fix(ci): make every manual gate default to a value that matches nothing

A manual pipeline creation instantiates every file in .crow/, and a declared
variable default is applied even when the run never passed that variable. So a
gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on
any manual run of any pipeline. Triggering a weekly-audit-missing run for one
slot started build-all-versions (including its Upload package indexes step) and
process-updates across every row.

#155 fixed the three pipelines that had no gate at all; these six had a gate
whose default was permissive, which left them just as exposed.

- add a 'none' option to each gate variable and default to it, so a manual run
  must name its target explicitly
- record why the default must match nothing, next to the default itself

Cron triggers are unaffected: they match on the cron name, not the variable.
This commit is contained in:
Patrick Schratz 2026-08-09 15:29:31 +00:00
commit 4edd5b43ee
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC

View file

@ -19,12 +19,16 @@
# --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \
# --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
repair_built_stamp:
description: 'Architecture of the slot to repair. Also gates this pipeline.'
description: 'Architecture of the slot to repair, or "none" to run nothing.'
options:
- none
- amd64
- arm64
default: arm64
default: none
OS:
description: 'Base OS image name.'
options: