Retire retained Forgejo branch and tag sources for Binjovi control #347

Merged
binjovi-bot merged 1 commit from feat/retire-forgejo-policy-sources into trunk 2026-09-06 13:40:52 +00:00
Owner

Remove 86 retained branch/tag protection declarations from the Binjovi Flux component. Binjovi core PR831 provides their exact approved bindings, initial PostgreSQL desired state, ownership guards and direct Forgejo authority reads. The plan-source webhook, repositories, mirrors, credentials and project execution settings remain present.

The source contract now rejects any rendered Forgejo branch/tag writer in this component. Existing credential, mirror and execution tests remain; policy-value validation lives with the Binjovi provider defaults. Focused red/green retirement check, full Binjovi source check, all affected project checks, component rendering and diff checks pass.

Release only after the exact PR831 core is verified in staging and production. Flux uses prune:false, so live objects are then retired with captured UID/resource-version preconditions after Retain and remote baseline checks. The separate six Pipelines-generated policies remain coordinated with the project migration owners.

Exact candidate: c584812d53

Core831/v355 is deployed in staging and production, each with 15 checks and zero failures. All92 provider baselines match. The first admission failed the expected ancestry check after Seanfarm345 landed concurrently; rebased10771d18 admission passed at exactc584812d. No source or remote effect occurred from the stale attempt.

Remove 86 retained branch/tag protection declarations from the Binjovi Flux component. Binjovi core PR831 provides their exact approved bindings, initial PostgreSQL desired state, ownership guards and direct Forgejo authority reads. The plan-source webhook, repositories, mirrors, credentials and project execution settings remain present. The source contract now rejects any rendered Forgejo branch/tag writer in this component. Existing credential, mirror and execution tests remain; policy-value validation lives with the Binjovi provider defaults. Focused red/green retirement check, full Binjovi source check, all affected project checks, component rendering and diff checks pass. Release only after the exact PR831 core is verified in staging and production. Flux uses prune:false, so live objects are then retired with captured UID/resource-version preconditions after Retain and remote baseline checks. The separate six Pipelines-generated policies remain coordinated with the project migration owners. Exact candidate: c584812d53740a66637a531fd73562589c98e370 Core831/v355 is deployed in staging and production, each with 15 checks and zero failures. All92 provider baselines match. The first admission failed the expected ancestry check after Seanfarm345 landed concurrently; rebased10771d18 admission passed at exactc584812d. No source or remote effect occurred from the stale attempt.
feat: retire retained Forgejo policy sources for Binjovi control
Some checks failed
binjovi/ci Binjovi failed the frozen plan
de8ffed99f
sean force-pushed feat/retire-forgejo-policy-sources from de8ffed99f
Some checks failed
binjovi/ci Binjovi failed the frozen plan
to c584812d53
All checks were successful
binjovi/ci Binjovi completed the frozen plan
2026-09-06 13:39:23 +00:00
Compare
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
sean/seanfarm!347
No description provided.