Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 1 | import type { User, Viewer } from "./identity"; |
| 2 | import type { RepoPath } from "./repos"; | |
| 3 | import type { Result } from "./result"; | |
| 4 | ||
| 5 | /** | |
| 6 | * GitHub Actions workflows, run on g1t as they are. Mirrors | |
| 7 | * `crates/contracts/src/actions.rs`. | |
| 8 | */ | |
| 9 | ||
| 10 | export type WorkflowNote = { | |
| 11 | severity: "info" | "warning" | "unsupported"; | |
| 12 | job: string | null; | |
| 13 | message: string; | |
| 14 | }; | |
| 15 | ||
| 16 | /** One `workflow_dispatch` input, as written in the workflow. */ | |
| 17 | export type DispatchInput = { | |
| 18 | description?: string; | |
| 19 | required?: boolean; | |
| 20 | default?: string | number | boolean; | |
| 21 | type?: "string" | "boolean" | "number" | "choice" | "environment"; | |
| 22 | options?: string[]; | |
| 23 | }; | |
| 24 | ||
| Actions: keep workflow runs safe | 25 | /** |
| 26 | * `action_required`: a pull request's run from outside, waiting for someone | |
| 27 | * with the Write role to approve it. `waiting`: its jobs are held by an | |
| 28 | * environment's protection rules (a run's detail says so; lists do not). | |
| 29 | */ | |
| 30 | export type RunStatus = "pending" | "action_required" | "queued" | "in_progress" | "waiting" | "completed"; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 31 | export type Conclusion = "success" | "failure" | "cancelled" | "skipped"; |
| 32 | ||
| 33 | export type WorkflowRun = { | |
| 34 | id: string; | |
| 35 | workflowId: string; | |
| 36 | path: string; | |
| 37 | name: string; | |
| 38 | title: string; | |
| 39 | number: number; | |
| 40 | attempt: number; | |
| 41 | event: string; | |
| 42 | ref: string; | |
| 43 | sha: string; | |
| 44 | pull: number | null; | |
| 45 | status: RunStatus; | |
| 46 | conclusion: Conclusion | null; | |
| 47 | error: string | null; | |
| 48 | actor: string | null; | |
| 49 | createdAt: string; | |
| 50 | startedAt: string | null; | |
| 51 | finishedAt: string | null; | |
| 52 | }; | |
| 53 | ||
| 54 | export type Workflow = { | |
| 55 | id: string; | |
| 56 | path: string; | |
| 57 | name: string; | |
| 58 | events: string[]; | |
| 59 | state: "active" | "disabled"; | |
| 60 | error: string | null; | |
| 61 | notes: WorkflowNote[]; | |
| 62 | dispatch: Record<string, DispatchInput> | null; | |
| 63 | lastRun: WorkflowRun | null; | |
| 64 | }; | |
| 65 | ||
| 66 | export type StepState = { | |
| 67 | number: number; | |
| 68 | name: string; | |
| 69 | status: "queued" | "in_progress" | "completed"; | |
| 70 | conclusion: Conclusion | null; | |
| 71 | startedAt: string | null; | |
| 72 | finishedAt: string | null; | |
| 73 | }; | |
| 74 | ||
| 75 | export type Annotation = { | |
| 76 | level: "error" | "warning" | "notice"; | |
| 77 | message: string; | |
| 78 | title: string | null; | |
| 79 | file: string | null; | |
| 80 | line: number | null; | |
| 81 | }; | |
| 82 | ||
| 83 | export type Job = { | |
| 84 | id: string; | |
| 85 | runId: string; | |
| 86 | key: string; | |
| 87 | name: string; | |
| 88 | needs: string[]; | |
| Actions: keep workflow runs safe | 89 | /** |
| 90 | * `calling`: running the reusable workflow it calls, whose jobs follow it. | |
| 91 | * `pending`: held by its environment's protection rules; `reason` says for what. | |
| 92 | */ | |
| 93 | status: "waiting" | "pending" | "queued" | "in_progress" | "calling" | "completed"; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 94 | conclusion: Conclusion | null; |
| 95 | steps: StepState[]; | |
| 96 | annotations: Annotation[]; | |
| 97 | reason: string | null; | |
| 98 | startedAt: string | null; | |
| 99 | finishedAt: string | null; | |
| Actions: keep workflow runs safe | 100 | /** The environment it names, once its needs are done. */ |
| 101 | environment?: string | null; | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 102 | /** Its `runs-on` names self-hosted runners. */ |
| 103 | selfHosted?: boolean; | |
| 104 | /** The self-hosted runner that took it, by name. */ | |
| 105 | runner?: string | null; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 106 | }; |
| 107 | ||
| Actions: keep workflow runs safe | 108 | export type RunDetail = { |
| 109 | run: WorkflowRun; | |
| 110 | jobs: Job[]; | |
| 111 | notes: WorkflowNote[]; | |
| 112 | /** For a pull request's run from outside: whether it waits for, or had, approval. */ | |
| 113 | approval?: RunApproval | null; | |
| 114 | /** The environments whose protection rules hold its jobs, this attempt. */ | |
| 115 | pendingDeployments?: PendingDeployment[]; | |
| 116 | }; | |
| 117 | ||
| 118 | export type RunApproval = { | |
| 119 | state: "required" | "approved"; | |
| 120 | /** Why it waits, in words. */ | |
| 121 | reason: string; | |
| 122 | approvedBy: string | null; | |
| 123 | }; | |
| 124 | ||
| 125 | /** One person or team who may approve an environment's jobs. */ | |
| 126 | export type EnvironmentReviewer = { type: "user" | "team"; name: string }; | |
| 127 | ||
| 128 | /** A branch or tag pattern an environment takes deployments from. */ | |
| 129 | export type BranchPattern = { name: string; type: "branch" | "tag" }; | |
| 130 | ||
| 131 | /** The most reviewers an environment may have. */ | |
| 132 | export const MAX_ENVIRONMENT_REVIEWERS = 6; | |
| 133 | /** The longest wait timer, in minutes (30 days). */ | |
| 134 | export const MAX_WAIT_MINUTES = 43_200; | |
| 135 | ||
| 136 | /** | |
| 137 | * An environment and its protection rules. Jobs naming it with | |
| 138 | * `environment:` wait until the rules let them through, and only then get | |
| 139 | * its secrets. | |
| 140 | */ | |
| 141 | export type Environment = { | |
| 142 | /** Lowercase. */ | |
| 143 | name: string; | |
| 144 | reviewers: EnvironmentReviewer[]; | |
| 145 | preventSelfReview: boolean; | |
| 146 | waitMinutes: number; | |
| 147 | /** `protected`: branches the rules protect; `selected`: `branchPatterns`. */ | |
| 148 | branchPolicy: "all" | "protected" | "selected"; | |
| 149 | branchPatterns: BranchPattern[]; | |
| 150 | adminsBypass: boolean; | |
| 151 | /** Whether it has rules saved; false for one only named by a workflow or a secret. */ | |
| 152 | protected: boolean; | |
| 153 | updatedAt: string | null; | |
| 154 | updatedBy: string | null; | |
| 155 | }; | |
| 156 | ||
| 157 | /** What changes an environment's rules; left out is unchanged. */ | |
| 158 | export type EnvironmentChange = Partial< | |
| 159 | Pick<Environment, "reviewers" | "preventSelfReview" | "waitMinutes" | "branchPolicy" | "branchPatterns" | "adminsBypass"> | |
| 160 | >; | |
| 161 | ||
| 162 | /** An environment holding a run's jobs, and where its rules stand. */ | |
| 163 | export type PendingDeployment = { | |
| 164 | environment: string; | |
| 165 | state: "waiting" | "approved" | "rejected"; | |
| 166 | needsReview: boolean; | |
| 167 | /** When its wait timer lets its jobs start. */ | |
| 168 | waitUntil: string | null; | |
| 169 | reviewers: EnvironmentReviewer[]; | |
| 170 | /** The jobs it holds, by name. */ | |
| 171 | jobs: string[]; | |
| 172 | /** Whether the viewer may approve or reject it now. */ | |
| 173 | canReview: boolean; | |
| 174 | reviewedBy: string | null; | |
| 175 | comment: string | null; | |
| 176 | reviewedAt: string | null; | |
| 177 | }; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 178 | |
| Actions: keep workflow runs safe | 179 | /** Which pull requests' runs wait for approval, least strict first. */ |
| 180 | export const APPROVAL_POLICIES = ["first_time_contributors", "outside_contributors", "all_external_contributors"] as const; | |
| 181 | export type ApprovalPolicy = (typeof APPROVAL_POLICIES)[number]; | |
