Add a Repository Setup workflow for the one-time repository settings - #170
Merged
Merged
Conversation
Three items on the Repository Setup Checklist are repository settings rather than files: the Pages source, the v* tag rule on the github-pages environment, and Dependabot alerts and security updates. None of them is visible to a pull request, so the checklist is the only thing enforcing them, and a skipped item fails months later instead of loudly. The tag rule reached the checklist only after a release deploy failed on riscv-performance-event-sampling (#165); the Dependabot switch only after a spec repository had accrued eleven open advisories with nothing opening a PR for any of them. This repository is itself missing the tag rule. repo-setup.yml applies all three from one dispatch, authenticating as GHTOKEN because GITHUB_TOKEN is refused for every one of them. It needs repo admin, which is more than template-sync.yml's workflow scope, so each step reports what to do by hand when a call is refused rather than aborting -- applying two of three beats stopping at the first refusal. Every step reads the current state first and skips when the setting is already correct, so it is safe to re-run and doubles as an audit. Added to template-sync.yml's copy list and UPGRADING.md's template-owned list, so migrated repositories receive it. README.adoc offers it as the fast path while keeping the manual steps as the fallback, and MIGRATION.md Step 16 points at it where a migrator already is. Verified by extracting the script and running it against riscv-high-assurance-cryptography and docs-spec-template with writes stubbed: the first reports all four settings already correct, the second correctly identifies the missing v* tag rule. That dry run also caught a real defect -- gh api prints its error body on stdout, so an unchecked read captured a JSON blob as the value and drove the wrong branch; all four reads now take their value only from a call whose exit status was checked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Bill Traynor <wmat@riscv.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three items on the Repository Setup Checklist are repository settings, not files:
v*tag rule on thegithub-pagesenvironmentNone of them is visible to a pull request, so the checklist prose is the only thing enforcing them — and a skipped item does not fail loudly, it fails months later at an awkward moment. Both of the last two were added to the checklist reactively: the tag rule after a release deploy failed on
riscv-performance-event-sampling(#165), and the Dependabot switch after a spec repository had accrued eleven open advisories withautomated-security-fixesdisabled and nothing opening a PR for any of them (#169).This repository is itself missing the tag rule, which is a fair indication of how well prose enforces settings:
What it does
.github/workflows/repo-setup.yml,workflow_dispatchonly, with a checkbox per setting (all default on). It authenticates asGHTOKENbecauseGITHUB_TOKENis refused for all three — creating a Pages site, changing environment settings and toggling Dependabot are admin-level operations the Actions app cannot perform.Design choices worth reviewing:
workflowscopetemplate-sync.ymlneeds. When a call is refused, that step recordsFAILwith the manual instruction and the job carries on — applying two of three beats stopping at the first refusal — then exits non-zero at the end.workflowrather than letting it default to Deploy from a branch, which is what queues the straypages-build-deploymentrun that can overwrite the site afterwards.github-pagesbut not always before the next step runs. If it still is not there, it says to re-run rather than reporting a failure.protected_branchescase by reporting it instead of silently changing the environment's policy model.Plumbing
Added to
template-sync.yml's copy list andUPGRADING.md's template-owned list, so migrated repositories receive it — the gap #167 closed fortemplate-sync.ymlitself.README.adocoffers it as the fast path for checklist steps 3–5 while keeping the manual instructions as the fallback, andMIGRATION.mdStep 16 points at it where a migrator is already standing in Actions.Verification
I extracted the script and ran it against two real repositories with a
ghshim that passes reads through and stubs writes:Two different states, correct verdict on each — including correctly identifying this repository's missing rule.
That dry run also caught a real defect before it shipped:
gh apiprints its error body on stdout, so an uncheckedcurrent="$(gh api … 2>/dev/null)"captured a JSON blob as the value and drove the wrong branch — a 404 on/pageswas reported as "Pages source changed from{ "message": "Bad credentials" … }". All four reads now take their value only from a call whose exit status was checked. Worth knowing for any other workflow in this repository that reads throughgh api.The
POST /pagescreation path is the one branch no repository I have admin on could exercise, since all of them already have Pages; it is structurally the same as thePUTpath next to it.check-yamlandyamlfmtpass on both workflows.🤖 Generated with Claude Code