ci(fix #350): trigger CI with the PAT (GITHUB_TOKEN dispatch needs manual approval) #351

Closed
opened 2026-07-05 18:16:40 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-05 18:16:40 +00:00 (Migrated from github.com)

#350 (merged) made the CI-trigger scheduler (ci-trigger.yml) dispatch ci.yml with the built-in GITHUB_TOKEN (gh workflow run), on the claim that workflow_dispatch is anti-recursion-exempt. In practice a GITHUB_TOKEN-triggered workflow requires MANUAL AUTHORIZATION — so auto-updated PRs sit with un-run CI pending approval (observed on #285). This is why the original #349 design used a PAT.

Fix — separation of concerns

  • ci-trigger.yml (scheduler): trigger CI with the PAT secrets.AUTOUPDATE_TOKEN (not GITHUB_TOKEN). A PAT-triggered run runs as the authorized owner → no approval gate.
  • autoupdate.yml: keep the branch UPDATE on GITHUB_TOKEN (unchanged — update must NOT retrigger; that kills the cascade).
    So: updates = GITHUB_TOKEN, triggering = PAT, cleanly separated.

Do

  • ci-trigger.yml: change the trigger step GH_TOKEN from ${{ github.token }} to ${{ secrets.AUTOUPDATE_TOKEN }} (AUTOUPDATE_TOKEN already exists — #350 left it unused; re-use it). Fail-open if the secret is absent.
  • Fix the now-wrong "no PAT needed / workflow_dispatch exempt" comments in ci-trigger.yml + docs.
  • Keep autoupdate.yml on GITHUB_TOKEN.
  • Validate: YAML parse; traffic-control unit tests still pass.

P2 — blocks auto-updated PRs' CI. Coordinator reviews before arming (core CI flow).

#350 (merged) made the CI-trigger scheduler (`ci-trigger.yml`) dispatch `ci.yml` with the built-in **GITHUB_TOKEN** (`gh workflow run`), on the claim that `workflow_dispatch` is anti-recursion-exempt. In practice a **GITHUB_TOKEN-triggered workflow requires MANUAL AUTHORIZATION** — so auto-updated PRs sit with un-run CI pending approval (observed on #285). This is why the original #349 design used a PAT. ## Fix — separation of concerns - **`ci-trigger.yml` (scheduler): trigger CI with the PAT** `secrets.AUTOUPDATE_TOKEN` (not GITHUB_TOKEN). A PAT-triggered run runs as the authorized owner → no approval gate. - **`autoupdate.yml`: keep the branch UPDATE on GITHUB_TOKEN** (unchanged — update must NOT retrigger; that kills the cascade). So: **updates = GITHUB_TOKEN, triggering = PAT**, cleanly separated. ## Do - `ci-trigger.yml`: change the trigger step `GH_TOKEN` from `${{ github.token }}` to `${{ secrets.AUTOUPDATE_TOKEN }}` (AUTOUPDATE_TOKEN already exists — #350 left it unused; re-use it). Fail-open if the secret is absent. - Fix the now-wrong "no PAT needed / workflow_dispatch exempt" comments in `ci-trigger.yml` + docs. - Keep `autoupdate.yml` on GITHUB_TOKEN. - Validate: YAML parse; traffic-control unit tests still pass. P2 — blocks auto-updated PRs' CI. Coordinator reviews before arming (core CI flow).
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#351