diff --git a/.github/workflows/promote-stable.yml b/.github/workflows/promote-stable.yml new file mode 100644 index 0000000..d99d4ba --- /dev/null +++ b/.github/workflows/promote-stable.yml @@ -0,0 +1,53 @@ +name: Promote to stable + +# Udrulningsknappen: fast-forwarder stable-kanalen til main med eet klik +# (Actions -> Promote to stable -> Run workflow). Manuel og bevidst - +# merge til main er IKKE deploy; dette workflow ER deployet. +# +# Sikkerhed: kun brugere med write-adgang kan dispatche. Nægter at køre, +# hvis stable er divergeret fra main (aldrig force). Hvis stable-branchen +# beskyttes af et ruleset, skal GitHub Actions (eller dette workflow) på +# rulesettets bypass-liste, for at push'et kan gennemføres. + +on: + workflow_dispatch: + +permissions: + contents: write + +jobs: + promote: + runs-on: ubuntu-latest + steps: + - name: Check out repository + uses: actions/checkout@v4 + with: + fetch-depth: 0 + ref: main + + - name: Fast-forward stable to main + run: | + git fetch origin stable + + if ! git merge-base --is-ancestor origin/stable origin/main; then + echo "::error::stable er ikke en forfader til main - kanalen er divergeret. Promotion afbrudt; undersøg manuelt (aldrig force)." + exit 1 + fi + + OLD=$(git rev-parse origin/stable) + NEW=$(git rev-parse origin/main) + + if [ "$OLD" = "$NEW" ]; then + echo "## Intet at promovere" >> "$GITHUB_STEP_SUMMARY" + echo "stable står allerede på main ($(git rev-parse --short "$NEW"))." >> "$GITHUB_STEP_SUMMARY" + exit 0 + fi + + { + echo "## Promoveret: $(git rev-parse --short "$OLD") → $(git rev-parse --short "$NEW")" + echo "" + echo "Commits udrullet til alle maskiner:" + git log --format='- `%h` %s' "$OLD".."$NEW" + } >> "$GITHUB_STEP_SUMMARY" + + git push origin origin/main:stable diff --git a/CONSUMPTION.md b/CONSUMPTION.md index 9fe2e89..d4db2a6 100644 --- a/CONSUMPTION.md +++ b/CONSUMPTION.md @@ -68,7 +68,22 @@ fetch URLs, and the agent templates' knowledge references — read from the **`stable`** branch, never from `main`. `main` is where PRs land and CI runs; `stable` is what every developer machine actually executes. -Deploying is a deliberate act (Michael only): +Deploying is a deliberate act (Michael only). Three equivalent ways, safest +first: + +**The button (works from any device):** GitHub → Actions → *Promote to +stable* → Run workflow. Refuses to run if the channel has diverged; writes a +summary of the promoted commits. + +**The one-liner (from any up-to-date clone, touches no working tree):** + + git fetch origin + git push origin origin/main:stable + +Git itself refuses a non-fast-forward push — if it is rejected, someone has +committed directly to stable: that is a finding, never a reason to force. + +**The explicit form (for understanding what a promote IS):** git checkout stable git merge --ff-only main