Commit 524dccc
fix(revertcommit): restrict restore targets, remove clones, no-op live restores, docs (#34)
* fix(revertcommit): only restore commits from the active branch's history and remove the clone
RestoreActiveBranch fetched spec.sha from origin when it was not local and
pushed its tree to the active branch, so any commit the remote serves (another
environment's branch, an unmerged pull request head) could be pushed past
promotion. It now requires spec.sha to be the active tip or one of its
ancestors and no longer fetches it.
Each RevertCommit also cloned the repository under its own identity and never
removed it, so clones accumulated for the life of the process. The reconciler
now removes its clone when the reconcile ends, via a new
EnvironmentOperations.RemoveClone and gitpaths.Delete.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AuLMzzgAYf1gDXmHg2rtgJ
Signed-off-by: Claude <noreply@anthropic.com>
* fix(revertcommit): no-op restore to the live version, document branch protection and resume
When the active branch already has spec.sha's content and no restore marker put
it there, RestoreActiveBranch now writes nothing and returns Unchanged with an
empty BlockedDrySha. Previously it wrote an empty restore commit and blocked
the live dry SHA, which held back the very version being restored. The
reconciler emits AlreadyRestored instead of Restored in that case.
rolling-back.md now warns that the restore pushes directly to the active
branch (so branch protection must let the controller through), and makes the
"deleting the RevertCommit does not re-propose the reverted change" behavior a
prominent warning. The RevertCommit spec.sha and status.blockedDrySha docs
describe the active-history requirement and the no-op case; CRDs, dist
bundles, and view/UI generated types are regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AuLMzzgAYf1gDXmHg2rtgJ
Signed-off-by: Claude <noreply@anthropic.com>
---------
Signed-off-by: Claude <noreply@anthropic.com>
Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Zach Aller <zachaller@users.noreply.github.com>1 parent feb6d49 commit 524dccc
15 files changed
Lines changed: 214 additions & 74 deletions
File tree
- api
- v1alpha1
- view/v1alpha1
- applyconfiguration/api/v1alpha1
- config/crd/bases
- dist
- docs
- advanced-usage
- monitoring
- internal
- controller
- git
- utils/gitpaths
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
39 | | - | |
40 | | - | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
41 | 43 | | |
42 | 44 | | |
43 | 45 | | |
| |||
71 | 73 | | |
72 | 74 | | |
73 | 75 | | |
74 | | - | |
| 76 | + | |
| 77 | + | |
75 | 78 | | |
76 | 79 | | |
77 | 80 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments