Sync from Intelligence Flow #3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Generated from operatorstack/intelligence-flow. | |
| name: Sync from Intelligence Flow | |
| on: | |
| schedule: | |
| - cron: "17 */6 * * *" | |
| workflow_dispatch: | |
| inputs: | |
| source_commit: | |
| description: Exact Intelligence Flow commit to project (defaults to main) | |
| required: false | |
| type: string | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| concurrency: | |
| group: sync-intelligence-flow | |
| cancel-in-progress: false | |
| jobs: | |
| sync: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Create repository automation token | |
| id: app-token | |
| uses: actions/create-github-app-token@v3 | |
| with: | |
| client-id: ${{ vars.OPERATOR_STACK_PUBLISHER_APP_CLIENT_ID || vars.BOATSTACK_APP_CLIENT_ID }} | |
| private-key: ${{ secrets.OPERATOR_STACK_PUBLISHER_APP_PRIVATE_KEY || secrets.BOATSTACK_APP_PRIVATE_KEY }} | |
| owner: operatorstack | |
| repositories: pitot | |
| permission-contents: write | |
| permission-pull-requests: write | |
| - name: Check out Pitot | |
| uses: actions/checkout@v4 | |
| with: | |
| path: pitot-repo | |
| token: ${{ steps.app-token.outputs.token }} | |
| - name: Check out Intelligence Flow | |
| uses: actions/checkout@v4 | |
| with: | |
| repository: operatorstack/intelligence-flow | |
| ref: ${{ inputs.source_commit || 'main' }} | |
| fetch-depth: 0 | |
| path: intelligence-flow | |
| - name: Generate projection | |
| id: generate | |
| shell: bash | |
| run: | | |
| source_commit="$(git -C intelligence-flow log -1 --format=%H -- labs/15-pitot)" | |
| current_commit="$(jq -r '.source.commit // empty' pitot-repo/UPSTREAM.json 2>/dev/null || echo '')" | |
| if [[ -n "$current_commit" ]] && | |
| ! git -C intelligence-flow merge-base --is-ancestor "$current_commit" "$source_commit"; then | |
| echo "Ignoring stale projection request $source_commit" | |
| echo "stale=true" >> "$GITHUB_OUTPUT" | |
| exit 0 | |
| fi | |
| # Perform the byte level sync for pitot | |
| rsync -av --delete --exclude='.git' intelligence-flow/labs/15-pitot/pitot/ pitot-repo/ | |
| # The preview files | |
| cp intelligence-flow/labs/15-pitot/public-readme-preview/README.md pitot-repo/ | |
| cp intelligence-flow/labs/15-pitot/public-readme-preview/CONTRIBUTING.md pitot-repo/ | |
| rsync -av --delete intelligence-flow/labs/15-pitot/public-readme-preview/assets/ pitot-repo/assets/ | |
| # The distribution package files | |
| if [[ -f intelligence-flow/labs/15-pitot/pitot-distribution/package.json ]]; then | |
| cp intelligence-flow/labs/15-pitot/pitot-distribution/package.json pitot-repo/ | |
| cp intelligence-flow/labs/15-pitot/pitot-distribution/tsconfig.json pitot-repo/ | |
| mkdir -p pitot-repo/types | |
| rsync -av --delete intelligence-flow/labs/15-pitot/pitot-distribution/types/ pitot-repo/types/ | |
| fi | |
| # Copy UPSTREAM.json | |
| cp intelligence-flow/labs/15-pitot/pitot-distribution/UPSTREAM.json pitot-repo/ | |
| echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT" | |
| echo "stale=false" >> "$GITHUB_OUTPUT" | |
| - name: Open generated pull request | |
| if: steps.generate.outputs.stale != 'true' | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| SOURCE_COMMIT: ${{ steps.generate.outputs.source_commit }} | |
| shell: bash | |
| run: | | |
| cd pitot-repo | |
| if [[ -z "$(git status --porcelain)" ]]; then | |
| echo "Pitot already matches Intelligence Flow." | |
| exit 0 | |
| fi | |
| git add -A | |
| body_file="$(mktemp)" | |
| { | |
| echo "## Projection provenance" | |
| echo | |
| echo "Generated from \`operatorstack/intelligence-flow@$SOURCE_COMMIT\`." | |
| echo "Review provenance before merging." | |
| } > "$body_file" | |
| short="${SOURCE_COMMIT:0:12}" | |
| branch="sync/intelligence-flow-$short" | |
| existing="$(gh pr list --head "$branch" --state open --json url --jq '.[0].url')" | |
| git config user.name "${{ steps.app-token.outputs.app-slug }}[bot]" | |
| git config user.email "${{ steps.app-token.outputs.app-slug }}[bot]@users.noreply.github.com" | |
| git switch -c "$branch" | |
| git commit -m "Sync Pitot from Intelligence Flow Labs @ $short" | |
| git push --set-upstream origin "$branch" | |
| if [[ -z "$existing" ]]; then | |
| pr_url="$(gh pr create --base main --head "$branch" --title "Sync Pitot from Intelligence Flow Labs @ $short" --body-file "$body_file")" | |
| echo "Opened generated PR: $pr_url" | |
| else | |
| pr_url="$existing" | |
| echo "Updated existing PR: $pr_url" | |
| fi | |
| # AUTO-MERGE the PR | |
| gh pr merge --auto --merge "$pr_url" || echo "Auto-merge failed (perhaps branch protection or settings don't allow it yet)" |