Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions .controlplane/docs/testing-cpflow-github-actions.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Testing cpflow GitHub Actions Changes

Generic reusable-workflow behavior belongs upstream in the
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.2.0/docs/ci-automation.md).
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.3.0/docs/ci-automation.md).
Use this repo note only as the canary checklist for
`react-webpack-rails-tutorial`.

Expand Down Expand Up @@ -30,8 +30,9 @@ bin/conductor-exec bin/test-cpflow-github-flow ruby /path/to/control-plane-flow/
```

Leave `CPFLOW_VERSION` unset while testing a commit SHA. After the upstream PR
ships in a release tag, repin wrappers to that tag. Use `v5.2.0` for the
promotion-hardening and release-runner timeout fixes; use immutable commit SHAs
ships in a release tag, repin wrappers to that tag. Use `v5.3.0` for the
current review-app flow, including the earlier promotion-hardening and
release-runner timeout fixes; use immutable commit SHAs
only for future unreleased upstream PR tests.

## Review App Canary
Expand Down
6 changes: 3 additions & 3 deletions .controlplane/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ You can see the definition of Postgres and Redis in the `.controlplane/templates

This repo uses the generated `cpflow-*` GitHub Actions wrappers. Keep the
generic behavior documented upstream in the
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.2.0/docs/ci-automation.md);
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.3.0/docs/ci-automation.md);
this section only lists the values that are specific to this app.

### Review Apps and Staging
Expand Down Expand Up @@ -629,13 +629,13 @@ React on Rails docs reference:
### Updating Generated cpflow Workflows

Keep the reusable-workflow mechanics in the upstream
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.2.0/docs/ci-automation.md).
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.3.0/docs/ci-automation.md).
For this repo, the update loop is:

1. Update the bundled `cpflow` gem to the desired release.
2. Refresh generated wrappers from that release with `--staging-branch master`.
3. Keep generated refs on the same release tag as the bundled `cpflow` gem.
This branch pins refs to `v5.2.0`, which includes upstream promotion
This branch pins refs to `v5.3.0`, which includes upstream promotion
hardening and the release-runner timeout fix. Use a full commit SHA only for
short-lived upstream testing and leave `CPFLOW_VERSION` unset in that case.
4. Keep app names and GitHub settings aligned with `.controlplane/controlplane.yml`.
Expand Down
4 changes: 2 additions & 2 deletions .controlplane/shakacode-team.md
Original file line number Diff line number Diff line change
Expand Up @@ -126,9 +126,9 @@ cpflow apply-template app postgres redis daily-task node-renderer rails \
```

Advanced optional settings are documented upstream in the
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.2.0/docs/ci-automation.md).
[`control-plane-flow` CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.3.0/docs/ci-automation.md).

Current workflow wrappers pin `control-plane-flow` release tag `v5.2.0`, which
Current workflow wrappers pin `control-plane-flow` release tag `v5.3.0`, which
includes promotion hardening and the release-runner timeout fix. Keep release
tags as the steady-state configuration; use a full commit SHA only for
short-lived upstream testing and leave `CPFLOW_VERSION` unset in that case.
Expand Down
8 changes: 4 additions & 4 deletions .github/cpflow-help.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

These commands are generated by [cpflow](https://github.com/shakacode/control-plane-flow).
For full setup, version-pinning, and troubleshooting details, see the upstream
[CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.2.0/docs/ci-automation.md).
[CI automation guide](https://github.com/shakacode/control-plane-flow/blob/v5.3.0/docs/ci-automation.md).

## Pull Request Commands

Expand Down Expand Up @@ -130,16 +130,16 @@ production org, using production-only secrets and values.
## Version Locking

Generated wrappers pin Control Plane Flow with a release tag, for example
`v5.2.0`. Reusable review-app, staging, cleanup, and
`v5.3.0`. Reusable review-app, staging, cleanup, and
Comment thread
justin808 marked this conversation as resolved.
helper workflows pin the tag in their `uses:` ref. Production promotion pins
the same tag in the `Checkout control-plane-flow actions` step so the
caller-owned job can keep `environment: production` and receive production
environment secrets directly.

