Files
Kill_LIFE/tools/ci/protected_environments.sh
L'électron rareandClaude Opus 4.6 7870c6cf58 feat: close plans 06/09/14 — CI firmware/HW gate, bulk edit, release process
Plan 06 CI/CD: .clang-format, lint_firmware.sh, branch_protection.sh,
  protected_environments.sh, firmware-lint + hardware-gate CI jobs
Plan 09 Bulk Edit: snapshot.sh, bulk_edit.py (dry-run/apply/verify), hw_diff.sh
Plan 14 Release: release_prep.sh, generate_changelog.py, release_policy.py

All 20 items closed across 3 plans.

Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
2026-03-25 12:43:33 +01:00

79 lines
1.9 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
# Configure GitHub deployment environments with protection rules.
# Requires: gh CLI authenticated with admin access.
#
# Usage:
# tools/ci/protected_environments.sh [--dry-run]
#
# Creates two environments:
# - staging: auto-deploy, no reviewers
# - production: requires 1 reviewer, wait timer 5 min
REPO="${GITHUB_REPOSITORY:-$(gh repo view --json nameWithOwner -q .nameWithOwner 2>/dev/null || echo '')}"
DRY_RUN=0
if [[ "${1:-}" == "--dry-run" ]]; then
DRY_RUN=1
fi
if [[ -z "$REPO" ]]; then
echo "ERROR: Cannot determine repository." >&2
exit 1
fi
create_environment() {
local name="$1"
local wait_timer="$2"
local reviewers_json="$3"
echo "--- Environment: $name ---"
local payload
payload=$(python3 -c "
import json, sys
data = {
'wait_timer': $wait_timer,
'prevent_self_review': False,
'deployment_branch_policy': {
'protected_branches': True,
'custom_branch_policies': False
}
}
reviewers = $reviewers_json
if reviewers:
data['reviewers'] = reviewers
print(json.dumps(data))
")
if [[ "$DRY_RUN" -eq 1 ]]; then
echo "[dry-run] PUT /repos/$REPO/environments/$name"
echo "$payload" | python3 -m json.tool 2>/dev/null || echo "$payload"
echo ""
return
fi
gh api \
--method PUT \
-H "Accept: application/vnd.github+json" \
"/repos/$REPO/environments/$name" \
--input - <<< "$payload"
echo "Created/updated environment: $name"
echo ""
}
echo "Repository: $REPO"
echo ""
# staging: no wait, no reviewers
create_environment "staging" 0 "[]"
# production: 5-min wait, require repo admin review
# Note: reviewer IDs need to be fetched dynamically; we use an empty list
# and instruct the admin to add reviewers via the GitHub UI.
create_environment "production" 5 "[]"
echo "Done. Add reviewers to the 'production' environment via GitHub Settings > Environments."