| 182 | ||
| 183 | /** A repository's choices for its workflows. */ | |
| 184 | export type ActionsSettings = { | |
| Merge main into the run-protection branch | 185 | /** |
| 186 | * What a workflow without `permissions:` gets. Unchosen, a repository made | |
| 187 | * before restricted tokens keeps `write`; a newer one takes its | |
| 188 | * workspace's default. Never more than `maxPermissions`. | |
| 189 | */ | |
| Actions: keep workflow runs safe | 190 | defaultPermissions: "read" | "write"; |
| Merge main into the run-protection branch | 191 | /** Whether the repository chose it. */ |
| 192 | defaultChosen: boolean; | |
| 193 | /** The most the workspace lets a repository's default be. */ | |
| 194 | maxPermissions: "read" | "write"; | |
| Actions: keep workflow runs safe | 195 | approvalPolicy: ApprovalPolicy; |
| Merge main into the run-protection branch | 196 | /** "Allow g1t Actions to create and approve pull requests". */ |
| 197 | canApprovePullRequests: boolean; | |
| 198 | /** Whether the workspace lets its repositories turn that on. */ | |
| 199 | workspaceAllowsPullRequests: boolean; | |
| Actions: keep workflow runs safe | 200 | }; |
| 201 | ||
| Merge main into the run-protection branch | 202 | /** What changes a repository's choices; `inherit` unchooses its default. */ |
| 203 | export type ActionsSettingsChange = { | |
| 204 | defaultPermissions?: "read" | "write" | "inherit"; | |
| 205 | approvalPolicy?: ApprovalPolicy; | |
| 206 | canApprovePullRequests?: boolean; | |
| 207 | }; | |
| 208 | ||
| 209 | /** A workspace's policy for its repositories' job tokens. */ | |
| 210 | export type WorkspaceActionsSettings = { | |
| 211 | /** What a repository made from now on gets by default. */ | |
| 212 | defaultPermissions: "read" | "write"; | |
| 213 | /** The most any repository's default may be. */ | |
| 214 | maxPermissions: "read" | "write"; | |
| 215 | canApprovePullRequests: boolean; | |
| 216 | }; | |
| 217 | ||
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 218 | export type LogChunk = { seq: number; step: number; text: string }; |
| 219 | export type JobLog = { chunks: LogChunk[]; done: boolean }; | |
| 220 | ||
| Secrets and variables: one list, rows per environment, for workflows and deployments | 221 | /** |
| 222 | * Who may read a secret or variable: `workflows` (`secrets.*`, `vars.*` in | |
| 223 | * GitHub Actions) and `deployments` (a deploy build's environment and the | |
| 224 | * running app's bindings). Agents, checks and the merge queue never read | |
| 225 | * any. | |
| 226 | */ | |
| 227 | export type SettingReader = "workflows" | "deployments"; | |
| 228 | ||
| 229 | /** | |
| 230 | * One row of secrets and variables, as Vercel lists environment variables: | |
| 231 | * a key, its type, the environments it applies to and who reads it. A key | |
| 232 | * may have one row per environment. Secrets' values are never returned. | |
| 233 | */ | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 234 | export type Setting = { |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 235 | id: string; |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 236 | name: string; |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 237 | /** `variable` is shown as Config. Config may become a secret, never back. */ |
| 238 | kind: SettingKind; | |
| 239 | /** A variable's value. */ | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 240 | value: string | null; |
| Projects: what a workspace builds and runs, first on every page | 241 | /** A project's (a repository's belong to its project) or the workspace's. */ |
| 242 | scope: "project" | "workspace"; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 243 | updatedAt: string; |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 244 | availableTo: SettingReader[]; |
