Publish curated ForgeFlow source from 2ed1787c0b52
This commit is contained in:
commit
f60b269686
254 files changed
+46204
No files matched your search
@@ -0,0 +1,51 @@
|
||||
name: ForgeFlow deployment
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
environment:
|
||||
description: Fixed ForgeFlow deployment environment
|
||||
required: true
|
||||
default: production
|
||||
commit_sha:
|
||||
description: Exact commit verified by ForgeFlow
|
||||
required: true
|
||||
request_id:
|
||||
description: ForgeFlow correlation identifier
|
||||
required: true
|
||||
|
||||
concurrency:
|
||||
group: forgeflow-${{ gitea.repository }}-${{ inputs.environment }}
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
# Register a trusted runner with this label, or replace it with your own.
|
||||
runs-on: forgeflow-production
|
||||
steps:
|
||||
- name: Validate dispatch inputs
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
[[ "${{ inputs.environment }}" =~ ^[a-z0-9][a-z0-9._-]{0,63}$ ]] || {
|
||||
echo "Invalid environment identifier" >&2
|
||||
exit 64
|
||||
}
|
||||
[[ "${{ inputs.commit_sha }}" =~ ^[0-9a-fA-F]{40,64}$ ]] || {
|
||||
echo "Invalid commit SHA" >&2
|
||||
exit 64
|
||||
}
|
||||
[[ "${{ inputs.request_id }}" =~ ^[A-Za-z0-9._:-]{1,100}$ ]] || {
|
||||
echo "Invalid request identifier" >&2
|
||||
exit 64
|
||||
}
|
||||
|
||||
- name: Deploy exact allowlisted version
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
sudo /usr/local/bin/forgeflow-deploy \
|
||||
"${{ gitea.repository }}" \
|
||||
"${{ inputs.environment }}" \
|
||||
"${{ inputs.commit_sha }}" \
|
||||
"${{ inputs.request_id }}"
|
||||
@@ -0,0 +1,90 @@
|
||||
name: ForgeFlow approved deploy
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
repository:
|
||||
description: Signed allowlisted deployment target (owner/repository)
|
||||
required: true
|
||||
type: string
|
||||
environment:
|
||||
description: Allowlisted ForgeFlow environment
|
||||
required: true
|
||||
type: string
|
||||
commit_sha:
|
||||
description: Exact approved commit SHA
|
||||
required: true
|
||||
type: string
|
||||
request_id:
|
||||
description: Immutable AppOps request identifier
|
||||
required: true
|
||||
type: string
|
||||
approval_id:
|
||||
description: AppOps approval identifier
|
||||
required: true
|
||||
type: string
|
||||
approval_fingerprint:
|
||||
description: Immutable AppOps approval fingerprint
|
||||
required: true
|
||||
type: string
|
||||
evidence_issued_at:
|
||||
description: Signed evidence UNIX timestamp
|
||||
required: true
|
||||
type: string
|
||||
evidence_signature:
|
||||
description: Base64 Ed25519 signature over the exact deployment evidence
|
||||
required: true
|
||||
type: string
|
||||
|
||||
concurrency:
|
||||
group: forgeflow-approved-${{ inputs.repository }}-${{ inputs.environment }}
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: forgeflow
|
||||
steps:
|
||||
- name: Validate signed deployment inputs
|
||||
shell: bash
|
||||
env:
|
||||
FF_REPOSITORY: ${{ inputs.repository }}
|
||||
FF_ENVIRONMENT: ${{ inputs.environment }}
|
||||
FF_COMMIT_SHA: ${{ inputs.commit_sha }}
