docs(adr): main protected at the forge, admins included (#11) #20
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!20
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/11-protect-main"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #11.
Makes "nothing goes directly to main" a fact rather than a sentence, and records the decision.
What changes
docs/adr/0002-main-protected-at-the-forge.md— the decision, in the shape of ADR 0001: What was decided (direct pushes rejected for everyone, the Operator included; zero required approvals; status checks off for now; signed commits not required), Why (agent safety — a non-human pusher cannot land onmainunreviewed — and the door it opens for required workflows later), Consequences, and Update when.docs/adr/index.md— lists 0002.docs/wiki-pages.yml— publishes the new ADR (the manifest is allowlist by default, so a new doc must be listed).Documentation-scoped, as the ticket asks: no tofu or role change.
The live step (evidence)
The protection is applied to the live repo through the API and read back. This is a manual step at merge time, not part of the diff. Read-back:
A direct push to
mainis observed rejected for the Operator (who is the repo admin):Pull-request merges keep working with zero approvals: the rule sets
required_approvals: 0, so the sole Operator is not locked out. Merging this PR is the exercise of that criterion.Out of scope
forgejorole — a separate follow-up, per the ticket.e9e8de11d9toebe6bc0af9@ -21,6 +21,7 @@ publish:- docs/runbooks/0001-deploy-and-rollback.md- docs/adr/index.md- docs/adr/0001-forgejo-actions-runner-on-guest.md- docs/adr/0002-main-protected-at-the-forge.mdDone —
docs/adr/*replaces the three individual ADR entries, so a new decision no longer edits the manifest. The header comment now says entries may be globs (a whole section published the same way, withexcludefor a specific one).Note for the sync in #2: the manifest now carries globs, so the sync has to expand them rather than treat entries as exact paths. Left as-is rather than a second mechanism (e.g. a
publish_dirslist) — the exclusion case you mention works unchanged underexclude: list the specific ADR path there and it wins.@ -21,6 +21,7 @@ publish:- docs/runbooks/0001-deploy-and-rollback.md- docs/adr/index.md- docs/adr/0001-forgejo-actions-runner-on-guest.md- docs/adr/0002-main-protected-at-the-forge.mdChange for docs/adr/* if possible, we can exclude specific adrs later if needed and that way we don't need to modify wiki-pages each time