From 0d03b0dd27aca2f529dfb9f3eab092b457601ebd Mon Sep 17 00:00:00 2001 From: Cato <41178744+catomean@users.noreply.github.com> Date: Mon, 7 Sep 2026 17:08:28 +0200 Subject: [PATCH] ci(auto-merge): hand the sweep a PAT so workflow PRs stop stalling MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GITHUB_TOKEN cannot merge a PR that touches .github/workflows. The sweep tries, the merge API refuses, it logs "leaving for the next sweep", and repeats — while still exiting 0. So the failure is invisible: every run reports success and the PR simply never merges. That is not hypothetical. ai-kit #11 (bump actions/checkout) sat green, CLEAN and MERGEABLE for nine days; aoz-housing #122 (bump actions/upload-artifact) for nine more. Both had to be merged by hand today. Every Dependabot `github_actions` bump in the fleet is in this class, permanently. A PAT fixes a second thing that costs more: THROUGHPUT. A dispatch made with GITHUB_TOKEN emits no workflow_run, so after each merge nothing wakes the sweep to take the next PR — it waits for the cron, and GitHub throttles scheduled workflows to roughly hourly regardless of what the cron says. Observed in fleetcrown: sweeps ~50-65 minutes apart against a */10 schedule. A PAT-created dispatch does emit workflow_run, so the queue drains at CI speed instead. The reusable workflow has always supported this — GH_TOKEN is `secrets.token || github.token`. This just passes it. SAFE BEFORE THE SECRET EXISTS: an undefined secret resolves to empty, and the fallback picks github.token. So this changes nothing until FLEET_PAT is created as an organisation secret, and needs no second pass afterwards. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01UvjGNAS9CMfEGNW26tUR4P --- .github/workflows/auto-merge.yml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 411b016..90efaa1 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -37,3 +37,19 @@ jobs: ci_workflow: ci.yml # SPACE-separated: the sweep word-splits this. rearm_workflows: 'ci.yml publish.yml' + secrets: + # GITHUB_TOKEN cannot merge a PR that touches .github/workflows, so every + # Dependabot `github_actions` bump stalls forever: the sweep tries, the + # merge API refuses, it logs "leaving for the next sweep", and repeats — + # while still exiting 0. ai-kit #11 sat green for nine days that way, and + # aoz-housing #122 for nine more. + # + # A PAT also makes the queue drain at CI speed rather than at the + # schedule's. A dispatch made with GITHUB_TOKEN emits no workflow_run, so + # after each merge nothing wakes the sweep for the next PR until the cron + # fires — and GitHub throttles that to roughly hourly whatever the cron + # says. A PAT-created dispatch does emit it. + # + # Undefined resolves to empty and the reusable workflow falls back to + # github.token, so this line is inert until the org secret exists. + token: ${{ secrets.FLEET_PAT }}