Skip to content

feat(config): estate canon — rulesets, gates map, repo settings, allowlist, autolink profiles (step 1 of #715) - #716

Merged
hyperpolymath merged 2 commits into
mainfrom
cicd-regularisation/step-1-canon
Sep 2, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
cicd-regularisation/step-1-canon

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Step 1 of the CI/CD regularisation (spec: docs/superpowers/specs/2026-09-02-cicd-regularisation-design.md, owner batch #715).

Adds config/:

  • rulesets/base.json — branch ruleset (identity = target branch + ~DEFAULT_BRANCH); gates-only.json (O6 option); immutable-tags.json
  • rulesets/gates.json — which canonical callers are GATE per repo type; contexts are derived from the latest run, never typed
  • settings/repo.json, settings/actions-allowlist.json (118 → 92, hygiene; applied at the tail of the sweep)
  • autolinks/{base,rust,proof,julia,elixir}.json — from a 428-repo audit; ADR- template fixed (live one 404s on every repo)
  • README.adoc — what each file is, what base drops from live and why, apply order

Also: MUST list + naming convention appended to docs/CICD-SIGNAL-DISCIPLINE.adoc; spec §13 amendments (findings that changed the plan: no App credential on standards → O11; rulesets work on private Free → P-priv dropped; update rule dropped; O12 allowlist enforcement).

Nothing here is applied to any repo. The applier is step 3.

🤖 Generated with Claude Code

hyperpolymath and others added 2 commits September 2, 2026 12:28
…ngs, allowlist, autolink profiles (step 1 of #715)

Machine-readable single source of truth for repo configuration:
config/rulesets/{base,gates,gates-only,immutable-tags}.json,
config/settings/{repo,actions-allowlist}.json, config/autolinks/*.json,
config/README.adoc. Tier doc gains the ratified MUST list, the caller
naming convention and two invariants. Spec gains §13 amendments.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ked hygiene (O12), gates never_required split by kind

- ADR files are ADR-<num>-<slug>.adoc; the copied template ADR-<num>.adoc
  returned 404 on every repo (verified on standards). Canon now uses a
  code-search URL that keeps <num>.
- verified_allowed=true means verified creators bypass patterns_allowed;
  the 118->92 prune is hygiene, R1 is enforced by deleting workflows.
  Flipping verified_allowed is O12, after a uses: census.
- gates.json: never_required_workflows vs never_required_contexts so the
  applier never globs a context string.
- README + spec §13 amended; direct-push consequence recorded.
@hyperpolymath
hyperpolymath merged commit 9b17111 into main Sep 2, 2026
35 of 37 checks passed
@hyperpolymath
hyperpolymath deleted the cicd-regularisation/step-1-canon branch September 2, 2026 11:34
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 9c89dc73-fb08-4db4-8ecc-7ea5f5cb04ad

📥 Commits

Reviewing files that changed from the base of the PR and between c51fb97 and d8be5c7.

📒 Files selected for processing (14)
  • config/README.adoc
  • config/autolinks/base.json
  • config/autolinks/elixir.json
  • config/autolinks/julia.json
  • config/autolinks/proof.json
  • config/autolinks/rust.json
  • config/rulesets/base.json
  • config/rulesets/gates-only.json
  • config/rulesets/gates.json
  • config/rulesets/immutable-tags.json
  • config/settings/actions-allowlist.json
  • config/settings/repo.json
  • docs/CICD-SIGNAL-DISCIPLINE.adoc
  • docs/superpowers/specs/2026-09-02-cicd-regularisation-design.md

📝 Summary

Summary by CodeRabbit

  • New Features

    • Added standardised repository governance for branch protection, pull requests, status checks, tag immutability, and bypass rules.
    • Added shared security and repository settings, including secret scanning, push protection, Dependabot updates, and approved GitHub Actions.
    • Added automatic links for security advisories, RFCs, ADRs, RustSec notices, and project-specific references.
    • Added workflow-based gate configuration that derives required checks from available workflow runs.
  • Documentation

    • Documented the estate-wide CI/CD standards, workflow conventions, enforcement rules, configuration decisions, and repository application order.

Walkthrough

Adds canonical repository settings, Actions permissions, autolink profiles, branch and tag rulesets, gate-context derivation rules, and supporting CI/CD governance documentation.

Changes

Estate CI/CD configuration canon

Layer / File(s) Summary
Canon contract and governance documentation
config/README.adoc, docs/CICD-SIGNAL-DISCIPLINE.adoc, docs/superpowers/specs/...
Documents the canonical configuration files, ruleset identity, gate-context derivation, bypass behaviour, apply order, workflow naming, invariants, and design amendments.
Branch, gate, and tag enforcement
config/rulesets/*
Defines branch rules, gate-only enforcement, workflow-derived required contexts, bypass actors, and immutable-tag protection.
Repository security and Actions controls
config/settings/*
Defines repository defaults, security overrides, Actions permissions, workflow permissions, vulnerability settings, and the 92-pattern allowlist.
Shared and profile-specific autolinks
config/autolinks/*
Defines shared advisory and repository-local autolinks, with Elixir, Julia, proof, and Rust profile detection and mappings.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ConfigApplier
  participant GitHubRepositoryAPI
  participant DefaultBranchWorkflow
  participant RulesetVerifier
  ConfigApplier->>GitHubRepositoryAPI: Apply repository settings and permissions
  ConfigApplier->>DefaultBranchWorkflow: Read latest default-branch check runs
  DefaultBranchWorkflow-->>ConfigApplier: Return workflow check-run names
  ConfigApplier->>GitHubRepositoryAPI: Apply derived branch and tag rulesets
  ConfigApplier->>RulesetVerifier: Verify configuration
  RulesetVerifier-->>ConfigApplier: Return verification status
Loading

Poem

I am a rabbit with configs to arrange
Branches stand firm while workflows change
Tags stay still in their tidy row
Links point where advisory breadcrumbs go
Gates check names before merges proceed
The canon now carries each rule and deed

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant