| 1 | import type { User, Viewer } from "./identity"; |
| 2 | import type { RepoPath } from "./repos"; |
| 3 | import type { Result } from "./result"; |
| 4 | |
| 5 | /** |
| 6 | * GitHub Actions workflows, run on g1t as they are. Mirrors |
| 7 | * `crates/contracts/src/actions.rs`. |
| 8 | */ |
| 9 | |
| 10 | export type WorkflowNote = { |
| 11 | severity: "info" | "warning" | "unsupported"; |
| 12 | job: string | null; |
| 13 | message: string; |
| 14 | }; |
| 15 | |
| 16 | /** One `workflow_dispatch` input, as written in the workflow. */ |
| 17 | export type DispatchInput = { |
| 18 | description?: string; |
| 19 | required?: boolean; |
| 20 | default?: string | number | boolean; |
| 21 | type?: "string" | "boolean" | "number" | "choice" | "environment"; |
| 22 | options?: string[]; |
| 23 | }; |
| 24 | |
| 25 | /** |
| 26 | * `action_required`: a pull request's run from outside, waiting for someone |
| 27 | * with the Write role to approve it. `waiting`: its jobs are held by an |
| 28 | * environment's protection rules (a run's detail says so; lists do not). |
| 29 | */ |
| 30 | export type RunStatus = "pending" | "action_required" | "queued" | "in_progress" | "waiting" | "completed"; |
| 31 | export type Conclusion = "success" | "failure" | "cancelled" | "skipped"; |
| 32 | |
| 33 | export type WorkflowRun = { |
| 34 | id: string; |
| 35 | workflowId: string; |
| 36 | path: string; |
| 37 | name: string; |
| 38 | title: string; |
| 39 | number: number; |
| 40 | attempt: number; |
| 41 | event: string; |
| 42 | ref: string; |
| 43 | sha: string; |
| 44 | pull: number | null; |
| 45 | status: RunStatus; |
| 46 | conclusion: Conclusion | null; |
| 47 | error: string | null; |
| 48 | actor: string | null; |
| 49 | createdAt: string; |
| 50 | startedAt: string | null; |
| 51 | finishedAt: string | null; |
| 52 | }; |
| 53 | |
| 54 | export type Workflow = { |
| 55 | id: string; |
| 56 | path: string; |
| 57 | name: string; |
| 58 | events: string[]; |
| 59 | state: "active" | "disabled"; |
| 60 | error: string | null; |
| 61 | notes: WorkflowNote[]; |
| 62 | dispatch: Record<string, DispatchInput> | null; |
| 63 | lastRun: WorkflowRun | null; |
| 64 | }; |
| 65 | |
| 66 | export type StepState = { |
| 67 | number: number; |
| 68 | name: string; |
| 69 | status: "queued" | "in_progress" | "completed"; |
| 70 | conclusion: Conclusion | null; |
| 71 | startedAt: string | null; |
| 72 | finishedAt: string | null; |
| 73 | }; |
| 74 | |
| 75 | export type Annotation = { |
| 76 | level: "error" | "warning" | "notice"; |
| 77 | message: string; |
| 78 | title: string | null; |
| 79 | file: string | null; |
| 80 | line: number | null; |
| 81 | }; |
| 82 | |
| 83 | export type Job = { |
| 84 | id: string; |
| 85 | runId: string; |
| 86 | key: string; |
| 87 | name: string; |
| 88 | needs: string[]; |
| 89 | /** |
| 90 | * `calling`: running the reusable workflow it calls, whose jobs follow it. |
| 91 | * `pending`: held by its environment's protection rules; `reason` says for what. |
| 92 | */ |
| 93 | status: "waiting" | "pending" | "queued" | "in_progress" | "calling" | "completed"; |
| 94 | conclusion: Conclusion | null; |
| 95 | steps: StepState[]; |
| 96 | annotations: Annotation[]; |
| 97 | reason: string | null; |
| 98 | startedAt: string | null; |
| 99 | finishedAt: string | null; |
| 100 | /** The environment it names, once its needs are done. */ |
| 101 | environment?: string | null; |
| 102 | /** Its `runs-on` names self-hosted runners. */ |
| 103 | selfHosted?: boolean; |
| 104 | /** The self-hosted runner that took it, by name. */ |
| 105 | runner?: string | null; |
| 106 | /** Cancelled, and running its `if: always()` and `cancelled()` steps and post steps before it ends. */ |
| 107 | cancelling?: boolean; |
| 108 | }; |
| 109 | |
| 110 | /** One attempt of a run: the first, or a re-run. */ |
| 111 | export type RunAttempt = { |
| 112 | attempt: number; |
| 113 | status: RunStatus; |
| 114 | conclusion: Conclusion | null; |
| 115 | /** Who started it: whoever caused the run, then whoever re-ran it. */ |
| 116 | actor: string | null; |
| 117 | /** It ran with debug logging. */ |
| 118 | debug: boolean; |
| 119 | startedAt: string | null; |
| 120 | finishedAt: string | null; |
| 121 | }; |
| 122 | |
| 123 | /** What a job's steps wrote to `$GITHUB_STEP_SUMMARY`, in Markdown, masked. */ |
| 124 | export type JobSummary = { jobId: string; name: string; steps: { step: number; markdown: string }[] }; |
| 125 | |
| 126 | /** A job's whole log, to download. `omitted`: left out of a run's logs that grew too large. */ |
| 127 | export type JobLogText = { |
| 128 | jobId: string; |
| 129 | name: string; |
| 130 | steps: StepState[]; |
| 131 | chunks: LogChunk[]; |
| 132 | done: boolean; |
| 133 | omitted?: boolean; |
| 134 | }; |
| 135 | |
| 136 | export type RunDetail = { |
| 137 | run: WorkflowRun; |
| 138 | jobs: Job[]; |
| 139 | notes: WorkflowNote[]; |
| 140 | /** For a pull request's run from outside: whether it waits for, or had, approval. */ |
| 141 | approval?: RunApproval | null; |
| 142 | /** The environments whose protection rules hold its jobs, this attempt. */ |
| 143 | pendingDeployments?: PendingDeployment[]; |
| 144 | /** Every attempt, oldest first, the one shown (`run.attempt`) included. */ |
| 145 | attempts?: RunAttempt[]; |
| 146 | }; |
| 147 | |
| 148 | export type RunApproval = { |
| 149 | state: "required" | "approved"; |
| 150 | /** Why it waits, in words. */ |
| 151 | reason: string; |
| 152 | approvedBy: string | null; |
| 153 | }; |
| 154 | |
| 155 | /** One person or team who may approve an environment's jobs. */ |
| 156 | export type EnvironmentReviewer = { type: "user" | "team"; name: string }; |
| 157 | |
| 158 | /** A branch or tag pattern an environment takes deployments from. */ |
| 159 | export type BranchPattern = { name: string; type: "branch" | "tag" }; |
| 160 | |
| 161 | /** The most reviewers an environment may have. */ |
| 162 | export const MAX_ENVIRONMENT_REVIEWERS = 6; |
| 163 | /** The longest wait timer, in minutes (30 days). */ |
| 164 | export const MAX_WAIT_MINUTES = 43_200; |
| 165 | |
| 166 | /** |
| 167 | * An environment and its protection rules. Jobs naming it with |
| 168 | * `environment:` wait until the rules let them through, and only then get |
| 169 | * its secrets. |
| 170 | */ |
| 171 | export type Environment = { |
| 172 | /** Lowercase. */ |
| 173 | name: string; |
| 174 | reviewers: EnvironmentReviewer[]; |
| 175 | preventSelfReview: boolean; |
| 176 | waitMinutes: number; |
| 177 | /** `protected`: branches the rules protect; `selected`: `branchPatterns`. */ |
| 178 | branchPolicy: "all" | "protected" | "selected"; |
| 179 | branchPatterns: BranchPattern[]; |
| 180 | adminsBypass: boolean; |
| 181 | /** Whether it has rules saved; false for one only named by a workflow or a secret. */ |
| 182 | protected: boolean; |
| 183 | updatedAt: string | null; |
| 184 | updatedBy: string | null; |
| 185 | }; |
| 186 | |
| 187 | /** What changes an environment's rules; left out is unchanged. */ |
| 188 | export type EnvironmentChange = Partial< |
| 189 | Pick<Environment, "reviewers" | "preventSelfReview" | "waitMinutes" | "branchPolicy" | "branchPatterns" | "adminsBypass"> |
| 190 | >; |
| 191 | |
| 192 | /** An environment holding a run's jobs, and where its rules stand. */ |
| 193 | export type PendingDeployment = { |
| 194 | environment: string; |
| 195 | state: "waiting" | "approved" | "rejected"; |
| 196 | needsReview: boolean; |
| 197 | /** When its wait timer lets its jobs start. */ |
| 198 | waitUntil: string | null; |
| 199 | reviewers: EnvironmentReviewer[]; |
| 200 | /** The jobs it holds, by name. */ |
| 201 | jobs: string[]; |
