Skip to content

feat(repo): preview every pull request and deploy production after the release gate - #51

Merged
kiro-systemf[bot] merged 150 commits into
mainfrom
lake1/previews
Oct 7, 2026
Merged

kiro-systemf[bot] merged 150 commits into
mainfrom
lake1/previews

Conversation

@systemfsoftware-maker

@systemfsoftware-maker systemfsoftware-maker commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Lake 1, U13, stacked on #50. Trimmed per Kiro's 2026-10-06 ruling: previews and a plain production deploy stay, guarded by is_template; no Workers Issues automation, no version check or rollback, no Alchemy patch.

  • .github/workflows/previews.yml: a same-repo pull request in an adopter's copy deploys as its pr-<N> stage, gets its URL in one PR comment (edited on every push), and is destroyed when the PR closes. Fork PRs and the template itself get none.
  • .github/workflows/release-gate.yml gains deploy · production: on main, once the plan passed and the mutation job passed (every shard at break 100) or was skipped (no decisions to mutate, ci(ci): move mutation to a release gate on main #35), pnpm run deploy (to vars.SITE_DOMAIN when that repository variable is set). A failed plan, a failed shard or a cancelled run never deploys.
  • .github/actions/cloudflare-secrets fails both jobs early, naming any missing secret.
  • Cloudflare credentials enter a sandbox only through bin/cloud (deploy, destroy, state reads). AGENTS.md states that boundary as a rule.

Alchemy patch: dropped. Deploy does not need it; its two hunks served only the CloudflareTracer subpath (traces, #45) and the Workers Issues reconcile (trimmed here).

Gate at bcd99ef, before the restack onto #35's no-decisions rule (the deployed-journeys lines it carried are gone with F11)

$ pnpm check:ci
checkci=1        # only check:sfs-sources, inherited from #52
$ pnpm journeys
journeys=0

Not exercised here: a preview or production run, which needs an adopter's copy and its secrets.

Restack, 2026-10-06

Rebased onto #35's no-decisions rule. The deploy job's condition (needs: [plan, mutation], !cancelled() && plan == success && mutation in {success, skipped} && !is_template) is the only change in this layer's tree; actionlint passes on it.

Cycle 35 (Kiro rulings on starter-verify's review)

  • F11 (93b958c): the deployed-site journeys are not in the spec, so they come out: bin/journeys-deployed, the journeys:deployed script, the journeys and artifact-upload steps in previews.yml and release-gate.yml (the uploads carried only what those journeys wrote), the README line, and the AGENTS.md clause, whose rule keeps a grounded wrong/right pair. Deploy, the preview comment and destroy are unchanged; the preview job is named preview · deploy. No reference to journeys:deployed or journeys-deployed remains on this branch.

Gate after the cycle 52 restack (Linux only)

Gate at c7b0037, clean worktree, Linux, sandboxed:

$ pnpm bootstrap                    # exit 0
$ pnpm check:ci                     # exit 1, only check:sfs-sources:
check-sfs-sources: 2 @systemfsoftware/* package(s) resolve from the npm registry, not the systemfsoftware flake
 Tasks:    8 successful, 8 total   # lint, typecheck, test, build
 Tasks:    1 successful, 1 total   # dist
ok | 1 passed (9 steps) | 0 failed  # sandbox proofs
$ pnpm journeys                     # exit 0
Tests  1 passed (1)

CI run 37573586754 on c7b0037: 6 of 7 jobs pass (format, lint, typecheck, test, dist, journeys); check (sfs-sources) fails, the same red as the local gate above.

Gate after cycle 83 (every @systemfsoftware/* package from our flakes, #52)

Gate at 2a15ef0, clean worktree, Linux, sandboxed:

$ pnpm bootstrap                    # exit 0
$ pnpm check:ci                     # exit 0
check-sfs-sources: all 16 @systemfsoftware/* packages resolve from the systemfsoftware flake
 Tasks:    8/8 successful, 8/8 total   # lint, typecheck, test, build
 Tasks:    1 successful, 1 total   # dist
ok | 1 passed (9 steps) | 0 failed  # sandbox proofs
$ pnpm journeys                     # exit 0
Tests  1 passed (1)

CI run 37675953316 on 2a15ef0: all 7 jobs pass, check (sfs-sources) included. The exit 1 gates above are from before the stryker packages came from the stryker-js-effect flake.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/previews branch 2 times, most recently from df94d42 to f1c3dca Compare October 6, 2026 07:09
@systemfsoftware-maker
systemfsoftware-maker force-pushed the lake1/previews branch 2 times, most recently from 2adfaea to c62be46 Compare October 6, 2026 07:16
systemfsoftware-maker added a commit that referenced this pull request Oct 6, 2026
…and QA evidence

Findings for #43, #45, #49, #50 and #51 from ce-code-review (8 lenses, validator), the verifier's probes of every P0/P1 including those the merge dropped, and the real-browser, local-Tempo and live-preview QA. Nothing applied; each finding waits for a ruling
@systemfsoftware-maker
systemfsoftware-maker removed this pull request from stack #34 October 6, 2026 16:04
…anagement input

Conductor ruling, cycle 71: since pnpm-release-management#11 (aa712d9), devshell: true runs nix develop --command sandbox -- changeset-management check with the release-tools in the caller's dev shell. The pinned input (5eb4c5d, followed from systemfsoftware main) already exports packages.<system>.release-tools, so the lock does not move
Conductor rulings, cycles 74 and 77: pnpm-release-management main 537d17c carries #14, #20 (the consumer store) and #24 (the linked-worktree change), so the starter's own copy of that change (nix/patches/sandbox-linked-worktree-git.patch) and its applyPatches wiring go. pnpm-release-management becomes a direct input on main, locked to 537d17c; systemfsoftware follows it, and its nixpkgs, comment-checker and importPnpmLock follow the starter's
starter-verify c73: withoutSandboxOnPath removed only the first directory that held sandbox, so with two launchers on PATH the hooks still found one and the refusal step failed falsely. It now drops every PATH entry that provides sandbox. Two launchers on PATH: the old helper fails the step, the new one passes; with the hooks' sandbox prefix stripped, the step fails
Conductor ruling, cycle 83: stryker-js-effect main f06f244 (#196) publishes its 17 members as tarballs with an index.json. The flake adds it as an input (locked to f06f244, following the starter's nixpkgs, comment-checker, importPnpmLock, pnpm-release-management and systemfsoftware), and .sfs-deps now holds both flakes' tarballs with one merged index.json. Every @systemfsoftware/stryker-* member is a file:.sfs-deps catalog entry with an override, the same mechanism as the systemfsoftware packages, plus one for the stryker-js-vm-runner npm alias that stryker-js 17.0.2 declares, so check:sfs-sources passes with no npm-sourced @systemfsoftware/* package
7857171 (lake1/nix-sandbox merged into lake1/deploy) was pushed to lake1/nix-sandbox by mistake during the cycle 83 merge-up. This restores the layer's tree to fb4f8a1 exactly; lake1/deploy reverts this revert so it keeps its own content
-s ours: the only change on lake1/nix-sandbox since 7857171 is the revert of 7857171 itself, which this layer must not take
@kiro-systemf
kiro-systemf Bot changed the base branch from lake1/deploy to main October 7, 2026 20:37

@kiro-systemf kiro-systemf Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: all checks green on da833eb, 0 threads, hunt clean.

@kiro-systemf
kiro-systemf Bot merged commit 90e9378 into main Oct 7, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant