From 28c500f47ab335b195bcaef10c2aa035908bb8ec Mon Sep 17 00:00:00 2001 From: Jared Knowles Date: Sat, 8 Aug 2026 20:20:56 -0400 Subject: [PATCH] ci: mirror main and tags to the GitHub mirror A plain non-force git push rather than Gitea's built-in push mirror. A push mirror force-updates the refs it owns, so a Merge clicked on a GitHub PR would be silently overwritten on the next sync -- the PR still reading 'Merged' while its commit became unreachable. A non-force push is rejected instead, which turns that into a red CI run. Secret is PAT_GH, not GITHUB_MIRROR_PAT: Gitea reserves the GITHUB_ and GITEA_ prefixes for its own injected variables and refuses secrets using them. --- .gitea/workflows/mirror-github.yml | 43 ++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 .gitea/workflows/mirror-github.yml diff --git a/.gitea/workflows/mirror-github.yml b/.gitea/workflows/mirror-github.yml new file mode 100644 index 0000000..69f3405 --- /dev/null +++ b/.gitea/workflows/mirror-github.yml @@ -0,0 +1,43 @@ +# Mirror the canonical Gitea repo to the public GitHub mirror. +# +# Deliberately a plain `git push`, NOT Gitea's built-in push mirror. A push +# mirror force-updates the refs it owns: if anyone ever clicks Merge on a +# GitHub PR, the next sync silently overwrites main, the PR still displays +# "Merged", the commit becomes unreachable, and nothing anywhere says so. +# A non-force push is REJECTED as non-fast-forward the moment that happens, +# turning a silent data-loss trap into a red CI run in a place we already look. +# +# Do NOT add --force here, and do NOT add GitHub branch protection to the +# mirror: protection rules block the mirror's legitimate pushes too, breaking +# normal syncing to catch an abnormal case. +# +# PAT_GH is a GitHub personal access token (repo + workflow scope; workflow is +# required because this pushes .github/workflows/). It is stored as a Gitea +# Actions secret. The name cannot begin with GITHUB_ or GITEA_ -- Gitea +# reserves both prefixes for its own injected variables and rejects the secret. +name: Mirror to GitHub + +on: + push: + branches: [main] + tags: ['v*'] + +jobs: + mirror: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Push main and tags to the GitHub mirror + env: + PAT_GH: ${{ secrets.PAT_GH }} + run: | + set -eu + if [ -z "${PAT_GH:-}" ]; then + echo "PAT_GH is unset -- add it under Settings > Actions > Secrets." >&2 + exit 1 + fi + git push "https://x-access-token:${PAT_GH}@github.com/civilytics/uscogdata.git" \ + HEAD:refs/heads/main --tags