| 202 | /** Whether the viewer may approve or reject it now. */ |
| 203 | canReview: boolean; |
| 204 | reviewedBy: string | null; |
| 205 | comment: string | null; |
| 206 | reviewedAt: string | null; |
| 207 | }; |
| 208 | |
| 209 | /** Which pull requests' runs wait for approval, least strict first. */ |
| 210 | export const APPROVAL_POLICIES = ["first_time_contributors", "outside_contributors", "all_external_contributors"] as const; |
| 211 | export type ApprovalPolicy = (typeof APPROVAL_POLICIES)[number]; |
| 212 | |
| 213 | /** A repository's choices for its workflows. */ |
| 214 | export type ActionsSettings = { |
| 215 | /** |
| 216 | * What a workflow without `permissions:` gets. Unchosen, a repository made |
| 217 | * before restricted tokens keeps `write`; a newer one takes its |
| 218 | * workspace's default. Never more than `maxPermissions`. |
| 219 | */ |
| 220 | defaultPermissions: "read" | "write"; |
| 221 | /** Whether the repository chose it. */ |
| 222 | defaultChosen: boolean; |
| 223 | /** The most the workspace lets a repository's default be. */ |
| 224 | maxPermissions: "read" | "write"; |
| 225 | approvalPolicy: ApprovalPolicy; |
| 226 | /** "Allow g1t Actions to create and approve pull requests". */ |
| 227 | canApprovePullRequests: boolean; |
| 228 | /** Whether the workspace lets its repositories turn that on. */ |
| 229 | workspaceAllowsPullRequests: boolean; |
| 230 | /** |
| 231 | * Who may use the repository's actions and reusable workflows while it is |
| 232 | * private: only itself (`none`), or private repositories of its workspace |
| 233 | * (`organization`). A public repository's are anyone's. |
| 234 | */ |
| 235 | accessLevel: ActionsAccessLevel; |
| 236 | }; |
| 237 | |
| 238 | /** Settings, Actions, Access. */ |
| 239 | export const ACTIONS_ACCESS_LEVELS = ["none", "organization"] as const; |
| 240 | export type ActionsAccessLevel = (typeof ACTIONS_ACCESS_LEVELS)[number]; |
| 241 | |
| 242 | /** What changes a repository's choices; `inherit` unchooses its default. */ |
| 243 | export type ActionsSettingsChange = { |
| 244 | defaultPermissions?: "read" | "write" | "inherit"; |
| 245 | approvalPolicy?: ApprovalPolicy; |
| 246 | canApprovePullRequests?: boolean; |
| 247 | accessLevel?: ActionsAccessLevel; |
| 248 | }; |
| 249 | |
| 250 | /** A workspace's policy for its repositories' job tokens. */ |
| 251 | export type WorkspaceActionsSettings = { |
| 252 | /** What a repository made from now on gets by default. */ |
| 253 | defaultPermissions: "read" | "write"; |
| 254 | /** The most any repository's default may be. */ |
| 255 | maxPermissions: "read" | "write"; |
| 256 | canApprovePullRequests: boolean; |
| 257 | }; |
| 258 | |
| 259 | export type LogChunk = { seq: number; step: number; text: string }; |
| 260 | export type JobLog = { chunks: LogChunk[]; done: boolean }; |
| 261 | |
| 262 | /** |
| 263 | * Who may read a secret or variable: `workflows` (`secrets.*`, `vars.*` in |
| 264 | * GitHub Actions) and `deployments` (a deploy build's environment and the |
| 265 | * running app's bindings). Agents, checks and the merge queue never read |
| 266 | * any. |
| 267 | */ |
| 268 | export type SettingReader = "workflows" | "deployments"; |
| 269 | |
| 270 | /** |
| 271 | * One row of secrets and variables, as Vercel lists environment variables: |
| 272 | * a key, its type, the environments it applies to and who reads it. A key |
| 273 | * may have one row per environment. Secrets' values are never returned. |
| 274 | */ |
| 275 | export type Setting = { |
| 276 | id: string; |
| 277 | name: string; |
| 278 | /** `variable` is shown as Config. Config may become a secret, never back. */ |
| 279 | kind: SettingKind; |
| 280 | /** A variable's value. */ |
| 281 | value: string | null; |
| 282 | /** A project's (a repository's belong to its project) or the workspace's. */ |
