Skip to content

Sync module catalog from registry #22

Sync module catalog from registry

Sync module catalog from registry #22

# Module registration is TWO merges: the registry PR (castacks/
# airstack-modules-index) and a trunk PR mirroring the entries into the
# contract-test fixture + regenerating the committed docs/modules pages
# (see the extract-module skill). This workflow automates the trunk half:
# it diffs trunk against the live registry and opens/refreshes one sync PR
# when they disagree. The develop docs deploy's drift alarm is the loud
# signal; this is the fix.
#
# Cadence: dispatched by the registry's trigger-trunk-sync workflow on
# every registry merge, plus a daily sweep and manual dispatch. The
# registry itself is cloned read-only.
#
# TOKEN: branch push + PR creation prefer the REGISTRY_SYNC_TOKEN secret
# (a fine-grained PAT on castacks/AirStack with contents+pull-requests
# read/write) so the bot PR triggers CI like any human PR. Without the
# secret it falls back to the workflow token, whose PRs do NOT trigger
# other workflows (unit-tests, check-version-increment) — close and
# reopen such a PR to run them.
name: Sync module catalog from registry
on:
workflow_dispatch:
schedule:
- cron: "43 7 * * *" # daily sweep, 07:43 UTC
permissions:
contents: write
pull-requests: write
jobs:
sync:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# schedule/workflow_dispatch run on the default branch; the sync
# PR always targets develop.
ref: develop
fetch-depth: 0
# PAT when configured (bot PR triggers CI); workflow token otherwise.
token: ${{ secrets.REGISTRY_SYNC_TOKEN || github.token }}
- uses: actions/setup-python@v4
with:
python-version: 3.10.6
- name: Install Dependencies
run: pip install pyyaml
- name: Sync fixture + committed catalog from the live registry
id: sync
run: |
rm -rf .modules-index
git clone --depth 1 https://github.com/castacks/airstack-modules-index .modules-index
python3 .github/workflows/scripts/registry_sync.py --index .modules-index --bump
rm -rf .modules-index
if [ -n "$(git status --porcelain)" ]; then
echo "changed=true" >> "$GITHUB_OUTPUT"
else
echo "changed=false" >> "$GITHUB_OUTPUT"
fi
- name: Open or refresh the sync PR
if: steps.sync.outputs.changed == 'true'
env:
GH_TOKEN: ${{ secrets.REGISTRY_SYNC_TOKEN || github.token }}
run: |
git config user.name "Registry Sync"
git config user.email "registry.sync@example.co.uk"
git checkout -B bot/sync-modules-index
git add -A
git commit -m "chore(catalog): sync committed module catalog from airstack-modules-index"
git push -f origin bot/sync-modules-index
if [ -z "$(gh pr list --head bot/sync-modules-index --state open --json number --jq '.[].number')" ]; then
gh pr create --base develop --head bot/sync-modules-index \
--title "chore(catalog): sync committed module catalog from the registry" \
--body "$(printf 'Automated trunk half of module registration (see the extract-module skill): mirrors the live [airstack-modules-index](https://github.com/castacks/airstack-modules-index) into tests/meta/fixtures/modules_index/ and regenerates the committed docs/modules pages with tools/gen_docs_catalog.py. VERSION is bumped only to satisfy the check-version-increment gate (docs-only change; publish will retag, not rebuild).\n\nEverything here is deterministic output of already-reviewed registry entries.\n\nIf CI checks did not start on this PR, it was opened with the fallback workflow token (REGISTRY_SYNC_TOKEN secret not configured) — close and reopen it to trigger them. The branch is force-refreshed from develop on each run, so a stale VERSION bump heals itself on the next run.\n\nWorkflow: sync-modules-index (%s/%s/actions/runs/%s)' "$GITHUB_SERVER_URL" "$GITHUB_REPOSITORY" "$GITHUB_RUN_ID")"
else
echo "sync PR already open — branch refreshed in place"
fi