Leave `CPFLOW_VERSION` unset so the workflow builds cpflow from the same
checked-out upstream source. If you set `CPFLOW_VERSION`, it must match the
release tag your wrappers are pinned to: a `CPFLOW_VERSION=5.2.x` runtime
override goes with a wrapper pinned to `uses: ...@v5.2.x` (substitute the
release tag your wrappers are pinned to: a `CPFLOW_VERSION=5.3.x` runtime
override goes with a wrapper pinned to `uses: ...@v5.3.x` (substitute the
release you pinned above).

After updating the `cpflow` gem in this repo, update the generated wrappers in
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cpflow-cleanup-stale-review-apps.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,6 @@ jobs:
cleanup:
# Cleanup targets the current inferred review-app prefix. If you changed
# naming conventions, manually delete review apps under the old prefix.
uses: shakacode/control-plane-flow/.github/workflows/cpflow-cleanup-stale-review-apps.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-cleanup-stale-review-apps.yml@v5.3.0
secrets:
CPLN_TOKEN_STAGING: ${{ secrets.CPLN_TOKEN_STAGING }}
12 changes: 11 additions & 1 deletion .github/workflows/cpflow-delete-review-app.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
name: Delete Review App

run-name: "Delete Review App - PR #${{ github.event.pull_request.number || github.event.issue.number || github.event.inputs.pr_number }}"

on:
pull_request_target:
types: [closed]
Expand All @@ -11,9 +13,15 @@ on:
description: Pull request number targeted for deletion
required: true
type: number
reconcile_intent_run_id:
description: Authenticated internal handoff; manual values are rejected
required: false
type: string

permissions:
actions: write
Comment thread
justin808 marked this conversation as resolved.
contents: read
deployments: write
issues: write
pull-requests: write

Expand All @@ -22,6 +30,8 @@ jobs:
# pull_request_target is intentional: fork PR-close events need access to
# staging secrets to delete review apps and update PR comments. The upstream
# reusable workflow checks out trusted base-branch action code, not fork code.
# author_association is a cheap caller-side cost filter. The reusable workflow
# still checks the commenter's current repository permission before privileged work.
if: |
(github.event_name == 'issue_comment' &&
github.event.issue.pull_request &&
Expand All @@ -31,6 +41,6 @@ jobs:
github.event_name == 'workflow_dispatch'
# This `if:` mirrors the upstream job guard to avoid a billable workflow_call
# when the event does not match. Keep both conditions in sync.
uses: shakacode/control-plane-flow/.github/workflows/cpflow-delete-review-app.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-delete-review-app.yml@v5.3.0
secrets:
CPLN_TOKEN_STAGING: ${{ secrets.CPLN_TOKEN_STAGING }}
11 changes: 10 additions & 1 deletion .github/workflows/cpflow-deploy-review-app.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,15 +13,24 @@ on:
description: Pull request number to deploy
required: true
type: number
reconcile_intent_run_id:
Comment thread
justin808 marked this conversation as resolved.
description: Authenticated internal handoff; manual values are rejected
required: false
type: string

permissions:
actions: write
contents: read
deployments: write
issues: write
pull-requests: write

