feat: [12] Branch-Protection per Pipeline reconcilen #51

Merged
hobbypunk merged 1 commit from enhancement/12_branch_protection into main 2026-09-27 15:37:56 +00:00
Owner

Folge-PR aus #12 – baut auf dem gemergten PR #50 (Labeler + Conventional-Title) auf.

Idee: Protection als Code

Statt Branch-Protection manuell pro Repo zu setzen (kein natives Forgejo-Default für neue Repos existiert), reconciled ein Pipeline-Job die Regel bei jedem Push auf main:

  • .github/actions/branch-protection/ – Composite Action (node, plain fetch): GET der Rule → bei 404 POST (anlegen), bei Abweichung PATCH (korrigieren), bei Sync no-op
  • .github/workflows/branch-protection.yml – feuert bei Push auf main + manuell per workflow_dispatch
  • Desired State steht als Inputs im Workflow (aktuell: CI / * (pull_request) als Required Check, Push erlaubt, 0 Approvals)

Warum Reconcile statt Change-Detection

Idempotent, billig (~20s) und self-healing: UI-Änderungen an der Rule werden beim nächsten main-Push auf den Sollzustand zurückgesetzt. Die Workflow-Inputs sind ab jetzt die Source of Truth.

Default für neue Repos

Der Workflow reist mit der Base-App: Jedes neue Projekt setzt seine Protection automatisch beim ersten Push auf main – ohne Token-Gedöns, ohne manuellen Schritt.

⚠️ Verhalten ab Merge

Was auch immer ab jetzt jemand (auch manuell in der UI) an der Protection-Regel ändert: Der nächste main-Push stellt den Workflow-Zustand wieder her. Anpassungen bitte künftig im Workflow machen.

Offene Frage

Ob der ephemeral secrets.GITHUB_TOKEN die Admin-API für Branch-Protection darf, zeigt der erste Run – falls 403, schalten wir auf einen PAT-Secret um.

**Folge-PR aus #12** – baut auf dem gemergten PR #50 (Labeler + Conventional-Title) auf. ## Idee: Protection als Code Statt Branch-Protection manuell pro Repo zu setzen (kein natives Forgejo-Default für neue Repos existiert), reconciled ein Pipeline-Job die Regel bei jedem Push auf main: - `.github/actions/branch-protection/` – Composite Action (node, plain fetch): GET der Rule → bei 404 POST (anlegen), bei Abweichung PATCH (korrigieren), bei Sync no-op - `.github/workflows/branch-protection.yml` – feuert bei Push auf main + manuell per workflow_dispatch - Desired State steht als Inputs im Workflow (aktuell: `CI / * (pull_request)` als Required Check, Push erlaubt, 0 Approvals) ## Warum Reconcile statt Change-Detection Idempotent, billig (~20s) und **self-healing**: UI-Änderungen an der Rule werden beim nächsten main-Push auf den Sollzustand zurückgesetzt. Die Workflow-Inputs sind ab jetzt die Source of Truth. ## Default für neue Repos Der Workflow reist mit der Base-App: Jedes neue Projekt setzt seine Protection **automatisch beim ersten Push auf main** – ohne Token-Gedöns, ohne manuellen Schritt. ## ⚠️ Verhalten ab Merge Was auch immer ab jetzt jemand (auch manuell in der UI) an der Protection-Regel ändert: Der nächste main-Push stellt den Workflow-Zustand wieder her. Anpassungen bitte künftig im Workflow machen. ## Offene Frage Ob der ephemeral `secrets.GITHUB_TOKEN` die Admin-API für Branch-Protection darf, zeigt der erste Run – falls 403, schalten wir auf einen PAT-Secret um.
[12] Branch-Protection per Pipeline reconcilen (GitOps)
All checks were successful
PR Triage / triage (pull_request) Successful in 2m39s
CI / scan_ruby (pull_request) Successful in 1m15s
CI / lint (pull_request) Successful in 1m40s
CI / test (pull_request) Successful in 4m6s
CI / system-test (pull_request) Successful in 6m6s
CI / coverage (pull_request) Successful in 5m37s
1f228fcf9b
---------

Co-Authored-By: opencode (Mistral GLM) <opencode-agent[bot]@hoppe-dev.eu>
forgejo-actions changed title from [12] Branch-Protection per Pipeline reconcilen (GitOps) to feat: [12] Branch-Protection per Pipeline reconcilen (GitOps) 2026-09-27 15:19:08 +00:00
hobbypunk scheduled this pull request to auto merge when all checks succeed 2026-09-27 15:21:51 +00:00
hobbypunk changed title from feat: [12] Branch-Protection per Pipeline reconcilen (GitOps) to feat: [12] Branch-Protection per Pipeline reconcilen 2026-09-27 15:23:24 +00:00

📊 Coverage

Metrik Abdeckung
Zeilen 97.69% (2619/2681)
Branches 81.46% (637/782)
Methoden 96.95% (413/426)

Patch-Coverage: keine getrackten Zeilen geändert

Schwächste Dateien im Projekt

Datei Abdeckung
app/models/concerns/has_uuid_v7.rb 54.55%
app/components/form/select.rb 72.41%
app/components/layout/flash.rb 84.0%
app/components/concerns/actionable.rb 86.67%
app/components/layout/sidebar.rb 89.47%
app/controllers/settings/security_controller.rb 90.24%
app/controllers/sessions_controller.rb 90.32%
app/components/concerns/inferrable.rb 90.63%
app/components/users/avatar.rb 91.23%
app/controllers/settings/security/otps_controller.rb 91.67%

🔍 Report im Browser ansehen · 📄 Run-Artifact „coverage-report“

<!-- coverage-report --> ## 📊 Coverage | Metrik | Abdeckung | |---|---| | Zeilen | 97.69% (2619/2681) | | Branches | 81.46% (637/782) | | Methoden | 96.95% (413/426) | **Patch-Coverage**: keine getrackten Zeilen geändert **Schwächste Dateien im Projekt** | Datei | Abdeckung | |---|---| | app/models/concerns/has_uuid_v7.rb | 54.55% | | app/components/form/select.rb | 72.41% | | app/components/layout/flash.rb | 84.0% | | app/components/concerns/actionable.rb | 86.67% | | app/components/layout/sidebar.rb | 89.47% | | app/controllers/settings/security_controller.rb | 90.24% | | app/controllers/sessions_controller.rb | 90.32% | | app/components/concerns/inferrable.rb | 90.63% | | app/components/users/avatar.rb | 91.23% | | app/controllers/settings/security/otps_controller.rb | 91.67% | [🔍 Report im Browser ansehen](https://pages.hoppe-dev.eu/hobbypunk/rails-base_app/pr-51/coverage) · [📄 Run-Artifact „coverage-report“](https://code.hoppe-dev.eu/hobbypunk/rails-base_app/actions/runs/1540/artifacts/coverage-report)
hobbypunk deleted branch enhancement/12_branch_protection 2026-09-27 15:37:57 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
hobbypunk/rails-base_app!51
No description provided.