fix(docs): scaffolded apps publish their docs, and drop dead docs ignore rules - #190
Merged
Merged
Conversation
The /website/ and /docusaurus/ rules date from before the docs moved to docs/. Every app scaffolded from this template inherits them; none of the 21 fleet apps has either folder. The docs/ rules below them stay. CONTRIBUTING no longer offers docusaurus/ as a docs location.
rubenvdlinde
requested review from
Rem-Dam,
SudoThijn,
WilcoLouwerse,
bbrands02,
remko48 and
rjzondervan
as code owners
September 28, 2026 05:32
Contributor
Quality Report — ConductionNL/nextcloud-app-template @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-specs | ✅ | ||||
| check-manifest | ✅ | ||||
| format | ✅ | ||||
| composer | ✅ | ✅ 103/103 | |||
| npm | ✅ | ✅ 737/737 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ✅ | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ❌ |
Quality workflow — 2026-09-28 05:37 UTC
Download the full PDF report from the workflow artifacts.
The template's documentation.yml listened on a `documentation` branch and
passed no secrets, so every app scaffolded from it inherited a docs
pipeline that never ran, and would have skipped publishing if it had.
The fleet apps were each fixed by hand; the template never was.
Now it matches the fleet: triggers on development, maps CF_API_TOKEN and
CF_ACCOUNT_ID, pins worker-name and lists docs-hosts. app-create's
app-template -> {APP_ID} substitution turns these into the new app's
host and worker.
The template itself must not publish: the org secrets reach it, and the
deploy registers each host as a Cloudflare custom domain. The secrets
are passed only when the repository is not a template (is_template),
which survives the scaffold's repository-name rewrite. The template
still builds and validates its docs.
This reverses #38 (2026-05-13), which chose the documentation branch so
docs could deploy separately from code. Across the fleet nobody pushed
to that branch after 2026-05-25 and the sites went stale.
Contributor
Quality Report — ConductionNL/nextcloud-app-template @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-specs | ✅ | ||||
| check-manifest | ✅ | ||||
| format | ✅ | ||||
| composer | ✅ | ✅ 103/103 | |||
| npm | ✅ | ✅ 737/737 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ✅ | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ❌ |
Quality workflow — 2026-09-28 05:50 UTC
Download the full PDF report from the workflow artifacts.
The lock pinned @conduction/docusaurus-preset 3.10.0 against a ^3.12.0 range, so npm ci refused to install. Nothing noticed because the docs workflow listened on a branch nobody pushed to; the development trigger in the previous commit ran it for the first time. Resolved to 3.52.0. npm ci and npm run build pass locally, including all 8 AI-baseline checks.
Contributor
Quality Report — ConductionNL/nextcloud-app-template @
|
| Check | PHP | Vue | Security | License | Tests |
|---|---|---|---|---|---|
| lint | ✅ | ||||
| phpcs | ✅ | ||||
| phpmd | ✅ | ||||
| psalm | ✅ | ||||
| phpstan | ✅ | ||||
| phpmetrics | ✅ | ||||
| eslint | ✅ | ||||
| stylelint | ✅ | ||||
| build | ✅ | ||||
| check-specs | ✅ | ||||
| check-manifest | ✅ | ||||
| format | ✅ | ||||
| composer | ✅ | ✅ 103/103 | |||
| npm | ✅ | ✅ 737/737 | |||
| app:check-code | ⏭️ | ||||
| info.xml | ✅ | ||||
| REUSE | ❌ | ||||
| lockfile sync | ✅ | ||||
| PHPUnit | ✅ | ||||
| Newman | ✅ | ||||
| Playwright | ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test. |
||||
| Hydra gates | ❌ |
Quality workflow — 2026-09-28 07:13 UTC
Download the full PDF report from the workflow artifacts.
rubenvdlinde
added a commit
that referenced
this pull request
Sep 28, 2026
After #190 the secrets guard worked: run 36390914494 skipped the Cloudflare publish and no app-template.conduction.nl record exists. But the shared workflow's "Verify the LIVE site" step then failed the run, as it does for any skipped publish, so every docs push to the template went red. In the template, pushes now skip the job. Pull requests still run it, and there the shared workflow only builds and validates. Scaffolded apps are not templates, so they run every push as before. The secrets guard stays as a second line of defence.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits, both about the docs site that new apps inherit from this template.
1. New apps' docs actually publish
documentation.ymllistened on adocumentationbranch and passed no secrets. Every app scaffolded from the template got a docs pipeline that never ran. Had it run, the publish step would have skipped, because it received no Cloudflare credentials. The fleet apps were each fixed by hand. The template never was.It now matches the fleet callers (planninq, humaniq, versioniq):
developmentCF_API_TOKENandCF_ACCOUNT_IDworker-nameand listsdocs-hostsapp-create's
app-templateto{APP_ID}substitution turns these into the new app's host ({APP_ID}.conduction.nl) and worker ({APP_ID}-docs).The template itself does not publish. The org
CF_*secrets are visible to every repo, this one included, and the deploy registers each host as a Cloudflare custom domain. So one push here would put a liveapp-template.conduction.nlonline. The secrets are passed only whengithub.event.repository.is_templateis false. The check deliberately avoids the repository name: app-create rewritesConductionNL/nextcloud-app-templateinto the new app's repo, which would turn publishing off in every new app. The template still builds and validates its docs on every run.This reverses #38 (2026-05-13), which chose the
documentationbranch so docs could deploy independently of code. Across the fleet nobody pushed to that branch after 2026-05-25, and the sites went stale. This repo has nodocumentationbranch either.2. Dead ignore rules
/website/*and/docusaurus/*rules from.gitignore. Docs live indocs/, and none of the 21 fleet apps has either folder./docs/rules stay.3. The docs lockfile
The first run of the docs job on
developmentexposed a lockfile out of step withpackage.json:@conduction/docusaurus-presetpinned at 3.10.0 against^3.12.0, sonpm cirefused to install. Regenerated, and it now resolves 3.52.0.npm ciandnpm run buildpass locally, including all 8 AI-baseline checks.Inherited, not fixed here
quality / Hydra Gatesandquality / Quality Reportfail on this PR and have failed ondevelopmentevery night (2a129e5, 2026-09-26 to 09-28). The job says the pinned hydra-gates package is missing paths the workflow needs. That is not a finding about this repo.E2E Tests (Playwright)is red on development too.Verified
documentation.yml.git check-ignoreconfirmsdocs/.docusaurus/stays ignored.isTemplate: true(gh repo view). That is what the guard reads.composer check:strictwas not run.🤖 Generated with Claude Code