mirror of
https://github.com/pezkuwichain/pezkuwi-telegram-miniapp.git
synced 2026-08-02 20:15:43 +00:00
b2b4751f7a
Two pieces of infrastructure existed only on servers, as single copies with no history and no review: /usr/local/bin/supabase-deploy-functions the gate both projects deploy through /opt/supabase-self-hosted/functions-registry.json who owns which function name The gate exists to stop silent drift between what a repo declares and what a server actually runs. Leaving it unversioned meant the mechanism was drifting the same way it was built to prevent — and losing that host would have lost it entirely, along with any record of why it works the way it does. Both are now in ops/ and synced to the host by CI on every deploy, installed before the functions they validate so a change to the gate ships together with them. Verified identical to the server copies by checksum before committing, so this captures the running state rather than replacing it. Branch protection gets the same treatment: apply-repo-settings.sh is idempotent and has a --check mode that reports drift without changing anything. It was applied by hand through the API today, so nothing here reflected it. Documented alongside: why the registry lives in this repo even though pwap-web depends on it (a pwap-web change needs a PR here — deliberate friction, since the registry is the record of who owns what and should not be edited on a server where nobody sees the change), and why listing each CI job individually in the protection rules is a weakness here that pwap-web avoids with an aggregate job.