Skip to content

fix: connect guarded App auto-merge to production deployment - #23

Merged
dextech-auto-merge[bot] merged 8 commits into
mainfrom
ci/guarded-merge-app-deploy
Sep 7, 2026
Merged

fix: connect guarded App auto-merge to production deployment#23
dextech-auto-merge[bot] merged 8 commits into
mainfrom
ci/guarded-merge-app-deploy

Conversation

@dexsword

@dexsword dexsword commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Automated merges made with GITHUB_TOKEN do not start the push-to-main production workflow. Use the configured GitHub App only for final exact-candidate revalidation, native squash auto-merge, and independent confirmation. Keep the workflow token read-only in that job for required-check and run metadata; reject missing App credentials and requests from the wrong bot identity.

Preserve required checks on the verified source HEAD, independent synthetic-merge/base binding, stale-run disarming/cancellation, bounded merge discovery, read-only Codex, deterministic eligibility, and all production gates. Preserve base-retarget evaluation while filtering title/body edits so they start no CI/review jobs and cannot cancel or supersede active review. Pin actions/create-github-app-token v3.2.0 to bcd2ba49218906704ab6c1aa796996da409d3eb1 and scope its revocable token to dexsword/dextech with Contents/Pull requests write only.

Validation: clean npm ci; 95 Node tests; 9 deployment-control tests; CI smoke/synthetic health; actionlint; ShellCheck; shell/JavaScript/Python syntax; YAML, JSON Schema, TOML schema; git diff --check. Production audit: zero high/critical findings, existing one low and one moderate.

This protected control change remains ineligible for unattended classification. Will explicitly authorized this installation PR's native squash auto-merge, with every required check enforced. The base-controlled workflow must be installed before an eligible follow-up PR can exercise the new App identity. Live merge/deployment evidence will be recorded in a comment. PR #17 remains closed and is diagnostic history only.

@dexsword
dexsword enabled auto-merge (squash) September 7, 2026 18:18
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Codex review feedback

Status: Resolved by a clean exact-head review
Reviewed head: 64540f1515d94a757972e5a27420f28e0521f99e
Confidence: 0.96

The latest schema-validated review found no blocking findings. Previous feedback is superseded.

@github-actions
github-actions Bot disabled auto-merge September 7, 2026 18:23
@dexsword
dexsword enabled auto-merge (squash) September 7, 2026 18:24
@github-actions
github-actions Bot disabled auto-merge September 7, 2026 18:30
@dexsword
dexsword enabled auto-merge (squash) September 7, 2026 18:30
@dextech-auto-merge
dextech-auto-merge Bot enabled auto-merge (squash) September 7, 2026 18:36
@github-actions
github-actions Bot disabled auto-merge September 7, 2026 18:49
@dextech-auto-merge
dextech-auto-merge Bot enabled auto-merge (squash) September 7, 2026 18:50
@github-actions
github-actions Bot disabled auto-merge September 7, 2026 18:55
@dextech-auto-merge
dextech-auto-merge Bot enabled auto-merge (squash) September 7, 2026 18:56
@github-actions
github-actions Bot disabled auto-merge September 7, 2026 19:01
@dextech-auto-merge
dextech-auto-merge Bot enabled auto-merge (squash) September 7, 2026 19:02
@github-actions
github-actions Bot disabled auto-merge September 7, 2026 19:08
@dextech-auto-merge
dextech-auto-merge Bot enabled auto-merge (squash) September 7, 2026 19:09
@dextech-auto-merge
dextech-auto-merge Bot merged commit fa08a35 into main Sep 7, 2026
10 checks passed
@dextech-auto-merge
dextech-auto-merge Bot deleted the ci/guarded-merge-app-deploy branch September 7, 2026 19:11
@dexsword

dexsword commented Sep 7, 2026

Copy link
Copy Markdown
Owner Author

End-to-end verification completed.

  • Installation head: 64540f1515d94a757972e5a27420f28e0521f99e. GitHub native App squash produced fa08a35fb5f5eae554caf644e2c5a96942ae0840; its production deployment passed.
  • Fresh eligible PR #25 then used the installed workflow without an operator/helper merge request. Scoped App token creation, native squash request/confirmation, token cleanup and custom-check publication all passed.
  • All three required checks (checks, Codex Review / gate, Auto Merge / eligible) succeeded on exact source HEAD a8e08e258ee16bf24f829c717350265cc4c66652; synthetic candidate e4934d6e1932c36e34b6fce5e6f26d872c65732f remained independently bound.
  • The App automatically merged PR25 into bff6dcab61a58f7799a8e5ce8212ad6cc76d4a0b; its push-triggered deployment passed. Local/public health return 200 with that SHA. Backup integrity, systemd, listener, Apache, Calendar refresh and sanitized log gates passed.
  • Local validation: 98 Node tests, 9 deployment tests, clean install, smoke/health, audit (zero high/critical), actionlint, ShellCheck and syntax/schema parsing passed. Installation CI also passed the live public-API contract regression.
  • The temporary installation helper branch was deleted. No ruleset, secret, tailnet or firewall changes; no immediate merge or admin bypass.

Observed non-blocking limitation: the pre-existing merged-PR closed handler may cancel trailing feedback and report a failed closed-candidate snapshot after successful required checks and automatic merging. It starts no new Codex review and did not block either successful deployment. Historical integration assertions are scoped to this installation PR so archived-run retention cannot block future application CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant