build-cran-binaries/.crow/auto-apply-patches.yaml
pat-s 1bca6004fd chore(local): reuse FORGEJO_TOKEN for the auto-patch push (#125)
Follow-up to #124 (merged): the auto-patch pipeline required a separate write-scoped `REPO_RW_TOKEN` to push the branch. Reuse the existing `FORGEJO_TOKEN` instead.

- `propose-patches.R --open-pr` now pushes `auto/registry-patch-proposals` over HTTPS with `FORGEJO_TOKEN` (the same token used for the PR API); the read-only `origin` clone URL can't push, so it builds an authenticated URL explicitly.
- Drop `REPO_RW_TOKEN` from `.crow/auto-apply-patches.yaml` and the docs.

No new secret needed: the pipeline's secrets are now `PGPASS`, `REPO_RO_TOKEN`, and `FORGEJO_TOKEN` (all existing). `FORGEJO_TOKEN` must have repository write scope for the push to succeed.

105 tests pass; all pre-commit hooks pass.

Reviewed-on: #125
2026-07-15 14:50:19 +00:00

64 lines
2.1 KiB
YAML

# Auto-apply registry patches (issue #115, step 3 automation).
# Classifies `single_builds` failures and, for the top-N auto-proposable
# candidates by failure volume, writes the registry entries onto the reused
# `auto/registry-patch-proposals` branch and opens/updates a single PR.
# Nothing merges: the `trial-build-registry` pipeline is the merge gate, and a
# human reviews the PR. Novel source diffs / unknown signatures are never
# proposed. Global across platforms, so a single job -- no matrix.
#
# FORGEJO_TOKEN is used for both the branch push and opening the PR (no separate
# write-scoped secret needed). Register the `auto-apply-patches` cron in the crow
# UI, or run manually:
# woodpecker-cli pipeline create --var task=auto-apply-patches --branch=main 7
variables:
patch_limit:
description: 'Max candidates to propose per run (top by failure volume).'
default: '10'
when:
- event: manual
evaluate: 'task == "auto-apply-patches"'
- event: cron
cron: auto-apply-patches
skip_clone: true
labels:
group: rpkgs-amd64
steps:
- name: 'Auto-apply registry patches'
image: reg.devxy.io/rpkgs/build-env-alpine:3.24
pull: true
environment:
PGPASS:
from_secret: PGPASS
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
FORGEJO_TOKEN:
from_secret: FORGEJO_TOKEN
GIT_USER: devxy-bot
GIT_EMAIL: bot@devxy.io
PATCH_LIMIT: ${patch_limit}
R_VERSION: 4.5.3
R_LIBS_USER: /mnt/cache/R-pkgs
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak(c("httr2", "jsonlite"))'
- /opt/R/$R_VERSION/bin/Rscript local/propose-patches.R --open-pr --limit $PATCH_LIMIT
backend_options:
kubernetes:
resources:
requests:
memory: 1Gi
cpu: 2000m
limits:
memory: 2Gi
cpu: 2000m
tolerations:
- key: 'CI'
operator: 'Equal'
value: 'true'
effect: 'NoSchedule'