From 89723c6ebde851abe353324a75232f9dab8491d9 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Wed, 12 Aug 2026 22:30:56 -0400 Subject: [PATCH] safety: disable deploy workflows on Windy Git before they can fire MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Six workflows deploy to production on push:. Windy Git now has a working runner, so the next synced commit to main would have attempted a production deploy FROM VERON 1. Their secrets are unset here so they would have failed — but loudly, on every push, with any pre-SSH step still running. All six now disabled_manually. Tests, lints and migration checks stay active: they need no secrets, which is exactly why Phase 1 delivers CI value with nothing to configure. Same class of mistake as the push-mirror direction, caught before firing this time rather than after. Co-Authored-By: Claude Opus 5 --- docs/CUTOVER.md | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/docs/CUTOVER.md b/docs/CUTOVER.md index a1aff9d..b060ee1 100644 --- a/docs/CUTOVER.md +++ b/docs/CUTOVER.md @@ -58,6 +58,26 @@ three ways, two sessions recording different HEADs hours apart. Resolve which is current and write it down before importing (G11.5). The import script refuses it by name. +## ⚠️ Deploy workflows are DISABLED on Windy Git, deliberately + +Six workflows fire on `push:` and deploy to production: +`windy-registry`, `Windy-Clone`, `WindyCloud`, `windy-mind`, `eternitas` +(`deploy.yml`) and `windy-agent` (`release.yml`). + +Windy Git now has a working runner, so the next synced commit to `main` would +have attempted a **production deploy from Veron 1**. Their secrets +(`DEPLOY_HOST` / `DEPLOY_KEY` / `VPS_SSH_KEY`) are unset here, so they would +have failed — but they would have failed *loudly on every push*, and any step +before the SSH step would still have run. + +All six are now `disabled_manually`. Tests, lints and migration checks stay +**active** — those need no secrets at all, which is why Phase 1 delivers real CI +value immediately. + +**Before re-enabling any deploy workflow here, decide deliberately whether +production should be deployable from Windy Git at all.** Kit 0 deploys are +currently manual runbooks; that is a feature, not a gap. + ## Backups `windygit-backup.timer`, nightly 04:17, `git bundle --all` + verify + `windgit`