Files
houseplan-card/.github/workflows/_process-reconcile.yml
Claude baf283c50f ci: thin default-branch callers invoke reusable bodies at @dev (#623)
Six workflows run from the default branch (issues, schedule, workflow_run):
process, process-resume, process-reconcile, mutation-gate, nightly,
process-metrics. Their bodies move to _<name>.yml (on: workflow_call); the
original files keep only triggers, run-name, permissions, concurrency and one
job `uses: Matysh/houseplan-card/.github/workflows/_<name>.yml@dev` with
`secrets: inherit`. A pipeline change becomes one commit to dev.

- caller job permissions = union of body job permissions (#556 minimum kept
  per job inside the body); caller `if` repeats the body guard for process and
  process-resume so unrelated events stay skipped;
- dispatch inputs forwarded via workflow_call inputs of the same names;
- _mutation-gate.yml keys evidence/marker on job.workflow_sha (the body SHA):
  in a called workflow github.workflow_sha belongs to the caller in main;
- action-pins: narrow exception for this repo's _*.yml at @dev with a reason;
- preflight workflow_sync compares all six thin callers (was 3 of 6);
  performance.yml excluded: its schedule judges main with main's own body;
- tests read bodies from _*.yml; new test/default-branch-workflows.test.mjs;
  six mutants; PROCESS.md §10.4, AGENTS.md, REVIEWER.md updated.

Issue: #623
User-Visible: no
2026-09-24 10:23:28 +03:00

58 lines
2.2 KiB
YAML

name: "Сверка очереди ревью · тело (#623)"
on:
# #623: тело вызывается тонким файлом `process-reconcile.yml` из ветки по умолчанию
# по ссылке `@dev`; триггеры, run-name и concurrency живут там.
workflow_call:
inputs:
apply:
description: "Повторно будить потерянные запросы и публиковать диагностику"
required: false
type: boolean
default: true
permissions:
actions: read
contents: read
issues: read
jobs:
reconcile:
name: "Один снимок S4/S7 без polling модели"
runs-on: ubuntu-latest
timeout-minutes: 10
concurrency:
group: process-reconcile
cancel-in-progress: false
steps:
# Расписание читается из main, а исполняемый reconciler — из dev: так
# после штатного merge действует та же версия кода, которую проверил CI.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: dev
fetch-depth: 1
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 22
- name: Сопоставить labels, requests, runs и sealed evidence
env:
GH_TOKEN: ${{ secrets.HP_PROCESS_TOKEN }}
REPO: ${{ github.repository }}
APPLY: ${{ github.event_name == 'schedule' || inputs.apply == true }}
run: |
mkdir -p artifacts/process-reconcile
node scripts/process-reconcile.mjs \
--repo "$REPO" \
--apply="$APPLY" \
--max-actions=5 \
--output=artifacts/process-reconcile/summary.json
- name: Опубликовать компактный machine-readable итог
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: process-reconcile-${{ github.run_id }}-${{ github.run_attempt }}
path: artifacts/process-reconcile/summary.json
if-no-files-found: error
retention-days: 14