generated from mathias/template-go-web
feat(ci): wire var-go/oath gate into CI (#1)
Adds an oath job to cd.yml: on pull_request, checks out swedsl (the vargo-gate source — its oath submodule isn't go-installable, module path isn't a real import path) and runs cmd/vargo-gate against this repo's linked issue, posting a var-go/oath commit status. Deliberately NOT required by branch protection: vargo-gate's candidate is still a hardcoded toy self-test registry (swedsl's own #9 fixture), not a real PR-diff checker, so it fails closed against any real oath until swedsl ships an Executor (swedsl#27). Requiring it now would permanently block every cad-atlas PR. Disclosed in the CI config comment, PROJECT.md, and docs/INCEPTION-OATH.md (honest-stub discipline). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+7
-3
@@ -54,9 +54,13 @@ assessor-loop ledger) → `06 PR → CI` (go test/vet/lint/govulncheck + **var-g
|
||||
|
||||
This repo is built *through* the workflow it depicts. It is `dispatch-allow`-enabled, and its
|
||||
own build increments are governed by a **var-go Oath** embedded in their spec issues (see the
|
||||
Stage-03 tracking issue). Bootstrapping honesty (per swedsl honest-stub discipline): the Oath is
|
||||
**defined** but `cmd/vargo-gate` is **not yet wired** into this repo's CI — until it is, the Oath
|
||||
is advisory here. Wiring it is a first tracked task; disclosed in code, this doc, and CI config.
|
||||
Stage-03 tracking issue). Bootstrapping honesty (per swedsl honest-stub discipline): `cmd/vargo-gate`
|
||||
is wired into `.gitea/workflows/cd.yml`'s `oath` job (issue #1) — it runs on every pull_request,
|
||||
fetches the linked issue's oath, and posts a `var-go/oath` commit status. But its candidate is
|
||||
still a hardcoded toy self-test registry, not a real PR-diff checker (swedsl's Executor question,
|
||||
swedsl#27, is unbuilt) — it fails closed against any real oath. The status is **not** required by
|
||||
branch protection, so it can't block merges yet; enabling that waits on the real-diff Executor.
|
||||
Disclosed in the CI config comment, this doc, and `docs/INCEPTION-OATH.md`.
|
||||
|
||||
## Brain references (source of truth — `brain_get <path>`)
|
||||
|
||||
|
||||
@@ -53,6 +53,50 @@ jobs:
|
||||
- name: Run checks
|
||||
run: task check
|
||||
|
||||
oath:
|
||||
name: var-go/oath
|
||||
needs: guard
|
||||
# Only a real pull_request event carries a linked-issue oath to gate (mirrors
|
||||
# swedsl's own oath job, .gitea/workflows/ci.yml). v1 simplification (swedsl#30):
|
||||
# the oath issue number is the PR's OWN number.
|
||||
#
|
||||
# DISCLOSED LIMITATION (honest-stub discipline, see docs/INCEPTION-OATH.md S3 and
|
||||
# knowledge/swedsl-vargo-sprint1-enforcement-teeth-verdict.md): cmd/vargo-gate's
|
||||
# candidate is a hardcoded toy self-test registry (swedsl's own #9 fixture
|
||||
# vocabulary), not a real PR-diff checker. It will fail closed against any oath
|
||||
# that isn't that toy vocabulary — which is every real oath, including this repo's
|
||||
# own #1. A red or green "var-go/oath" status here currently proves the WIRING
|
||||
# (fetch issue -> gate -> post commit status) runs end-to-end on a real PR, not
|
||||
# that the PR satisfies its linked issue's oath. Deliberately NOT required by
|
||||
# branch protection until swedsl ships a real-diff Executor (swedsl#27) — making
|
||||
# it required now would permanently block every cad-atlas PR.
|
||||
if: needs.guard.outputs.is_template != 'true' && github.event_name == 'pull_request'
|
||||
runs-on: self-hosted
|
||||
steps:
|
||||
- name: Checkout swedsl (var-go source — not go-installable, module path isn't a real import path)
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: mathias/swedsl
|
||||
path: swedsl
|
||||
token: ${{ secrets.DMABE_GITEA_API_TOKEN }}
|
||||
|
||||
- uses: actions/setup-go@v5
|
||||
with:
|
||||
go-version-file: swedsl/oath/go.mod
|
||||
cache: false
|
||||
|
||||
- name: Run vargo-gate (fetch -> gate -> post status against this PR)
|
||||
working-directory: swedsl/oath
|
||||
env:
|
||||
VARGO_GITEA_BASEURL: ${{ github.server_url }}
|
||||
VARGO_GITEA_OWNER: ${{ github.repository_owner }}
|
||||
VARGO_GITEA_REPO: cad-atlas
|
||||
VARGO_GITEA_ISSUE: ${{ github.event.pull_request.number }}
|
||||
VARGO_GITEA_SHA: ${{ github.event.pull_request.head.sha }}
|
||||
run: |
|
||||
export DMABE_GITEA_API_TOKEN='${{ secrets.DMABE_GITEA_API_TOKEN }}'
|
||||
go run ./cmd/vargo-gate
|
||||
|
||||
build:
|
||||
name: Build & Import
|
||||
needs: [guard, check]
|
||||
|
||||
@@ -3,8 +3,9 @@
|
||||
The acceptance contract for standing up cad-atlas. The sprint is finalized only when this
|
||||
Oath holds. Methodology: brain `wiki/homelab/decisions/inception-sprint-and-oath.md`.
|
||||
|
||||
> **Status of enforcement:** this Oath is currently **advisory** (human-verified). Machine
|
||||
> enforcement via `var-go/oath` is deferred — see the honesty rule below and issue #1.
|
||||
> **Status of enforcement:** this Oath is currently **advisory** (human-verified). `var-go/oath`
|
||||
> is wired (issue #1) and runs on every PR, but its candidate is a toy self-test — it fails closed
|
||||
> against any real oath and is not required by branch protection. See the honesty rule below.
|
||||
|
||||
## General clauses (any inception sprint)
|
||||
|
||||
@@ -24,7 +25,7 @@ Oath holds. Methodology: brain `wiki/homelab/decisions/inception-sprint-and-oath
|
||||
|---|--------|--------|----------|
|
||||
| S1 | Atlas served at `/`, renders all 9 stages signal→pod | ✅ | `internal/web/handler.go` + `static/cad-atlas.html` |
|
||||
| S2 | Oath covered in the viz (stages 03 + 06) | ✅ | var-go Oath nodes in the atlas |
|
||||
| S3 | `var-go/oath` enforces cad-atlas's own PRs | ⏸ **deferred → #1** | var-go v1 candidate is a toy self-test; module not cross-repo consumable. See honesty rule. |
|
||||
| S3 | `var-go/oath` enforces cad-atlas's own PRs | ⏸ **wired, not enforcing → #1** | `oath` job runs + posts status (#1). Not branch-protection-required: candidate is still a toy self-test, fails closed on every real oath until swedsl's Executor (swedsl#27) exists. See honesty rule. |
|
||||
|
||||
## Deployment
|
||||
|
||||
|
||||
Reference in New Issue
Block a user