushes to `main` are prohibited.
|
||||||
- PR merges to the integration trunk MUST use squash merge.
|
- PR merges to `main` MUST use squash merge.
|
||||||
|
|
||||||
**Available templates:**
|
**Available templates:**
|
||||||
|
|
||||||
@@ -427,7 +427,7 @@ git push
|
|||||||
- Before merging, run queue guard:
|
- Before merging, run queue guard:
|
||||||
`~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`
|
`~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`
|
||||||
- Ensure PR exists for the task branch (create/update via wrappers if needed):
|
- Ensure PR exists for the task branch (create/update via wrappers if needed):
|
||||||
`~/.config/mosaic/tools/git/pr-create.sh ... -B {integration_trunk}` (default `main`)
|
`~/.config/mosaic/tools/git/pr-create.sh ... -B main`
|
||||||
- Merge via wrapper:
|
- Merge via wrapper:
|
||||||
`~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
`~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
||||||
- Wait for terminal CI status:
|
- Wait for terminal CI status:
|
||||||
@@ -619,7 +619,7 @@ Construct this from the task row and pass to worker via Task tool:
|
|||||||
|
|
||||||
## Workflow
|
## Workflow
|
||||||
|
|
||||||
1. Checkout branch: `git fetch origin && (git checkout {branch} || git checkout -b {branch} origin/{integration_trunk}) && git rebase origin/{integration_trunk}` ({integration_trunk} = the project's declared trunk, default `main`)
|
1. Checkout branch: `git fetch origin && (git checkout {branch} || git checkout -b {branch} origin/main) && git rebase origin/main`
|
||||||
2. Read `docs/PRD.md` or `docs/PRD.json` and align implementation with PRD requirements
|
2. Read `docs/PRD.md` or `docs/PRD.json` and align implementation with PRD requirements
|
||||||
3. Read the finding details from the report
|
3. Read the finding details from the report
|
||||||
4. Implement the fix following existing code patterns
|
4. Implement the fix following existing code patterns
|
||||||
@@ -637,7 +637,7 @@ Do NOT leave lint warnings or errors for someone else to clean up. 6. Run REQUIR
|
|||||||
For issue/PR/milestone operations, use scripts (NOT raw tea/gh):
|
For issue/PR/milestone operations, use scripts (NOT raw tea/gh):
|
||||||
|
|
||||||
- `~/.config/mosaic/tools/git/issue-view.sh -i {N}`
|
- `~/.config/mosaic/tools/git/issue-view.sh -i {N}`
|
||||||
- `~/.config/mosaic/tools/git/pr-create.sh -t "Title" -b "Desc" -B {integration_trunk}`
|
- `~/.config/mosaic/tools/git/pr-create.sh -t "Title" -b "Desc" -B main`
|
||||||
- Push: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B {task_branch}`
|
- Push: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B {task_branch}`
|
||||||
- Merge: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B {pr_head_branch} -R {pr_head_owner/repo} --sha {pr_head_full_sha}`
|
- Merge: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B {pr_head_branch} -R {pr_head_owner/repo} --sha {pr_head_full_sha}`
|
||||||
- `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
- `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
||||||
@@ -994,13 +994,13 @@ mv docs/reports/qa-automation/pending/*failing-file* docs/reports/qa-automation/
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Merge-to-Trunk Candidate Protocol (Container Deployments)
|
## Merge-to-Main Candidate Protocol (Container Deployments)
|
||||||
|
|
||||||
If deployment is in scope and container images are used, every merge to the integration trunk MUST execute this protocol:
|
If deployment is in scope and container images are used, every merge to `main` MUST execute this protocol:
|
||||||
|
|
||||||
1. Build and push immutable candidate image tags:
|
1. Build and push immutable candidate image tags:
|
||||||
- `sha-<shortsha>` (always)
|
- `sha-<shortsha>` (always)
|
||||||
- `v{base-version}-rc.{build}` (for integration-trunk merges)
|
- `v{base-version}-rc.{build}` (for `main` merges)
|
||||||
- `testing` mutable pointer to the same digest
|
- `testing` mutable pointer to the same digest
|
||||||
2. Resolve and record the image digest for each service.
|
2. Resolve and record the image digest for each service.
|
||||||
3. Deploy by digest to testing environment (never deploy by mutable tag alone).
|
3. Deploy by digest to testing environment (never deploy by mutable tag alone).
|
||||||
|
|||||||
Reference in New Issue
Block a user