diff --git a/.gitea/workflows/README.md b/.gitea/workflows/README.md new file mode 100644 index 0000000..b6d4e71 --- /dev/null +++ b/.gitea/workflows/README.md @@ -0,0 +1,40 @@ +# Gitea Workflows — Limitation Documentation (v1.14, REQ-150) + +## Shared workflows (byte-identical Gitea + GitHub) + +These 3 workflows exist in both `.gitea/workflows/` and `.github/workflows/` +and are byte-identical (asserted by `tests/test_pipeline_contract.py`): + +- `ci.yml` — lint + test + check-only (runs on every PR) +- `deploy.yml` — reusable deploy workflow (invoked by consumer repos) +- `modules-lifecycle.yml` — L1 + L2 module lifecycle pipeline (plan-only + default, full on workflow_dispatch override) + +## GitHub-only workflows (no Gitea mirror) + +These 4 workflows exist only in `.github/workflows/`: + +- `platform-test.yml` — PR pipeline: lint + unit + integration + schema + validation. Uses GitHub Actions features (reusable workflow composition, + environment protection) not available in Gitea Actions. +- `primitives-plan.yml` — PR plan-only matrix over all L1 primitives. Uses + GitHub matrix strategy + `terraform plan` against live AWS. +- `patterns-plan.yml` — PR plan-only matrix over all L2 modules. Same + pattern as primitives-plan. +- `release.yml` — release job on merge to main: computes next semver, + creates + updates MAJOR.MINOR.PATCH / MAJOR.MINOR / MAJOR floating tags, + creates a GitHub release. GitHub-only by design (Gitea releases are + created via the ship workflow's API call, not a workflow). + +## Why no Gitea mirror + +Gitea Actions (act_runner) has limited support for reusable workflow +composition, environment protection, and the `gh` CLI used by the release +job. The 3 shared workflows are the ones that need to run on both forges +(CI + deploy + lifecycle). The 4 GitHub-only workflows are the +production-grade platform pipelines that run on GitHub Actions; Gitea is +the dev/integration forge. Mirroring them would require feature parity +that Gitea Actions does not currently provide. + +This is a documented limitation, not a defect. A future milestone may +add Gitea mirrors if act_runner gains the required features. \ No newline at end of file diff --git a/scripts/rotate_spike_key.sh b/scripts/rotate_spike_key.sh index 6bd9a87..8faf94b 100755 --- a/scripts/rotate_spike_key.sh +++ b/scripts/rotate_spike_key.sh @@ -13,7 +13,7 @@ # # Spike scope (D-039): the spike user key is per-run-rotated; real OIDC is # v1.2 (blocked on go-gitea/gitea#36988). -set -u +set -euo pipefail ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" cd "$ROOT" ENV_FILE="$ROOT/.env.secrets"