docs(tekton): a PR red your diff cannot reach is INHERITED β measured 3x in one session, on 3 legs - #1183
Open
ZacxDev wants to merge 1 commit into
Open
docs(tekton): a PR red your diff cannot reach is INHERITED β measured 3x in one session, on 3 legs#1183ZacxDev wants to merge 1 commit into
ZacxDev wants to merge 1 commit into
Conversation
β¦ 3x in one session, on 3 legs
Routed here by /handoff step 4: the subsystem-index windows came back no-match
(the work landed as PRs from throwaway worktrees, and the nominated slug was a
generic `scripts`), so the durable lesson belongs in the skill that owns the
gate rather than in a per-topic handoff doc that gets overwritten.
All three on ZacxDev/homelab-infra, 2026-08-31:
gitleaks docs-only diff; TRUNK ITSELF had been red ~5h since e097d136 on
another session's handoff QUOTING `password: "changeme-..."`.
Fixed by #598 -- a rule-scoped [[rules.allowlists]] exempting
^claudedocs/ from unrotated-template-default ONLY (global
[[allowlists]] paths would exempt the file under EVERY rule)
sops-rules `rule count DROPPED: 33 -> 32` naming a rule the branch never
touched -- trunk ADDED it after the branch point
scripts-tests docs-only diff; trunk was broken and c902cdd5 fixed it after
branching
The tell is constant: a failing leg the diff cannot touch. The control is
base-vs-branch -- run the leg against origin/trunk and compare. Then REBASE.
Also records two things that cost real time:
* trunk can be red for HOURS while every open PR looks green, because they all
branched earlier. A green PR is evidence about its branch point, not trunk
* `gh pr checks` says "no checks reported" for a PR with a PASSING commit
status -- Tekton posts a legacy status, not a check-run
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UGspsNfAdDqeD74yFvYzDa
Claude-Session-Id: f1f6b2ed-d8ca-4830-b379-5e19f7222460
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Routed here by
/handoffstep 4. The subsystem-index windows returnedno-match(the work landed as PRs authored in throwaway worktrees, and the only nomination was a genericscriptsslug covering two unrelated paths), so the durable lesson belongs in the skill that owns the gate rather than in a per-topic handoff doc that gets overwritten.Measured three times in one session, on three different legs
All on
ZacxDev/homelab-infra, 2026-08-31:gitleakse097d136, on another session's handoff quotingpassword: "changeme-clickhouse-password"sops-rulesrule count DROPPED: 33 β 32, naming a rule the branch never touched β trunk added it after the branch pointscripts-testsc902cdd5("unbreak trunk CI") fixed it after branchingThe tell is constant: a failing leg your diff cannot touch. The control is base-vs-branch β run the same leg against
origin/trunkand compare; identical output proves the red is not yours. Then rebase; don't debug the leg.Two things that cost real time
gh pr checksreports "no checks reported" for a PR with a passing commit status β Tekton posts a legacy status, not a check-run. Usegh api repos/<o>/<r>/commits/<sha>/status.The gitleaks instance was fixed in
homelab-infra#598with a rule-scoped[[rules.allowlists]]exempting^claudedocs/fromunrotated-template-defaultonly β a global[[allowlists]]pathsentry would have exempted those files under every rule.π€ Generated with Claude Code
https://claude.ai/code/session_01UGspsNfAdDqeD74yFvYzDa