jobs:
# The reusable job exposes `image_built`; downstream jobs can read
# `needs.deploy.outputs.image_built`. A value of `false` means this check did not validate the Docker image.
deploy:
# author_association is a cheap caller-side cost filter. The reusable workflow
# still checks the commenter's current repository permission before privileged work.
if: |
(github.event_name == 'pull_request' &&
github.event.pull_request.head.repo.full_name == github.repository) ||
Expand All @@ -30,7 +39,7 @@ jobs:
github.event.issue.pull_request &&
contains(fromJson('["+review-app-deploy","+review-app-deploy\n","+review-app-deploy\r\n"]'), github.event.comment.body) &&
contains(fromJson('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association))
uses: shakacode/control-plane-flow/.github/workflows/cpflow-deploy-review-app.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-deploy-review-app.yml@v5.3.0
secrets:
CPLN_TOKEN_STAGING: ${{ secrets.CPLN_TOKEN_STAGING }}
DOCKER_BUILD_SSH_KEY: ${{ secrets.DOCKER_BUILD_SSH_KEY }}
2 changes: 1 addition & 1 deletion .github/workflows/cpflow-deploy-staging.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ permissions:

jobs:
deploy-staging:
uses: shakacode/control-plane-flow/.github/workflows/cpflow-deploy-staging.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-deploy-staging.yml@v5.3.0
with:
staging_app_branch_default: "master"
secrets:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cpflow-help-command.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,4 +23,4 @@ jobs:
contains(fromJson('["+review-app-help","+review-app-help\n","+review-app-help\r\n"]'), github.event.comment.body) &&
contains(fromJson('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) ||
github.event_name == 'workflow_dispatch'
uses: shakacode/control-plane-flow/.github/workflows/cpflow-help-command.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-help-command.yml@v5.3.0
4 changes: 2 additions & 2 deletions .github/workflows/cpflow-promote-staging-to-production.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ jobs:
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
with:
repository: shakacode/control-plane-flow
ref: v5.2.0
ref: v5.3.0
path: .cpflow
persist-credentials: false

Expand Down Expand Up @@ -179,7 +179,7 @@ jobs:
cpln_cli_version: ${{ vars.CPLN_CLI_VERSION }}
cpflow_version: ${{ vars.CPFLOW_VERSION }}
# The setup action validates CPFLOW_VERSION against this full workflow ref.
control_plane_flow_ref: shakacode/control-plane-flow/.github/workflows/cpflow-promote-staging-to-production.yml@v5.2.0
control_plane_flow_ref: shakacode/control-plane-flow/.github/workflows/cpflow-promote-staging-to-production.yml@v5.3.0

# Runs after Setup production environment so the pinned Ruby (>= 3.1) is on PATH.
# YAML.load_file(..., aliases: true) is not supported on Ruby 3.0 (system Ruby on ubuntu-22.04).
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/cpflow-review-app-help.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,4 @@ jobs:
# to PR-open help. Remove it, or uncomment and adapt this guard, if forks or
# clones should stay quiet until Control Plane is configured:
# if: vars.REVIEW_APP_PREFIX != '' || vars.CPLN_ORG_STAGING != ''
uses: shakacode/control-plane-flow/.github/workflows/cpflow-review-app-help.yml@v5.2.0
uses: shakacode/control-plane-flow/.github/workflows/cpflow-review-app-help.yml@v5.3.0
2 changes: 1 addition & 1 deletion Gemfile
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ git_source(:github) { |repo| "https://github.com/#{repo}.git" }

ruby "3.4.6"

gem "cpflow", "5.2.0", require: false
gem "cpflow", "5.3.0", require: false
gem "react_on_rails_pro", "17.0.0"
gem "shakapacker", "10.2.0"

Expand Down
4 changes: 2 additions & 2 deletions Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ GEM
term-ansicolor (~> 1.6)
thor (>= 0.20.3, < 2.0)
tins (~> 1.16)
cpflow (5.2.0)
cpflow (5.3.0)
dotenv (~> 3.1)
jwt (~> 3.1)
psych (~> 5.2)
Expand Down Expand Up @@ -530,7 +530,7 @@ DEPENDENCIES
capybara-screenshot
coffee-rails
coveralls_reborn (~> 0.25.0)
cpflow (= 5.2.0)
cpflow (= 5.3.0)
database_cleaner
debug (>= 1.0.0)
factory_bot_rails
Expand Down
Loading