docs: document conservative PR smoke classification

This commit is contained in:
2026-09-25 09:50:25 +00:00
parent 15e9b6cd70
commit 8015f8a2ef
2 changed files with 3 additions and 3 deletions
+2 -2
View File
@@ -1,7 +1,7 @@
---
name: corp-v1-channel-uat
description: Use when validating a deployed Corp v1 environment through UAT journeys.
version: 1.1.1
version: 1.1.2
author: Hermes Agent
license: MIT
metadata:
@@ -68,7 +68,7 @@ merge to the default `test` branch
└── structured regression evidence
```
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and use the checkout credential only in the classification job to query Gitea for an open PR whose head branch and exact SHA both match. Never classify from retained `refs/pull/*` refs because Gitea keeps them after closure. Never print or persist the checkout credential, and do not pass it to validation jobs. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and compare the exact commit with Gitea pull-request head refs without exposing a broad API token to candidate-controlled code. Gitea retains those refs after closure, so an unchanged closed-PR head may conservatively receive smoke again; a new branch-only commit receives repository validation only. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.