mirror of
https://github.com/pezkuwichain/pezkuwi-telegram-miniapp.git
synced 2026-08-06 08:05:39 +00:00
ops: version the ownership gate and this repo's branch protection
Two pieces of infrastructure existed only on servers, as single copies with no history and no review: /usr/local/bin/supabase-deploy-functions the gate both projects deploy through /opt/supabase-self-hosted/functions-registry.json who owns which function name The gate exists to stop silent drift between what a repo declares and what a server actually runs. Leaving it unversioned meant the mechanism was drifting the same way it was built to prevent — and losing that host would have lost it entirely, along with any record of why it works the way it does. Both are now in ops/ and synced to the host by CI on every deploy, installed before the functions they validate so a change to the gate ships together with them. Verified identical to the server copies by checksum before committing, so this captures the running state rather than replacing it. Branch protection gets the same treatment: apply-repo-settings.sh is idempotent and has a --check mode that reports drift without changing anything. It was applied by hand through the API today, so nothing here reflected it. Documented alongside: why the registry lives in this repo even though pwap-web depends on it (a pwap-web change needs a PR here — deliberate friction, since the registry is the record of who owns what and should not be edited on a server where nobody sees the change), and why listing each CI job individually in the protection rules is a weakness here that pwap-web avoids with an aggregate job.
This commit is contained in:
@@ -96,6 +96,21 @@ jobs:
|
||||
source: 'functions.tgz'
|
||||
target: '/opt/miniapp-deploy-staging'
|
||||
|
||||
# The gate and its registry are versioned here, so the server copy is
|
||||
# replaced from source control on every deploy rather than edited in
|
||||
# place. They previously existed only at /usr/local/bin — one copy, no
|
||||
# history, no review, gone with the server. The mechanism built to stop
|
||||
# silent drift was itself drifting.
|
||||
- name: Sync ownership gate to host
|
||||
uses: appleboy/scp-action@v1.0.0
|
||||
with:
|
||||
host: ${{ secrets.VPS2_HOST }}
|
||||
username: ${{ secrets.VPS2_USER }}
|
||||
key: ${{ secrets.VPS2_SSH_KEY }}
|
||||
source: 'ops/supabase-deploy-functions,ops/functions-registry.json'
|
||||
target: '/opt/miniapp-deploy-staging'
|
||||
strip_components: 1
|
||||
|
||||
- name: Deploy through ownership gate
|
||||
uses: appleboy/ssh-action@v1.0.0
|
||||
with:
|
||||
@@ -105,6 +120,11 @@ jobs:
|
||||
script: |
|
||||
set -e
|
||||
BASE=/opt/miniapp-deploy-staging
|
||||
|
||||
# Install the gate before using it, so a change to the gate ships in
|
||||
# the same deploy as the functions it validates.
|
||||
install -m 755 "$BASE/supabase-deploy-functions" /usr/local/bin/supabase-deploy-functions
|
||||
install -m 644 "$BASE/functions-registry.json" /opt/supabase-self-hosted/functions-registry.json
|
||||
trap 'rm -rf "$BASE"' EXIT
|
||||
rm -rf "$BASE/functions"
|
||||
tar xzf "$BASE/functions.tgz" -C "$BASE"
|
||||
|
||||
Reference in New Issue
Block a user