scripts: add onboard-product.sh, teach doctor-channels.sh to check signing secrets
breadcast shipped with a full bakery.toml + CI workflows but was missing from registry/bread-ecosystem.toml and had zero Forgejo Actions secrets configured, so its release workflows would have failed closed (or worse, published unsigned on an older workflow shape) the first time they ran. Neither gap was visible until checked by hand. doctor-channels.sh now also flags any registry product's repo missing the BAKERY_MINISIGN_SEC_KEY_PATH secret (soft-skipped without a local Forgejo token). onboard-product.sh handles the one genuine write step — adding a [[products]] entry — then runs doctor-channels.sh so nothing else gets missed silently again. Also fixes a pre-existing false positive where the local-checkout drift scan didn't recognize worktree checkouts of bread-ecosystem itself beyond the one literal "-fix-worktree" suffix it special-cased.
This commit is contained in:
parent
227247907b
commit
a4f0c96b90
2 changed files with 117 additions and 2 deletions
52
scripts/onboard-product.sh
Executable file
52
scripts/onboard-product.sh
Executable file
|
|
@ -0,0 +1,52 @@
|
|||
#!/usr/bin/env bash
|
||||
# onboard-product.sh — register a new product in registry/bread-ecosystem.toml.
|
||||
#
|
||||
# This is the one step in bringing a product under bakery that's a genuine
|
||||
# write action; everything else (bakery.toml, CI workflows, the
|
||||
# BAKERY_MINISIGN_SEC_KEY_PATH Actions secret) is either copied from an
|
||||
# existing product repo or diagnosed by scripts/doctor-channels.sh, which
|
||||
# this script runs at the end so nothing gets missed the way breadcast's
|
||||
# missing secret did.
|
||||
#
|
||||
# Usage:
|
||||
# scripts/onboard-product.sh <name> <owner/repo> <description>
|
||||
#
|
||||
# Example:
|
||||
# scripts/onboard-product.sh breadcast Breadway/breadcast \
|
||||
# "Cast your screen to any Chromecast/Google TV or DLNA renderer — daemon + GTK4 popup"
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
if [[ $# -ne 3 ]]; then
|
||||
echo "usage: $0 <name> <owner/repo> <description>" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
NAME="$1"
|
||||
REPO="$2"
|
||||
DESCRIPTION="$3"
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
REGISTRY="${SCRIPT_DIR}/registry/bread-ecosystem.toml"
|
||||
|
||||
if python3 -c "
|
||||
import tomllib, sys
|
||||
with open('${REGISTRY}', 'rb') as f:
|
||||
d = tomllib.load(f)
|
||||
sys.exit(0 if any(p['name'] == '${NAME}' for p in d['products']) else 1)
|
||||
"; then
|
||||
echo "${NAME} is already registered in ${REGISTRY}, skipping"
|
||||
else
|
||||
cat >> "${REGISTRY}" <<EOF
|
||||
|
||||
[[products]]
|
||||
name = "${NAME}"
|
||||
repo = "${REPO}"
|
||||
description = "${DESCRIPTION}"
|
||||
EOF
|
||||
echo "added ${NAME} (${REPO}) to ${REGISTRY}"
|
||||
fi
|
||||
|
||||
echo
|
||||
echo "running doctor-channels.sh to check bakery.toml / CI workflows / signing secret are all in place for ${NAME}..."
|
||||
bash "${SCRIPT_DIR}/scripts/doctor-channels.sh" || true
|
||||
Loading…
Add table
Add a link
Reference in a new issue