| 245 | /** The environments it applies to; empty is every environment. */ | |
| 246 | environments: string[]; | |
| Projects: what a workspace builds and runs, first on every page | 247 | /** A workspace's row: the projects it reaches, by slug; empty is every one. */ |
| 248 | projects: string[]; | |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 249 | /** Where to rotate it, or who to ask. */ |
| 250 | note: string | null; | |
| 251 | updatedBy: string | null; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 252 | }; |
| 253 | ||
| Secrets and variables: one list, rows per environment, for workflows and deployments | 254 | /** What saving a row sets beyond its value; left out is unchanged. */ |
| 255 | export type SettingOptions = { | |
| 256 | /** The row to change; left out, the key's row for every environment. */ | |
| 257 | id?: string; | |
| 258 | availableTo?: SettingReader[]; | |
| 259 | environments?: string[]; | |
| Projects: what a workspace builds and runs, first on every page | 260 | /** A workspace's row: project slugs; empty for every one. */ |
| 261 | projects?: string[]; | |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 262 | note?: string; |
| 263 | }; | |
| 264 | ||
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 265 | export type SettingsOwner = { repo: RepoPath } | { workspace: string }; |
| 266 | export type SettingKind = "secret" | "variable"; | |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 267 | /** `all` lists both. */ |
| 268 | export type SettingKindFilter = SettingKind | "all"; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 269 | |
| 270 | export type RunsFilter = { | |
| 271 | workflow?: string; | |
| 272 | branch?: string; | |
| 273 | event?: string; | |
| 274 | pull?: number; | |
| 275 | sha?: string; | |
| 276 | limit?: number; | |
| 277 | }; | |
| 278 | ||
| 279 | export interface ActionsApi { | |
| 280 | workflows(repo: RepoPath, viewer: Viewer): Promise<Result<Workflow[]>>; | |
| 281 | runs(repo: RepoPath, viewer: Viewer, filter?: RunsFilter): Promise<Result<WorkflowRun[]>>; | |
| 282 | run(repo: RepoPath, viewer: Viewer, id: string): Promise<Result<RunDetail>>; | |
| 283 | logs(repo: RepoPath, viewer: Viewer, job: string, after?: number): Promise<Result<JobLog>>; | |
| 284 | dispatch( | |
| 285 | actor: User, | |
| 286 | repo: RepoPath, | |
| 287 | workflow: string, | |
| 288 | ref: string | undefined, | |
| 289 | inputs: Record<string, unknown>, | |
| 290 | ): Promise<Result<WorkflowRun>>; | |
| 291 | cancel(actor: User, repo: RepoPath, id: string): Promise<Result<WorkflowRun>>; | |
| 292 | rerun(actor: User, repo: RepoPath, id: string, failedOnly?: boolean): Promise<Result<WorkflowRun>>; | |
| 293 | setWorkflowEnabled(actor: User, repo: RepoPath, workflow: string, enabled: boolean): Promise<Result<Workflow>>; | |
| Secrets and variables: one list, rows per environment, for workflows and deployments | 294 | settings(actor: User, owner: SettingsOwner, kind: SettingKindFilter): Promise<Result<Setting[]>>; |
| 295 | /** `value` null keeps an existing entry's default value. */ | |
| 296 | setSetting( | |
| 297 | actor: User, | |
| 298 | owner: SettingsOwner, | |
| 299 | kind: SettingKind, | |
| 300 | name: string, | |
| 301 | value: string | null, | |
| 302 | options?: SettingOptions, | |
| 303 | ): Promise<Result<Setting>>; | |
| 304 | /** One row by `id`, or every row of the key. */ | |
| 305 | deleteSetting(actor: User, owner: SettingsOwner, kind: SettingKindFilter, name: string, id?: string): Promise<Result<boolean>>; | |
| Actions: keep workflow runs safe | 306 | /** Lets a pull request's run from outside start. Write role. */ |
| 307 | approveRun(actor: User, repo: RepoPath, id: string): Promise<Result<WorkflowRun>>; | |
| 308 | pendingDeployments(repo: RepoPath, viewer: Viewer, id: string): Promise<Result<PendingDeployment[]>>; | |
