feat(shared-vault-sync): add commit-driven auto-push script

push-shared-vault.sh pushes the shared vault only when the worktree is clean
and the local branch is ahead of origin (fetch first); never rebases,
force-pushes, or resolves conflicts. Ships with launchd setup docs. Bump 0.1.2.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-09-01 10:33:49 +07:00
parent 1bd000e595
commit 6ad7202fdf
5 changed files with 55 additions and 5 deletions

View File

@@ -18,7 +18,7 @@
"name": "shared-vault-sync", "name": "shared-vault-sync",
"source": "./plugins/shared-vault-sync", "source": "./plugins/shared-vault-sync",
"description": "Safely pulls the shared vault at session start.", "description": "Safely pulls the shared vault at session start.",
"version": "0.1.1" "version": "0.1.2"
} }
] ]
} }

View File

@@ -1,6 +1,6 @@
{ {
"name": "shared-vault-sync", "name": "shared-vault-sync",
"version": "0.1.1", "version": "0.1.2",
"description": "Safely pulls the shared vault at interactive session start.", "description": "Safely pulls the shared vault at interactive session start.",
"author": { "name": "Senkensha" }, "author": { "name": "Senkensha" },
"hooks": "./hooks/claude-codex-hooks.json" "hooks": "./hooks/claude-codex-hooks.json"

View File

@@ -1,6 +1,6 @@
{ {
"name": "shared-vault-sync", "name": "shared-vault-sync",
"version": "0.1.1+codex.20260901101401", "version": "0.1.2+codex.20260901103344",
"description": "Safely pulls the shared vault at interactive session start.", "description": "Safely pulls the shared vault at interactive session start.",
"author": { "author": {
"name": "Local developer" "name": "Local developer"

View File

@@ -15,6 +15,25 @@ The hook skips a dirty worktree and uses `git pull --ff-only`; it never rebases,
Install `shared-vault-sync` from the `infra-plugins` marketplace, then open a new session to activate its `SessionStart` hook. Install `shared-vault-sync` from the `infra-plugins` marketplace, then open a new session to activate its `SessionStart` hook.
## Recommended push automation ## Auto-push (launchd)
Keep pushes commit-driven. A scheduled local job may run `git fetch` and `git push` only when the vault is clean and the local branch is ahead; it must never rebase, force-push, or resolve conflicts. Let this hook handle the next safe pull after a rejected push. `scripts/push-shared-vault.sh` mengirim commit lokal ke remote secara **commit-driven**:
hanya jika worktree bersih **dan** branch lokal di depan `origin` (fetch dulu). Tidak pernah
rebase, force-push, atau resolve conflict; no-op saat offline atau tidak ada yang perlu di-push.
Setup (macOS launchd, interval 5 menit):
```bash
# 1. pastikan script tersedia di plugin (repo infra-plugins)
# 2. buat plist ~/Library/LaunchAgents/com.mbugroup.shared-vault-push.plist:
# - ProgramArguments: /bin/bash <infra-plugins>/plugins/shared-vault-sync/scripts/push-shared-vault.sh
# - EnvironmentVariables: SHARED_VAULT_DIR=<path ke clone shared vault>
# - StartInterval: 300
# 3. muat:
launchctl bootstrap gui/$(id -u) ~/Library/LaunchAgents/com.mbugroup.shared-vault-push.plist
launchctl kickstart -k gui/$(id -u)/com.mbugroup.shared-vault-push
```
Log push: `$PUSH_SHARED_VAULT_LOG` (default `/tmp/shared-vault-push.log`), hanya timestamp + jumlah commit.
Hook pull tetap menangani sinkronisasi masuk; agent ini menangani arah keluar. Push tetap commit-driven:
agent tidak pernah membuat komit, hanya mengirim komit yang sudah Anda buat di `Areas/DevOps`.

View File

@@ -0,0 +1,31 @@
#!/usr/bin/env bash
# push-shared-vault — commit-driven auto-push for the shared vault.
#
# Safe by design:
# - pushes only when the worktree is clean (no uncommitted changes),
# - pushes only when the local branch is ahead of its remote (fetch first),
# - never rebases, force-pushes, or resolves conflicts,
# - silently no-ops when offline or when there is nothing to push.
#
# Intended to run from launchd or cron at an interval (e.g. every 5 minutes).
# Requires: SHARED_VAULT_DIR=<path to the shared vault clone>.
set -u
VAULT_DIR="${SHARED_VAULT_DIR:-}"
LOG="${PUSH_SHARED_VAULT_LOG:-/tmp/shared-vault-push.log}"
[ -n "$VAULT_DIR" ] || exit 0
log() { printf '%s %s\n' "$(date '+%Y-%m-%d %H:%M:%S')" "$*" >> "$LOG"; }
git -C "$VAULT_DIR" rev-parse --is-inside-work-tree >/dev/null 2>&1 || exit 0
[ -z "$(git -C "$VAULT_DIR" status --porcelain)" ] || exit 0
git -C "$VAULT_DIR" fetch --quiet origin 2>/dev/null || exit 0
branch="$(git -C "$VAULT_DIR" rev-parse --abbrev-ref HEAD)" || exit 0
ahead="$(git -C "$VAULT_DIR" rev-list --count "origin/$branch..HEAD" 2>/dev/null || echo 0)"
[ "${ahead:-0}" -gt 0 ] || exit 0
if GIT_TERMINAL_PROMPT=0 git -C "$VAULT_DIR" push origin "$branch"; then
log "pushed $ahead commit(s) to origin/$branch"
fi