|
||||
FF_REQUEST_ID: ${{ inputs.request_id }}
|
||||
FF_APPROVAL_ID: ${{ inputs.approval_id }}
|
||||
FF_APPROVAL_FINGERPRINT: ${{ inputs.approval_fingerprint }}
|
||||
FF_EVIDENCE_ISSUED_AT: ${{ inputs.evidence_issued_at }}
|
||||
FF_EVIDENCE_SIGNATURE: ${{ inputs.evidence_signature }}
|
||||
run: |
|
||||
set -Eeuo pipefail
|
||||
[[ "$FF_REPOSITORY" =~ ^[A-Za-z0-9._-]+/[A-Za-z0-9._-]+$ ]]
|
||||
[[ "$FF_ENVIRONMENT" =~ ^[a-z0-9][a-z0-9._-]{0,63}$ ]]
|
||||
[[ "$FF_COMMIT_SHA" =~ ^[0-9a-fA-F]{40,64}$ ]]
|
||||
[[ "$FF_REQUEST_ID" =~ ^appr-[A-Za-z0-9._-]{1,75}$ ]]
|
||||
[[ "$FF_APPROVAL_ID" == "$FF_REQUEST_ID" ]]
|
||||
[[ "$FF_APPROVAL_FINGERPRINT" =~ ^[0-9a-f]{64}$ ]]
|
||||
[[ "$FF_EVIDENCE_ISSUED_AT" =~ ^[0-9]{10,11}$ ]]
|
||||
[[ "$FF_EVIDENCE_SIGNATURE" =~ ^[A-Za-z0-9+/]{86}==$ ]]
|
||||
|
||||
- name: Execute root-owned verified deployment
|
||||
shell: bash
|
||||
env:
|
||||
FF_REPOSITORY: ${{ inputs.repository }}
|
||||
FF_ENVIRONMENT: ${{ inputs.environment }}
|
||||
FF_COMMIT_SHA: ${{ inputs.commit_sha }}
|
||||
FF_REQUEST_ID: ${{ inputs.request_id }}
|
||||
FF_APPROVAL_ID: ${{ inputs.approval_id }}
|
||||
FF_APPROVAL_FINGERPRINT: ${{ inputs.approval_fingerprint }}
|
||||
FF_EVIDENCE_ISSUED_AT: ${{ inputs.evidence_issued_at }}
|
||||
FF_EVIDENCE_SIGNATURE: ${{ inputs.evidence_signature }}
|
||||
run: |
|
||||
set -Eeuo pipefail
|
||||
sudo /usr/local/bin/forgeflow-deploy \
|
||||
"$FF_REPOSITORY" \
|
||||
"$FF_ENVIRONMENT" \
|
||||
"$FF_COMMIT_SHA" \
|
||||
"$FF_REQUEST_ID" \
|
||||
"$FF_APPROVAL_ID" \
|
||||
"$FF_APPROVAL_FINGERPRINT" \
|
||||
"$FF_EVIDENCE_ISSUED_AT" \
|
||||
"$FF_EVIDENCE_SIGNATURE"
|
||||
@@ -0,0 +1,50 @@
|
||||
name: ForgeFlow rollback
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
environment:
|
||||
description: Fixed ForgeFlow deployment environment
|
||||
required: true
|
||||
default: production
|
||||
target_sha:
|
||||
description: Exact previously successful commit verified by ForgeFlow
|
||||
required: true
|
||||
request_id:
|
||||
description: ForgeFlow correlation identifier
|
||||
required: true
|
||||
|
||||
concurrency:
|
||||
group: forgeflow-${{ gitea.repository }}-${{ inputs.environment }}
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
rollback:
|
||||
runs-on: forgeflow-production
|
||||
steps:
|
||||
- name: Validate rollback inputs
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
[[ "${{ inputs.environment }}" =~ ^[a-z0-9][a-z0-9._-]{0,63}$ ]] || {
|
||||
echo "Invalid environment identifier" >&2
|
||||
exit 64
|
||||
}
|
||||
[[ "${{ inputs.target_sha }}" =~ ^[0-9a-fA-F]{40,64}$ ]] || {
|
||||
echo "Invalid target SHA" >&2
|
||||
exit 64
|
||||
}
|
||||
[[ "${{ inputs.request_id }}" =~ ^[A-Za-z0-9._:-]{1,100}$ ]] || {
|
||||
echo "Invalid request identifier" >&2
|
||||
exit 64
|
||||
}
|
||||
|
||||
- name: Restore exact allowlisted version
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
sudo /usr/local/bin/forgeflow-deploy \
|
||||
"${{ gitea.repository }}" \
|
||||
"${{ inputs.environment }}" \
|
||||
"${{ inputs.target_sha }}" \
|
||||
"${{ inputs.request_id }}"
|
||||
Reference in new issue
Block a user