Skip to content

feat: enable guarded webhook canary ingestion - #233

Open
giscebot wants to merge 1 commit into
mainfrom
feat/webhooks-canary-ingest
Open

giscebot wants to merge 1 commit into
mainfrom
feat/webhooks-canary-ingest

Conversation

@giscebot

@giscebot giscebot commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • add canary webhook mode backed by the existing policy file
  • enqueue only supported actionable deliveries for repositories explicitly listed in enabledRepos
  • translate signed structured payloads into the common transport-neutral queue
  • preserve first-writer-wins idempotency across webhook and IMAP
  • document the durable ordering and recovery behavior

Safety boundary

Shadow remains the default. Canary fails closed without a policy file, an empty enabledRepos enqueues nothing, edited/unsupported deliveries remain observational, and IMAP continues unchanged.

The queue transaction commits before the monitoring receipt. A crash in that narrow gap cannot lose work: GitHub retries the delivery, the webhook receipt key deduplicates the queue operation, and the retry repairs monitoring.

Dependency

Stacked on #232 so operators can measure the canary before enabling it.

Validation

  • pytest -q — 392 passed on the complete stack
  • dashboard npm test -- --run — 60 passed
  • dashboard npm run build — passed

Requested by: @ecarreras

Refs #191

TASK-85718

@giscebot
giscebot added this pull request to stack #235 October 3, 2026 10:22
@giscebot
giscebot requested a review from ecarreras October 3, 2026 10:23
@giscebot giscebot self-assigned this Oct 3, 2026
@giscebot
giscebot force-pushed the feat/webhooks-canary-ingest branch 2 times, most recently from 7eeeefd to c826166 Compare October 3, 2026 13:54
Base automatically changed from feat/webhooks-coverage-gate to main October 3, 2026 13:58
Co-authored-by: Eduard Carreras <ecarreras@gisce.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant