Protect main branch of recipes #777
Closed
opened 2026-02-16 11:24:00 +00:00 by benjaminlyng
·
1 comment
No Branch/Tag Specified
main
local-integration-testing
renovate/otel-weaver-0.x
renovate/codespell-2.x
renovate/github.com-charmbracelet-lipgloss-2.x
renovate/github.com-charmbracelet-bubbletea-2.x
renovate/tonistiigi-xx-1.x
renovate/alpine-3.x
renovate/github.com-charmbracelet-log-2.x
chore-deps
fix/492
fix/deps
fix/613
0.13.0-beta
0.13.0-rc2-beta
0.13.0-rc1-beta
0.12.0-beta
0.11.0-beta
0.10.1-beta
0.10.0-beta
0.10.0-rc2-beta
0.10.0-rc1-beta
0.9.0-beta
0.8.1-beta
0.8.0-beta
0.8.0-rc2-beta
0.8.0-rc1-beta
0.7.0-beta
0.7.0-rc3-beta
0.7.0-rc2-beta
0.6.0-beta
0.5.1-beta
0.5.0-alpha
0.4.1-alpha
0.4.0-alpha
0.4.0-alpha-rc8
0.4.0-alpha-rc7
0.4.0-alpha-rc6
0.4.0-alpha-rc5
0.4.0-alpha-rc4
0.4.0-alpha-rc3
0.4.0-alpha-rc2
0.4.0-alpha-rc1
0.3.1-alpha-rc2
0.3.1-alpha-rc1
0.3.1-rc1
0.3.0-alpha
0.2.2-alpha
0.2.1-alpha
0.2.0-alpha
0.1.8-alpha
0.1.7-alpha
0.1.6-alpha
0.1.5-alpha
0.1.4-alpha
0.1.3-alpha
0.1.2-alpha
0.1.1-alpha
0.1.0-alpha
10.0.5
10.0.3
10.0.2
10.0.1
10.0.0
9.0.0
8.0.1
8.0.0
0.7.4
0.7.3
0.7.2
0.7.1
0.7.0
checkout
0.6.0
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
0.1.2
0.1.1
0.1.0
Labels
Clear labels
bug
build
ci/cd
critical fix
design
documentation
duplicate
easy-first-issue
enhancement
help wanted
i10n
i18n
installer
invalid
question
release
release-candidate
security
tech-debt
test
wontfix
Something is not working
go build related issues
Building things with CI/CD
https://docs.coopcloud.tech/federation/resolutions/passed/010/
UI/UX
Documenting all the things
This issue or pull request already exists
Something for new people to get stuck into. We hope it's easy!
New feature
Need some help
Everything to do with localisation
Everything to do with internationalisation
Everything to do with the install script.
Something is wrong
More information is needed
Release management
Related to the new release candidate
Security related
Unit/integration testing
This won't be fixed
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
3wordchant
aadil (Aadil Ayub)
abra-bot (Abra Bot)
ammaratef45
amras (Sarma)
Apfelwurm
BornDeleuze
Brooke
carla
cas (Cassowary)
coopcloud
cyrnel
decentral1se (d1)
dede
devydave
fauno (fauno)
iexos
jade (Jade Ambrose)
jjsfunhouse
jmakdah2 (Jackie Makdah)
joe-irving (Joe Irving)
kawaiipunk (KawaiiPunk)
knoflook
kolaente
lambdabundesverband
linnealovespie (April)
moosemower
moritz
notplants
oxaliq (sorrel)
p4u1
pharaohgraphy (Andrew 🐦🔥❤️🔥✴️)
renovate-bot (Comrade Renovate Bot)
ripclap
simon
sixsmith (Sixsmith)
stevensting
trav
val (val (he/him))
yksflip
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: toolshed/abra#777
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Upgrading recipes requires pushing new commits and tags directly to the main branch of the repository. This is risky and it requires enormous trust in maintainers. The risk is somewhat reduced by automating the procedure with
abra, but it would be even better to protect the main branches of recipes. The way I imagine upgrades with protected main-branches is to push new commits to feature-branches, require maintainer approvals before merges and then handle creation of tags in pipelines.Requirements:
--chaosflag?)abratoday.This could also potentially make the renovate bot extremely powerful, as new upgrades would just require merging it's MRs (after testing the feature-branch of course).
I realize this requires a change to every recipe repo, but it should be possible to change one at a time by just including a pipeline template. It would change the workflow for every maintainer using coopcloud so it has to be discussed thoroughly before implementing!
hey @benjaminlyng, thanks for opening this and sharing your thoughts.
You're on the right track, and your initiative is very welcome. We recently wrote https://docs.coopcloud.tech/maintainers/maintain/ together after some of us met at CCC in germany. This was a follow-up of https://docs.coopcloud.tech/federation/resolutions/passed/025/ which was voted on.
There has been a serious amount of collective discussion on this topic in the last few months.
The TLDR; is to reduce the chaos of upgrades through encouraging more maintainers to get involved on specific recipes they maintain. You'll see in https://docs.coopcloud.tech/maintainers/maintain/#repository-permissions that the main branch does get protected. This will reduce the worst of the "push to main" praxis we've had for several years which is now becoming untenable due to increasing participation (a great problem to have).
I would recommend you consider joining the federation and/or becoming a recipe maintainer and getting involved via that route. If you want to discuss specific concrete things that maintainers can implement, I'd ask first in the matrix channels and then if it sees traction, raise a broader issue on https://git.coopcloud.tech/toolshed/organising/issues. This could then be integrated into the
MAINTENANCE.mdagreements that each maintainer agrees to honour.This issue isn't specifically about
abraand concerns broader issues, so I will close it here. If you're looking for more discussion on howabra recipe releaseshould improve, that'd be over here: toolshed/organising#663.I hoep that is clear, thanks!