| 283 | scope: "project" | "workspace"; |
| 284 | updatedAt: string; |
| 285 | availableTo: SettingReader[]; |
| 286 | /** The environments it applies to; empty is every environment. */ |
| 287 | environments: string[]; |
| 288 | /** A workspace's row: the projects it reaches, by slug; empty is every one. */ |
| 289 | projects: string[]; |
| 290 | /** Where to rotate it, or who to ask. */ |
| 291 | note: string | null; |
| 292 | updatedBy: string | null; |
| 293 | }; |
| 294 | |
| 295 | /** What saving a row sets beyond its value; left out is unchanged. */ |
| 296 | export type SettingOptions = { |
| 297 | /** The row to change; left out, the key's row for every environment. */ |
| 298 | id?: string; |
| 299 | availableTo?: SettingReader[]; |
| 300 | environments?: string[]; |
| 301 | /** A workspace's row: project slugs; empty for every one. */ |
| 302 | projects?: string[]; |
| 303 | note?: string; |
| 304 | }; |
| 305 | |
| 306 | export type SettingsOwner = { repo: RepoPath } | { workspace: string }; |
| 307 | export type SettingKind = "secret" | "variable"; |
| 308 | /** `all` lists both. */ |
| 309 | export type SettingKindFilter = SettingKind | "all"; |
| 310 | |
| 311 | export type RunsFilter = { |
| 312 | workflow?: string; |
| 313 | branch?: string; |
| 314 | event?: string; |
| 315 | pull?: number; |
| 316 | sha?: string; |
| 317 | limit?: number; |
| 318 | }; |
| 319 | |
| 320 | export interface ActionsApi { |
| 321 | workflows(repo: RepoPath, viewer: Viewer): Promise<Result<Workflow[]>>; |
| 322 | runs(repo: RepoPath, viewer: Viewer, filter?: RunsFilter): Promise<Result<WorkflowRun[]>>; |
| 323 | /** The latest attempt, or an earlier one. */ |
| 324 | run(repo: RepoPath, viewer: Viewer, id: string, attempt?: number): Promise<Result<RunDetail>>; |
| 325 | logs(repo: RepoPath, viewer: Viewer, job: string, after?: number): Promise<Result<JobLog>>; |
| 326 | /** The job summaries of an attempt (the latest by default), jobs without one left out. */ |
| 327 | summaries(repo: RepoPath, viewer: Viewer, id: string, attempt?: number): Promise<Result<JobSummary[]>>; |
| 328 | /** A job's whole log, any attempt's, by the id the run gave the job. */ |
| 329 | jobLogText(repo: RepoPath, viewer: Viewer, job: string): Promise<Result<JobLogText>>; |
| 330 | /** Every job's whole log for an attempt, to download as one archive. */ |
| 331 | runLogs(repo: RepoPath, viewer: Viewer, id: string, attempt?: number): Promise<Result<JobLogText[]>>; |
| 332 | dispatch( |
| 333 | actor: User, |
| 334 | repo: RepoPath, |
| 335 | workflow: string, |
| 336 | ref: string | undefined, |
| 337 | inputs: Record<string, unknown>, |
| 338 | ): Promise<Result<WorkflowRun>>; |
| 339 | /** Running jobs clean up first; `force` (or cancelling a run that is cancelling) stops them outright. */ |
| 340 | cancel(actor: User, repo: RepoPath, id: string, force?: boolean): Promise<Result<WorkflowRun>>; |
| 341 | /** A new attempt: every job, the failed ones, or `job` and what needs it; `debug` for debug logging. */ |
| 342 | rerun( |
| 343 | actor: User, |
| 344 | repo: RepoPath, |
| 345 | id: string, |
| 346 | failedOnly?: boolean, |
| 347 | options?: { job?: string; debug?: boolean }, |
| 348 | ): Promise<Result<WorkflowRun>>; |
| 349 | setWorkflowEnabled(actor: User, repo: RepoPath, workflow: string, enabled: boolean): Promise<Result<Workflow>>; |
| 350 | settings(actor: User, owner: SettingsOwner, kind: SettingKindFilter): Promise<Result<Setting[]>>; |
| 351 | /** `value` null keeps an existing entry's default value. */ |
| 352 | setSetting( |
| 353 | actor: User, |
| 354 | owner: SettingsOwner, |
| 355 | kind: SettingKind, |
| 356 | name: string, |
| 357 | value: string | null, |
| 358 | options?: SettingOptions, |
| 359 | ): Promise<Result<Setting>>; |
| 360 | /** One row by `id`, or every row of the key. */ |
| 361 | deleteSetting(actor: User, owner: SettingsOwner, kind: SettingKindFilter, name: string, id?: string): Promise<Result<boolean>>; |
| 362 | /** Lets a pull request's run from outside start. Write role. */ |
| 363 | approveRun(actor: User, repo: RepoPath, id: string): Promise<Result<WorkflowRun>>; |
| 364 | pendingDeployments(repo: RepoPath, viewer: Viewer, id: string): Promise<Result<PendingDeployment[]>>; |
| 365 | /** Approves or rejects the jobs `environments` hold (every waiting one when empty). */ |
| 366 | reviewDeployments( |
| 367 | actor: User, |
| 368 | repo: RepoPath, |
| 369 | id: string, |
| 370 | state: "approved" | "rejected", |
| 371 | environments?: string[], |
| 372 | comment?: string, |
| 373 | ): Promise<Result<PendingDeployment[]>>; |
| 374 | actionsSettings(repo: RepoPath, viewer: Viewer): Promise<Result<ActionsSettings>>; |
| 375 | /** Admin role. Left out is unchanged. */ |
| 376 | setActionsSettings(actor: User, repo: RepoPath, change: ActionsSettingsChange): Promise<Result<ActionsSettings>>; |
| 377 | /** Members. */ |
| 378 | workspaceActionsSettings(workspace: string, viewer: Viewer): Promise<Result<WorkspaceActionsSettings>>; |
| 379 | /** Owners. Left out is unchanged. */ |
| 380 | setWorkspaceActionsSettings( |
| 381 | actor: User, |
| 382 | workspace: string, |
| 383 | change: Partial<WorkspaceActionsSettings>, |
| 384 | ): Promise<Result<WorkspaceActionsSettings>>; |
| 385 | /** Every environment the repository's rules, secrets, workflows or jobs name. */ |
| 386 | environments(repo: RepoPath, viewer: Viewer): Promise<Result<Environment[]>>; |
| 387 | /** Admin role. */ |
| 388 | setEnvironment(actor: User, repo: RepoPath, name: string, change: EnvironmentChange): Promise<Result<Environment>>; |
| 389 | deleteEnvironment(actor: User, repo: RepoPath, name: string): Promise<Result<boolean>>; |
| 390 | /** A repository's artifacts, newest first, or one run's. */ |
| 391 | artifacts(repo: RepoPath, viewer: Viewer, filter?: { run?: string; name?: string; page?: number; per_page?: number }): Promise<Result<ArtifactList>>; |
| 392 | /** One artifact by id, or by run and name, with a token to download it for a few minutes. */ |
| 393 | artifactDownload(repo: RepoPath, viewer: Viewer, by: { id?: number; run?: string; name?: string }): Promise<Result<ArtifactBlob>>; |
| 394 | /** Needs the Write role. */ |
| 395 | deleteArtifact(actor: User, repo: RepoPath, id: number): Promise<Result<Artifact>>; |
| 396 | /** How long the repository keeps artifacts; with `days`, sets it (Maintain). */ |
| 397 | artifactRetention(repo: RepoPath, viewer: Viewer, days?: number): Promise<Result<ArtifactRetention>>; |
| 398 | } |
| 399 | |
| 400 | /** |
| 401 | * A workflow run's artifact, kept in R2 for its retention days. Mirrors |
| 402 | * `g1t_contracts::actions::Artifact` (which travels in `snake_case`). |
| 403 | */ |
| 404 | export type Artifact = { |
| 405 | id: number; |
| 406 | name: string; |
| 407 | size: number; |
| 408 | /** `sha256:<hex>`, when the uploader said. */ |
| 409 | digest: string | null; |
| 410 | /** `zip`, or `tgz` for one an older runner sent. */ |
| 411 | format: string; |
| 412 | run_id: string; |
| 413 | job_id: string; |
| 414 | repo_id: string; |
| 415 | expired: boolean; |
| 416 | created_at: string; |
| 417 | updated_at: string; |
| 418 | expires_at: string; |
| 419 | head_branch?: string | null; |
| 420 | head_sha?: string | null; |
| 421 | }; |
| 422 | |
| 423 | export type ArtifactList = { total_count: number; artifacts: Artifact[] }; |
| 424 | |
| 425 | /** An artifact, where it is, and a signed token for the API's `/actions/toolkit/blobs/{blob}`. */ |
| 426 | export type ArtifactBlob = { artifact: Artifact; object: string; blob: string }; |
| 427 | |
| 428 | export type ArtifactRetention = { days: number; maximum_allowed_days: number }; |