Skip to content

Sync from Intelligence Flow #67

Sync from Intelligence Flow

Sync from Intelligence Flow #67

Workflow file for this run

# Generated by labkit (python -m labkit gen). Do not edit by hand.
# Edit labs/<lab>/publish.config.json and regenerate; drift fails `labkit doctor`.
# Install into operatorstack/interlock at .github/workflows/sync-upstream.yml (bootstrap step).
name: Sync from Intelligence Flow
on:
schedule:
- cron: "50 */6 * * *"
workflow_dispatch:
inputs:
source_commit:
description: Exact Intelligence Flow commit to project (defaults to main)
required: false
type: string
permissions:
contents: write
pull-requests: write
concurrency:
group: sync-intelligence-flow
cancel-in-progress: false
jobs:
sync:
runs-on: ubuntu-latest
steps:
- name: Create Operator Stack Publisher token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ vars.OPERATOR_STACK_PUBLISHER_APP_CLIENT_ID || vars.BOATSTACK_APP_CLIENT_ID }}
private-key: ${{ secrets.OPERATOR_STACK_PUBLISHER_APP_PRIVATE_KEY || secrets.BOATSTACK_APP_PRIVATE_KEY }}
owner: operatorstack
repositories: |
intelligence-flow
interlock
permission-contents: write
permission-pull-requests: write
- name: Check out Interlock
uses: actions/checkout@v4
with:
path: public-repo
token: ${{ steps.app-token.outputs.token }}
- name: Check out Intelligence Flow
uses: actions/checkout@v4
with:
repository: operatorstack/intelligence-flow
ref: ${{ inputs.source_commit || 'main' }}
fetch-depth: 0
path: intelligence-flow
token: ${{ steps.app-token.outputs.token }}
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install labkit
shell: bash
run: python3 -m pip install --quiet ./intelligence-flow/labkit
- name: Generate projection
id: generate
shell: bash
run: |
source_commit="$(git -C intelligence-flow log -1 --format=%H -- labs/21-interlock)"
current_commit="$(jq -r '.source.commit // empty' public-repo/UPSTREAM.json 2>/dev/null || echo '')"
if [[ -n "$current_commit" ]] &&
! git -C intelligence-flow merge-base --is-ancestor "$current_commit" "$source_commit"; then
echo "Ignoring stale request; Interlock already records $current_commit."
echo "stale=true" >> "$GITHUB_OUTPUT"
exit 0
fi
python3 -m labkit project \
--config intelligence-flow/labs/21-interlock/publish.config.json \
--repo public-repo \
--source-commit "$source_commit" \
--write
echo "source_commit=$source_commit" >> "$GITHUB_OUTPUT"
echo "stale=false" >> "$GITHUB_OUTPUT"
- name: Open generated pull request
if: steps.generate.outputs.stale != 'true'
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
SOURCE_COMMIT: ${{ steps.generate.outputs.source_commit }}
shell: bash
run: |
cd public-repo
if [[ -z "$(git status --porcelain)" ]]; then
echo "Interlock already matches Intelligence Flow."
exit 0
fi
git add -A
body_file="$(mktemp)"
{
echo "## Projection provenance"; echo
echo "Generated from \`operatorstack/intelligence-flow@$SOURCE_COMMIT\`."
echo "Review the operator contract, provenance, and compatibility before merging."
} > "$body_file"
short="${SOURCE_COMMIT:0:12}"
branch="sync/intelligence-flow-$short"
existing="$(gh pr list --head "$branch" --state open --json url --jq '.[0].url')"
git config user.name "${{ steps.app-token.outputs.app-slug }}[bot]"
git config user.email "${{ steps.app-token.outputs.app-slug }}[bot]@users.noreply.github.com"
git switch -c "$branch"
git commit -m "Sync Interlock from Intelligence Flow @ $short"
git push --force --set-upstream origin "$branch"
if [[ -z "$existing" ]]; then
pr_url="$(gh pr create --base main --head "$branch" \
--title "Sync Interlock from Intelligence Flow @ $short" \
--body-file "$body_file")"
echo "Opened generated PR: $pr_url"
else
pr_url="$existing"
echo "Updated existing PR: $existing"
fi
gh pr merge "$pr_url" --auto --squash
echo "Native auto-merge requested; branch protection owns merge eligibility."