docs(quick-260613-fp9): .gitea/.planning pushes should not trigger a docker image publish
CI / changes (pull_request) Successful in 2s
CI / fast-checks (pull_request) Successful in 1m24s
CI / api (pull_request) Successful in 1m0s
CI / harness (pull_request) Successful in 3m53s
CI / security (pull_request) Successful in 39s
CI / gate (pull_request) Successful in 1s

This commit is contained in:
Lucas Berger
2026-06-13 11:22:16 -04:00
parent cd5a88c8a2
commit 4d4ffad059
3 changed files with 125 additions and 1 deletions
@@ -0,0 +1,62 @@
---
quick_id: 260613-fp9
title: ".gitea and .planning pushes should not trigger a docker image publish"
status: ready
---
# Quick Task 260613-fp9: Skip Docker publish for `.gitea`/`.planning`-only pushes
## Problem
`.gitea/workflows/publish.yml` triggers on every `push` to `main` with no path
filter. Two classes of push currently fire a full Docker build + publish that
produce an identical image:
- `.planning/**`-only commits, which push straight to `main` (the `.planning/*`
branch-protection pattern is unprotected).
- `.gitea/**`-only changes (CI/workflow edits) merged via PR.
Neither changes the shipped artifact — `.dockerignore` already excludes
`.planning` (and `apps/api/tests`) from the image — so the rebuild is wasted
runner time and a needless `:latest` re-push / new `:vMILESTONE-<sha>` tag.
## Change
Add a `paths-ignore` filter to the `push` trigger in `publish.yml`:
```yaml
on:
push:
branches: [main]
paths-ignore:
- '.gitea/**'
- '.planning/**'
```
Gitea Actions follows GitHub-compatible workflow syntax (the repo already relies
on the native `branches:` push filter). When every file changed in a push to
`main` matches a `paths-ignore` glob, the `publish` job is skipped. A push that
also touches code/Dockerfile/manifests still triggers publish — correct.
Also update the header comment block to document the new skip behavior.
## Tasks
1. **Edit `.gitea/workflows/publish.yml`**
- files: `.gitea/workflows/publish.yml`
- action: Add `paths-ignore: ['.gitea/**', '.planning/**']` under `on.push`;
update the top-of-file `# Trigger:` comment to note doc/CI-only pushes skip.
- verify: `paths-ignore` present under `on.push`; YAML still parses; the
existing `--target production` self-assertion grep still matches.
- done: pushes touching only `.gitea/**` and/or `.planning/**` no longer
trigger the publish job; mixed pushes (code + docs) still publish.
## must_haves
- truths:
- publish.yml `on.push` carries a `paths-ignore` listing `.gitea/**` and `.planning/**`
- `branches: [main]` is retained
- artifacts:
- `.gitea/workflows/publish.yml`
- key_links:
- `.gitea/workflows/publish.yml`
@@ -0,0 +1,61 @@
---
quick_id: 260613-fp9
title: ".gitea and .planning pushes should not trigger a docker image publish"
status: complete
date: 2026-06-13
---
# Quick Task 260613-fp9 — Summary
## What changed
Added a `paths-ignore` filter to the `push` trigger in
`.gitea/workflows/publish.yml`:
```yaml
on:
push:
branches: [main]
paths-ignore:
- '.gitea/**'
- '.planning/**'
```
Updated the file's header comment to document the new skip behavior.
## Why
Every push to `main` previously ran a full Docker build + push. Pushes confined
to `.planning/**` (planning docs push straight to main under the unprotected
`.planning/*` branch-protection pattern) or `.gitea/**` (CI/workflow edits) never
change the shipped image — `.dockerignore` already excludes `.planning`. The
rebuild and `:latest` re-push were wasted runner time.
## Behavior
- Push touching only `.gitea/**` and/or `.planning/**``publish` job skipped.
- Push touching code / Dockerfile / manifests (alone or mixed with docs) →
`publish` runs as before. `paths-ignore` skips only when **every** changed
file matches a glob.
## Verification
- `python3 yaml.safe_load` parses the file; `on.push` carries both
`branches: [main]` and `paths-ignore: ['.gitea/**', '.planning/**']`; the
`publish` job is intact.
- The in-workflow `grep "--target production"` self-assertion still matches
(D-10 hygiene check unaffected).
## Isolation note
Executed in a dedicated worktree (`familysync-wt-fp9`, branch
`quick/260613-fp9-publish-paths-ignore` off `origin/main`) because a concurrent
phase-10 agent has the main working tree checked out on
`gsd/phase-10-admin-role-settings`. No subagents spawned — trivial single-file
config edit done inline.
## Follow-up
`publish.yml` lives under `.gitea/**`, so merging this change will itself be a
`.gitea`-only push and will (correctly) not publish. Open a PR to `main`
(protected; code changes require PR).