Skip to content

Commit 524dccc

Browse files
zachallerclaude
andcommitted
fix(revertcommit): restrict restore targets, remove clones, no-op live restores, docs (#34)
* fix(revertcommit): only restore commits from the active branch's history and remove the clone RestoreActiveBranch fetched spec.sha from origin when it was not local and pushed its tree to the active branch, so any commit the remote serves (another environment's branch, an unmerged pull request head) could be pushed past promotion. It now requires spec.sha to be the active tip or one of its ancestors and no longer fetches it. Each RevertCommit also cloned the repository under its own identity and never removed it, so clones accumulated for the life of the process. The reconciler now removes its clone when the reconcile ends, via a new EnvironmentOperations.RemoveClone and gitpaths.Delete. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AuLMzzgAYf1gDXmHg2rtgJ Signed-off-by: Claude <noreply@anthropic.com> * fix(revertcommit): no-op restore to the live version, document branch protection and resume When the active branch already has spec.sha's content and no restore marker put it there, RestoreActiveBranch now writes nothing and returns Unchanged with an empty BlockedDrySha. Previously it wrote an empty restore commit and blocked the live dry SHA, which held back the very version being restored. The reconciler emits AlreadyRestored instead of Restored in that case. rolling-back.md now warns that the restore pushes directly to the active branch (so branch protection must let the controller through), and makes the "deleting the RevertCommit does not re-propose the reverted change" behavior a prominent warning. The RevertCommit spec.sha and status.blockedDrySha docs describe the active-history requirement and the no-op case; CRDs, dist bundles, and view/UI generated types are regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AuLMzzgAYf1gDXmHg2rtgJ Signed-off-by: Claude <noreply@anthropic.com> --------- Signed-off-by: Claude <noreply@anthropic.com> Co-authored-by: Claude <noreply@anthropic.com> Signed-off-by: Zach Aller <zachaller@users.noreply.github.com>
1 parent feb6d49 commit 524dccc

15 files changed

Lines changed: 214 additions & 74 deletions

File tree

‎api/v1alpha1/revertcommit_types.go‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,11 @@ type RevertCommitSpec struct {
3535
// +kubebuilder:validation:Required
3636
ChangeTransferPolicyRef ObjectReference `json:"changeTransferPolicyRef"`
3737

38-
// Sha is the hydrated commit to restore onto the active branch. The controller writes a new
39-
// commit (the commit's tree, or only activePath when the policy sets one) parented on the
40-
// current active tip and records a promotion-history note with Promoter-restored-from.
38+
// Sha is the hydrated commit to restore onto the active branch. It must already be in the active
39+
// branch's history (the tip or one of its ancestors); any other commit is refused. The
40+
// controller writes a new commit (the commit's tree, or only activePath when the policy sets
41+
// one) parented on the current active tip and records a promotion-history note with
42+
// Promoter-restored-from. When the active branch already has that content, nothing is written.
4143
// The proposed branch is left as the hydrator wrote it. The ChangeTransferPolicy does not open
4244
// a promotion pull request that would put the active branch's dry SHA back. A pull request
4345
// for a different proposed dry SHA may open, but nothing is auto-merged while this
@@ -71,7 +73,8 @@ type RevertCommitStatus struct {
7173
// moved off of. The ChangeTransferPolicy does not open a promotion pull request while its
7274
// proposed dry SHA still equals this value, so the reverted change is not put back. A different
7375
// proposed dry SHA may open a pull request, but nothing is auto-merged while this RevertCommit
74-
// exists. Empty when that active tip had no hydrator.metadata. Deleting the RevertCommit lifts
76+
// exists. Empty when that active tip had no hydrator.metadata, or when the active branch already
77+
// had spec.sha's content so nothing was moved off it. Deleting the RevertCommit lifts
7578
// this block, but a promotion pull request only opens when the proposed branch has a commit the
7679
// active branch does not already contain. The restore commit is parented on the tip it moved
7780
// off of, so when that tip already contains the proposed commit (a merge-commit promotion),

‎api/view/v1alpha1/zz_generated.openapi.go‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎applyconfiguration/api/v1alpha1/revertcommitspec.go‎

Lines changed: 5 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎applyconfiguration/api/v1alpha1/revertcommitstatus.go‎

Lines changed: 2 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎config/crd/bases/promoter.argoproj.io_revertcommits.yaml‎

Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/install-with-dashboard-byo-cert.yaml‎

Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/install-with-dashboard-cert-manager.yaml‎

Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/install-without-ui.yaml‎

Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)