Prune GitHub Environments left behind by PR envs - #69
Merged
Merged
Conversation
Each anchor repo's deploy job runs in a pr-<repo>-<N> GitHub Environment, which GitHub creates on first use and never removes. An hourly job now deletes the ones whose PR is closed or no longer carries the deploy label, the same test the PR-env ApplicationSet applies. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
mindsdb-devops
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Each anchor repo's deploy job runs in a
pr-<repo>-<N>GitHub Environment. GitHub creates these on first use and never removes them, so 456 have piled up across the seven anchor repos.prune-pr-environments.ymlruns hourly and deletes each environment whose PR is closed or no longer carries thedeploylabel. That is the same test the PR-env ApplicationSet uses. It uses a release-train App token downscoped to Actions read, Environments write, and Pull requests read on the anchor repos only. Other environments (dev,staging,prod, and so on) never match the name pattern. If a repo's PR list can't be read, nothing in that repo is deleted.Before merge: the release-train App needs Environments: write added, and must be installed on all seven anchor repos. Until then the token mint fails and the notify job reports it.
Verified with a dry run against the live repos using read-only access. It found 237 stale in auth, 98 in mindshub_frontend, 58 in cowork-server, 49 in cowork, 10 in mindshub_stafftools, 3 in mindshub_inference, and 1 in mindshub_services. Every env backing an open
deployPR was kept. Tests: 8 new, 237 passed in total.Run it once by hand with
dry_runafter the App change, then without it to clear the backlog.🤖 Generated with Claude Code