docs: document conservative PR smoke classification
This commit was merged in pull request #3.
This commit is contained in:
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
name: corp-v1-channel-uat
|
name: corp-v1-channel-uat
|
||||||
description: Use when validating a deployed Corp v1 environment through UAT journeys.
|
description: Use when validating a deployed Corp v1 environment through UAT journeys.
|
||||||
version: 1.1.1
|
version: 1.1.2
|
||||||
author: Hermes Agent
|
author: Hermes Agent
|
||||||
license: MIT
|
license: MIT
|
||||||
metadata:
|
metadata:
|
||||||
@@ -68,7 +68,7 @@ merge to the default `test` branch
|
|||||||
└── structured regression evidence
|
└── structured regression evidence
|
||||||
```
|
```
|
||||||
|
|
||||||
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and use the checkout credential only in the classification job to query Gitea for an open PR whose head branch and exact SHA both match. Never classify from retained `refs/pull/*` refs because Gitea keeps them after closure. Never print or persist the checkout credential, and do not pass it to validation jobs. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
|
Use one change workflow for both pre-PR branches and PR heads. A PR-open or PR-reopen event adds the first smoke-bearing run. Do not subscribe that workflow to `pull_request.synchronize`; later branch pushes are the single trigger and compare the exact commit with Gitea pull-request head refs without exposing a broad API token to candidate-controlled code. Gitea retains those refs after closure, so an unchanged closed-PR head may conservatively receive smoke again; a new branch-only commit receives repository validation only. Cancel superseded change runs for the same branch. Never run full regression on a PR, and never treat smoke as complete UAT.
|
||||||
|
|
||||||
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.
|
Integrated regression runs only for exact commits pushed to `test`; they queue rather than cancel one another so every merged commit receives a result. This automatic run proves the integrated journey set against the configured non-production URL but does not issue `UAT_PASSED`. A release-facing UAT verdict requires a separately frozen Delivery handoff plus pre-run and post-run live verification of application commit, image digests, deployable GitOps commit, Argo CD revision/sync/health, environment, and base URL. Neither workflow deploys or publishes application artifacts.
|
||||||
|
|
||||||
|
|||||||
@@ -51,6 +51,6 @@ push to test after merge
|
|||||||
└── structured regression evidence upload
|
└── structured regression evidence upload
|
||||||
```
|
```
|
||||||
|
|
||||||
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The classification job queries Gitea using the checkout credential held only in memory and requires both the open PR head branch and exact SHA to match. Never infer open state from retained pull-request refs. Cancel superseded change runs for the same branch and expose one required aggregate result.
|
Use one change workflow rather than separate branch and PR workflow files. It subscribes to non-default `push` plus `pull_request` `opened` and `reopened`, but not `synchronize`; later branch pushes are the single trigger. The classification job compares the exact commit with Gitea pull-request head refs without exposing a broad API token to candidate-controlled code. Because Gitea retains those refs after closure, an unchanged closed-PR head may conservatively receive smoke again; a new branch-only commit receives repository validation only. Cancel superseded change runs for the same branch and expose one required aggregate result.
|
||||||
|
|
||||||
The integrated workflow runs only on `push` to `test` and queues instead of cancelling older integrated commits. It requires an explicit non-production base URL and runtime-only authentication when the regression set requires it. Its artifacts are integrated regression evidence, not a release-facing UAT verdict. `UAT_PASSED` additionally requires the project UAT procedure to verify the immutable Delivery deployment tuple live before and after the run. Smoke is not complete UAT, and full regression does not run on a PR.
|
The integrated workflow runs only on `push` to `test` and queues instead of cancelling older integrated commits. It requires an explicit non-production base URL and runtime-only authentication when the regression set requires it. Its artifacts are integrated regression evidence, not a release-facing UAT verdict. `UAT_PASSED` additionally requires the project UAT procedure to verify the immutable Delivery deployment tuple live before and after the run. Smoke is not complete UAT, and full regression does not run on a PR.
|
||||||
|
|||||||
Reference in New Issue
Block a user