Push mirroring: push repos to an upstream (password/token/SSH-key auth, keypair generation) with on-push + optional scheduled sync #623
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#623
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What's requested
Push mirroring for repositories: walhub should be able to push a repository's refs (and objects) to a remote upstream — so walhub can be the primary and a Forgejo/GitHub mirror or personal backup host receives the pushes. This complements the existing pull mirror (
internal/mirror), which today only fetches FROM an upstream and refuses pushes (IsMirrorininternal/mirror/mirror.go).Configured post-hoc only, in repo Settings — never at create or import time (mirroring a repo's destination is a lifecycle decision made after the repo exists, matching how the pull mirror is configured).
Auth support (all three, per-mirror choice)
Credentials must never be echoed back in full after save (write-only fields; show presence/last-4-style confirmation instead) and must never appear in
last_resulterror strings (the existing mirror doc scrubs failures — keep that contract).Sync triggers
(repo, kind)single-flight task machinery ininternal/wal/tasks.gocomposes here; a task kind distinct from pullmirror-sync, e.g.mirror-push-sync).internal/mirror/mirror.gopresetCrons/NextFire), reusinginternal/bundle/cron.go. Default off — on-push only unless the user opts into a schedule.Evidence / current state
internal/mirror/mirror.go—MirrorDoc(upstream_url, schedule, last_result, consecutive_failures) andIsMirrorpush-refusal probe; sidecar precedent atmeta/mirror.json.internal/mirror/sync.go— pull-direction sync; comment at line 434 notes server-side publish bypasses the push funnel.POST /api/v1/repos/mirrors,New.jsxmirror-create mode,summary.mirrorprojection).Architecture notes
internal/bundle/cron.go),(repo, kind)task single-flight (internal/wal/tasks.go), sidecar doc pattern (internal/mirrorLoad/store.MirrorKey), separate-cadence loop pattern (internal/maintain/follow.go).meta/pushmirror.json) or an extended mirror doc — planner's call; keep pull and push mirror configs independent so either can exist alone.access.json/meta/placeholder.json) — planner's call on storage shape and what redaction applies.internal/mirror/sync.go:434) does NOT accidentally fan out push-mirror syncs.git push --mirror-style ref+object transfer over the git transport; consider what happens with walhub's manifest-store refs vs forge git refs (refs live in the manifest store, not forge git refs — the sync must push what the store publishes, matching the pull direction's ref reconstruction).internal/api/routes.go: template/api/v1/…,api-browser/v1,services/api).web/src/pages/).Acceptance criteria
make cover, 95% per-package floor) for new/changed packages.Fixed by #624 (merged): push mirroring with on-push fan-out + optional schedule (password/token/SSH provided-or-generated via stdlib ed25519, git-push subprocess, sidecar secrets with redaction, summary ETag, independent pull/push). Review fixed pre-merge: scoped refspecs (no forge-ref leak), shell-injection via username, keygen/update guards, ETag gaps. Rendered verification attached on the PR (headless Chromium desktop + 390px, zero console errors; live file:// on-push sync confirmed). Coverage gates green. TOFU persistence tracked as #625.