feat(api): push signed delivery events to Kanbanger #634
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!634
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/kanbanger-notifications"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
ForgeGraph now pushes signed delivery events to Kanbanger (https://tasks.gmac.io), so an issue can show its PR updates, CI builds, evidence and attestations (including sidecar results from Veritas, PlayTrek, Preflight and others), readiness verdicts and deploys.
{ url, secret, enabled }. It is stored as aworkspace_integrationsrow with providerkanbanger.hasSecret.GET,PUTandDELETEon/api/fg/integrations/kanbanger. DELETE disables the target and keeps the URL and secret.integration.kanbangerStatus,integration.kanbangerConnect,integration.kanbangerDisable.forge integration kanbanger connect --url <url> --secret-stdin,forge integration kanbanger statusandforge integration kanbanger disable.notification_outbox, which the minute cron drains.x-kanbanger-deliverykeeps the sameeventId.cancelled.eventIdcomes from a per-event dedupe key. Webhook redeliveries collapse into one event, and so do events reported at two layers (merge route plus Forgejo merge webhook,workflow_runplus CI report).Hooked event sites
onChangesetOpened. It covers all 7 creation paths and skips default-branch and draft rows.applyBranchPush, the Forgejo push handler and the agent changeset-upsert, each when the head moves. Also the Forgejo PR webhook on opened/reopened/edited, which is when the PR link becomes known.POST /api/fg/prs/[id]/merge, the tRPCchangeset.merge, the Forgejo PR webhook (merges done in the Forgejo UI) and the merged-branch reconciler.POST /api/fg/prs/[id]/close.review.submitand the Forgejo review webhook.workflow_run(started and terminal)./api/fg/ci/report, whose summary comes from the check-events counts, e.g. "2 of 214 tests failed"./api/evidencebuild evidence.POST /api/v1/attestations, with the producer set to the sidecar name.checkAndFireReadinessWebhook, baselined on the last readiness event sent. Changesets with no work-item link are covered too./api/fg/deploys/complete(Workers CI deploys).Verification
.returning().go vetandgo test ./cmd/fg/...are green.Not done here
deploy.urlis sent only when a Control Panel callback provides one. ForgeGraph does not store a per-stage URL.🤖 Generated with Claude Code
Kanbanger (tasks.gmac.io) shows an issue's PR, CI, evidence, readiness and deploys. ForgeGraph now pushes those as signed, versioned events instead of Kanbanger polling for them. Configuration is a per-workspace `workspace_integrations` row with provider "kanbanger": the HMAC secret is the encrypted credential (FG_ENCRYPTION_KEY, same as every integration) and { url, enabled } is its metadata, so there is no schema change. Reads expose hasSecret, never the secret. Managed through GET/PUT/DELETE /api/fg/integrations/kanbanger, the integration.kanbanger* tRPC procedures, and `forge integration kanbanger connect --url --secret-stdin | status | disable`. Writes need team owner/admin. Emission only enqueues into the existing notification_outbox after the triggering write commits; it never throws and costs one query when the workspace has no enabled target (zero behaviour change). The minute cron drain signs each attempt with a fresh timestamp (sha256=HMAC(secret, "v1:" + ts + ":" + body)) while x-kanbanger-delivery stays the stable eventId. 5xx/408/429 and network errors retry with the outbox backoff; other 4xx, or a disabled/removed target, end the row. eventIds derive from a per-event dedupe key, so webhook redeliveries and layered sites (merge route + Forgejo merge webhook, workflow_run + ci report) collapse onto one event. Hooked: changeset opened/updated/merged/closed (lifecycle, branch push, Forgejo push/PR webhooks, agent upsert/merge-report, PR merge/close routes, tRPC merge, merged-branch reconciler); reviews (tRPC + Forgejo webhook); builds (Forgejo workflow_run, CI report, agent ci-report, evidence API); attestations (sidecar POST /api/v1/attestations with producer name, rule engine, push invalidation, waivers, timeout cron); readiness.changed (from the readiness check, baselined on the last event sent so unlinked changesets work too); deploys (agent deploy report, CI deploy completion, Control Panel callbacks, dispatch failure). Evidence: api unit 1316 + new 20 (incl. the shared signature vector), api database lane 37 files / 264 tests plus 12 new Kanbanger DB tests (enqueue, dedupe, disabled => nothing, retry/terminal/cancel, re-signing), api concurrency and web database lanes green on a real Postgres, web unit lanes green, api + web typecheck clean, oxlint clean (warnings only), go vet + go test ./cmd/fg/... green. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>