Skip to content

ci: queue team-memory maintenance through Java Pack - #638

Merged
Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-queued-team-memory
Oct 10, 2026
Merged

Changyong Gong (chagong) merged 2 commits into
mainfrom
chagong-queued-team-memory

Conversation

@chagong

@chagong Changyong Gong (chagong) commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Workflow-only migration: replace direct team-memory maintenance in .github/workflows/team-memory-post-merge.yml with the standalone, pinned microsoft/IssueLens/.github/actions/queue-team-memory@a81d2d96167fc0e69ac631c2edc85f858e693289 dispatcher targeting microsoft/vscode-java-pack, team-memory-coordinator.yml, and independent coordinator ref main.

  • Preserve ISSUELENS_TEAM_MEMORY_ENABLED and admit only actual microsoft/java-debug default-branch pushes with matching workflow/head SHAs and created/deleted/forced flags false.
  • Mint a dedicated token using actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 (v3.2.0), scoped only to Java Pack with Contents read and Actions write; keep the source GITHUB_TOKEN permissions empty.
  • Send exactly five string inputs: source repository, run ID, run attempt, requested before SHA, and after SHA. The coordinator validates the source run/head and authorized ancestor range and owns shared-wiki serialization and maintenance. push_before is reconciliation authorization, not attested original-event provenance.
  • Remove the local manual/direct invocation path; manual merged-PR reconciliation uses the central coordinator's Run workflow with source repository and PR number. Dispatch acknowledgement does not claim maintenance completion.
  • No public documentation updates. README additions were removed at the user's request, leaving only the workflow migration. No issue-triage, Java source, build, wiki policy, receiver, or other repository changes.

Rollout prerequisites — configure before merging an enabled source

These internal setup requirements are retained only in this PR description, not repository documentation. They are not changes performed by this PR. If the existing source opt-in is true, merging immediately switches it from direct maintenance to queue dispatch.

  1. In microsoft/java-debug, configure the proposed repository variable ISSUELENS_DISPATCH_APP_CLIENT_ID and secret ISSUELENS_DISPATCH_APP_PRIVATE_KEY for a dedicated App installed only on microsoft/vscode-java-pack, with Contents read and Actions write. These names were absent from the read-only caller names listing during initial preparation. Do not reuse the hosted IssueLens App key or the central source-read App credentials.
  2. In Java Pack, configure the separate secrets ISSUELENS_SOURCE_READ_APP_CLIENT_ID and ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY for the central source-read App with Actions, Contents, and Pull requests read access to selected sources including microsoft/java-debug. The coordinator already allowlists this source, but the parent rollout investigation found both central credentials missing during initial preparation. The successful own-repository coordinator run skipped external authentication and does not establish external readiness.

The existing source opt-in is preserved; no new disabled variable, live configuration, credentials, workflow dispatch/rerun, or agent invocation was introduced or performed.

Validation

  • actionlint v1.7.12 on the migrated workflow: passed during initial preparation; the documentation-removal follow-up leaves that workflow unchanged.
  • Offline YAML and official GitHub expression evaluation: 12 admit/reject gate cases passed; exact five-string JSON payload, independent target ref, and token repository/permission scope verified.
  • Supplied action inputs checked against both immutable pinned action.yml schemas; passed.
  • Documentation-removal follow-up: README exactly matches its pre-migration content; workflow safeguards remain unchanged; git diff --check and aggregate file-scope checks confirm only .github/workflows/team-memory-post-merge.yml differs from main.
  • No live dispatch or IssueLens invocation used as a test.

Based on verified main at bcae605a6240f11b447163a614e215721c11b107.

Replace direct source maintenance with the scoped, pinned coordinator dispatcher and document independent caller and central authentication prerequisites.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the internal onboarding migration workflow-only and retain setup prerequisites in the pull request description.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@chagong
Changyong Gong (chagong) merged commit ebbe6db into main Oct 10, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants