From 30b8f0d04d9ce21a4ec3d2568eb1bf4c940db92d Mon Sep 17 00:00:00 2001 From: sync-test Date: Mon, 13 Jul 2026 22:01:41 +0530 Subject: [PATCH] fix(ci): make sync-to-forgejo tolerate Forgejo-only commits Flux's ImageUpdateAutomation commits directly to Forgejo (the GitRepository it actually watches), so Forgejo routinely has commits GitHub never sees. The previous rebase-then-push assumed Forgejo was always a fast-forward of GitHub; once that stopped being true the rebase failed on every run and silently stalled all deploys for three days (fixed manually in the prior commit). Switch to a merge that favors GitHub's content on conflict (-X ours) and only pushes the merge commit to Forgejo, leaving GitHub's branch untouched. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/sync-to-forgejo.yml | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sync-to-forgejo.yml b/.github/workflows/sync-to-forgejo.yml index a7e7fe8..eb63e2c 100644 --- a/.github/workflows/sync-to-forgejo.yml +++ b/.github/workflows/sync-to-forgejo.yml @@ -39,8 +39,27 @@ jobs: git remote add forgejo "$REMOTE_URL" 2>/dev/null || git remote set-url forgejo "$REMOTE_URL" git fetch forgejo "$BRANCH" || true + + # This repo isn't a plain mirror: FluxCD's ImageUpdateAutomation + # commits directly to Forgejo (the GitRepository Flux actually + # watches), so Forgejo routinely has commits GitHub never sees. + # A rebase here assumes Forgejo is always a fast-forward of + # GitHub, which breaks the moment Flux has pushed anything - and + # once one run fails, every run after it fails the same way, + # silently stalling all deploys until someone notices and + # reconciles history by hand. + # + # Merge instead. GitHub is the source of truth for human/CI + # content, so conflicting hunks resolve in its favor (-X ours), + # but Flux's commits are kept as merge ancestors rather than + # discarded. The merge commit is only pushed to Forgejo - GitHub's + # branch is left untouched - so this repeats cleanly next run + # instead of accumulating rewritten history on GitHub. if git show-ref --verify --quiet "refs/remotes/forgejo/$BRANCH"; then - git rebase "refs/remotes/forgejo/$BRANCH" + if ! git merge -X ours --no-edit "refs/remotes/forgejo/$BRANCH"; then + echo "::error::Merge with Forgejo's $BRANCH has conflicts -X ours could not resolve; manual reconciliation needed." >&2 + exit 1 + fi fi git push forgejo "HEAD:$BRANCH"