| 309 | /** Approves or rejects the jobs `environments` hold (every waiting one when empty). */ | |
| 310 | reviewDeployments( | |
| 311 | actor: User, | |
| 312 | repo: RepoPath, | |
| 313 | id: string, | |
| 314 | state: "approved" | "rejected", | |
| 315 | environments?: string[], | |
| 316 | comment?: string, | |
| 317 | ): Promise<Result<PendingDeployment[]>>; | |
| 318 | actionsSettings(repo: RepoPath, viewer: Viewer): Promise<Result<ActionsSettings>>; | |
| 319 | /** Admin role. Left out is unchanged. */ | |
| Merge main into the run-protection branch | 320 | setActionsSettings(actor: User, repo: RepoPath, change: ActionsSettingsChange): Promise<Result<ActionsSettings>>; |
| 321 | /** Members. */ | |
| 322 | workspaceActionsSettings(workspace: string, viewer: Viewer): Promise<Result<WorkspaceActionsSettings>>; | |
| 323 | /** Owners. Left out is unchanged. */ | |
| 324 | setWorkspaceActionsSettings( | |
| 325 | actor: User, | |
| 326 | workspace: string, | |
| 327 | change: Partial<WorkspaceActionsSettings>, | |
| 328 | ): Promise<Result<WorkspaceActionsSettings>>; | |
| Actions: keep workflow runs safe | 329 | /** Every environment the repository's rules, secrets, workflows or jobs name. */ |
| 330 | environments(repo: RepoPath, viewer: Viewer): Promise<Result<Environment[]>>; | |
| 331 | /** Admin role. */ | |
| 332 | setEnvironment(actor: User, repo: RepoPath, name: string, change: EnvironmentChange): Promise<Result<Environment>>; | |
| 333 | deleteEnvironment(actor: User, repo: RepoPath, name: string): Promise<Result<boolean>>; | |
| Merge main into the run-protection branch | 334 | /** A repository's artifacts, newest first, or one run's. */ |
| 335 | artifacts(repo: RepoPath, viewer: Viewer, filter?: { run?: string; name?: string; page?: number; per_page?: number }): Promise<Result<ArtifactList>>; | |
| 336 | /** One artifact by id, or by run and name, with a token to download it for a few minutes. */ | |
| 337 | artifactDownload(repo: RepoPath, viewer: Viewer, by: { id?: number; run?: string; name?: string }): Promise<Result<ArtifactBlob>>; | |
| 338 | /** Needs the Write role. */ | |
| 339 | deleteArtifact(actor: User, repo: RepoPath, id: number): Promise<Result<Artifact>>; | |
| 340 | /** How long the repository keeps artifacts; with `days`, sets it (Maintain). */ | |
| 341 | artifactRetention(repo: RepoPath, viewer: Viewer, days?: number): Promise<Result<ArtifactRetention>>; | |
| GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs | 342 | } |
| Merge main into the run-protection branch | 343 | |
| 344 | /** | |
| 345 | * A workflow run's artifact, kept in R2 for its retention days. Mirrors | |
| 346 | * `g1t_contracts::actions::Artifact` (which travels in `snake_case`). | |
| 347 | */ | |
| 348 | export type Artifact = { | |
| 349 | id: number; | |
| 350 | name: string; | |
| 351 | size: number; | |
| 352 | /** `sha256:<hex>`, when the uploader said. */ | |
| 353 | digest: string | null; | |
| 354 | /** `zip`, or `tgz` for one an older runner sent. */ | |
| 355 | format: string; | |
| 356 | run_id: string; | |
| 357 | job_id: string; | |
| 358 | repo_id: string; | |
| 359 | expired: boolean; | |
| 360 | created_at: string; | |
| 361 | updated_at: string; | |
| 362 | expires_at: string; | |
| 363 | head_branch?: string | null; | |
| 364 | head_sha?: string | null; | |
| 365 | }; | |
| 366 | ||
| 367 | export type ArtifactList = { total_count: number; artifacts: Artifact[] }; | |
| 368 | ||
| 369 | /** An artifact, where it is, and a signed token for the API's `/actions/toolkit/blobs/{blob}`. */ | |
| 370 | export type ArtifactBlob = { artifact: Artifact; object: string; blob: string }; | |
| 371 | ||
| 372 | export type ArtifactRetention = { days: number; maximum_allowed_days: number }; |
This file's history is long; its oldest lines are credited to the oldest commit read.