Skip to content

ci: mirror canonical main to Gitea with a drift check (Refs #342) - #37

Merged
AlexMikhalev merged 1 commit into
mainfrom
task/342-forge-mirror
Oct 4, 2026
Merged

AlexMikhalev merged 1 commit into
mainfrom
task/342-forge-mirror

Conversation

@AlexMikhalev

Copy link
Copy Markdown
Contributor

Summary

Implements the cross-forge mirroring decision: GitHub is canonical, and a CI workflow mirrors main + tags to the Gitea mirror and then proves the reconciliation invariant.

  • .github/workflows/forge-mirror.yml — on push to main and v* tags, pushes to git.terraphim.cloud/terraphim/terraphim-clients and runs the drift check. Requires a repository secret GITEA_MIRROR_TOKEN (Gitea token with Contents: write). Fails closed with a clear ::error:: when the secret is absent.
  • scripts/ci/check-forge-drift.sh — fails when two refs differ on a path set (default .github scripts); used by the workflow and usable locally.

This turns the manual #342 invariant into an enforced one: any Gitea-side change to .github//scripts/ must be mirrored to GitHub first, or CI fails.

Evidence

$ scripts/ci/check-forge-drift.sh refs/remotes/gitea/main refs/remotes/github/main .github scripts
forge drift: refs/remotes/gitea/main == refs/remotes/github/main on: .github scripts  (exit 0)

$ scripts/ci/check-forge-drift.sh refs/remotes/github/main refs/remotes/github/main~5 .github scripts
forge drift: ... differ on: .github scripts  (exit 1)

Refs terraphim-clients#342.

@AlexMikhalev
AlexMikhalev merged commit e94ff47 into main Oct 4, 2026
1 of 2 checks passed
@AlexMikhalev
AlexMikhalev deleted the task/342-forge-mirror branch October 4, 2026 09:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant