Sync module catalog from registry #25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Module registration is TWO merges: the registry PR (castacks/ | |
| # airstack-modules-index) and a trunk PR mirroring the entries into the | |
| # contract-test fixture + regenerating the committed docs/modules pages | |
| # (see the extract-module skill). This workflow automates the trunk half: | |
| # it diffs trunk against the live registry and opens/refreshes one sync PR | |
| # when they disagree. The develop docs deploy's drift alarm is the loud | |
| # signal; this is the fix. | |
| # | |
| # Cadence: dispatched by the registry's trigger-trunk-sync workflow on | |
| # every registry merge, plus a daily sweep and manual dispatch. The | |
| # registry itself is cloned read-only. | |
| # | |
| # TOKEN: branch push + PR creation prefer the REGISTRY_SYNC_TOKEN secret | |
| # (a fine-grained PAT on castacks/AirStack with contents+pull-requests | |
| # read/write) so the bot PR triggers CI like any human PR. Without the | |
| # secret it falls back to the workflow token, whose PRs do NOT trigger | |
| # other workflows (unit-tests, check-version-increment) — close and | |
| # reopen such a PR to run them. | |
| name: Sync module catalog from registry | |
| on: | |
| workflow_dispatch: | |
| schedule: | |
| - cron: "43 7 * * *" # daily sweep, 07:43 UTC | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| jobs: | |
| sync: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| # schedule/workflow_dispatch run on the default branch; the sync | |
| # PR always targets develop. | |
| ref: develop | |
| fetch-depth: 0 | |
| # PAT when configured (bot PR triggers CI); workflow token otherwise. | |
| token: ${{ secrets.REGISTRY_SYNC_TOKEN || github.token }} | |
| - uses: actions/setup-python@v4 | |
| with: | |
| python-version: 3.10.6 | |
| - name: Install Dependencies | |
| run: pip install pyyaml | |
| - name: Sync fixture + committed catalog from the live registry | |
| id: sync | |
| run: | | |
| rm -rf .modules-index | |
| git clone --depth 1 https://github.com/castacks/airstack-modules-index .modules-index | |
| python3 .github/workflows/scripts/registry_sync.py --index .modules-index --bump | |
| rm -rf .modules-index | |
| if [ -n "$(git status --porcelain)" ]; then | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Open or refresh the sync PR | |
| if: steps.sync.outputs.changed == 'true' | |
| env: | |
| GH_TOKEN: ${{ secrets.REGISTRY_SYNC_TOKEN || github.token }} | |
| run: | | |
| git config user.name "Registry Sync" | |
| git config user.email "registry.sync@example.co.uk" | |
| git checkout -B bot/sync-modules-index | |
| git add -A | |
| git commit -m "chore(catalog): sync committed module catalog from airstack-modules-index" | |
| git push -f origin bot/sync-modules-index | |
| if [ -z "$(gh pr list --head bot/sync-modules-index --state open --json number --jq '.[].number')" ]; then | |
| gh pr create --base develop --head bot/sync-modules-index \ | |
| --title "chore(catalog): sync committed module catalog from the registry" \ | |
| --body "$(printf 'Automated trunk half of module registration (see the extract-module skill): mirrors the live [airstack-modules-index](https://github.com/castacks/airstack-modules-index) into tests/meta/fixtures/modules_index/ and regenerates the committed docs/modules pages with tools/gen_docs_catalog.py. VERSION is bumped only to satisfy the check-version-increment gate (docs-only change; publish will retag, not rebuild).\n\nEverything here is deterministic output of already-reviewed registry entries.\n\nIf CI checks did not start on this PR, it was opened with the fallback workflow token (REGISTRY_SYNC_TOKEN secret not configured) — close and reopen it to trigger them. The branch is force-refreshed from develop on each run, so a stale VERSION bump heals itself on the next run.\n\nWorkflow: sync-modules-index (%s/%s/actions/runs/%s)' "$GITHUB_SERVER_URL" "$GITHUB_REPOSITORY" "$GITHUB_RUN_ID")" | |
| else | |
| echo "sync PR already open — branch refreshed in place" | |
| fi |