Skip to content

Commit 513e82e

Browse files
Install the breakglass caller (#235)
Nineteen lines, no logic — the whole per-repo install for breakglass. Comment `/breakglass <reason>` on a PR here and it merges without its required approval, recording the reason on the PR. The mechanism lives in [kernel/security-workflows](kernel/security-workflows#18) and is shared, so changes to it need no PR here. **This repo is public**, which is why the mechanism is hosted in a public repo — a public repository cannot call a reusable workflow stored in a private one, and the failure is silent (run created, zero jobs, nothing on the PR). Why a file per repo: `issue_comment` fires in the repo where the comment is left, and GitHub only runs a workflow if the file is on *that* repo's default branch. Reusable workflows share logic, not triggers. Docs: [kernel/infra docs/breakglass.md](https://github.com/kernel/infra/blob/main/docs/breakglass.md) Depends on kernel/security-workflows#18 landing first. Requires the org-level `BREAKGLASS_APP_ID` / `BREAKGLASS_APP_PRIVATE_KEY` secrets shared with this repo, and the `kernel-breakglass` app installed on it. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Introduces an approval-bypass merge path tied to org breakglass app credentials; impact is limited by the thin caller and narrowly scoped secrets, but misuse or misconfiguration could merge PRs without normal review gates. > > **Overview** > Adds a minimal **Breakglass** GitHub Actions workflow so reviewers can comment `/breakglass <reason>` on a PR to merge without required approvals, with the reason recorded on the PR. > > The new `.github/workflows/breakglass.yml` only wires the trigger: it runs on `issue_comment` when the comment is on a PR and starts with `/breakglass`, then calls the shared reusable workflow `kernel/security-workflows/.github/workflows/breakglass-merge.yml@main`. Workflow-level `permissions` are empty, and only `BREAKGLASS_APP_ID` and `BREAKGLASS_APP_PRIVATE_KEY` are passed (not `secrets: inherit`) so the external workflow does not receive this repo’s other secrets. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 3f88d13. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> Co-authored-by: ulziibay-kernel <253135130+ulziibay-kernel@users.noreply.github.com>
1 parent 1a2c351 commit 513e82e

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

‎.github/workflows/breakglass.yml‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
name: Breakglass
2+
3+
# Comment `/breakglass <reason>` on a PR to merge it without its required approval.
4+
# The mechanism lives in kernel/security-workflows; this file is the whole per-repo install
5+
# and should never grow logic. See kernel/infra docs/breakglass.md.
6+
7+
on:
8+
issue_comment:
9+
types: [created]
10+
11+
permissions: {}
12+
13+
jobs:
14+
merge:
15+
if: github.event.issue.pull_request && startsWith(github.event.comment.body, '/breakglass')
16+
uses: kernel/security-workflows/.github/workflows/breakglass-merge.yml@main
17+
# Named rather than `secrets: inherit`: this calls a workflow in another repository, and
18+
# inherit would hand it every secret this repo holds.
19+
secrets:
20+
BREAKGLASS_APP_ID: ${{ secrets.BREAKGLASS_APP_ID }}
21+
BREAKGLASS_APP_PRIVATE_KEY: ${{ secrets.BREAKGLASS_APP_PRIVATE_KEY }}

0 commit comments

Comments
 (0)