feat(mirrors) — kadans-admin rejoint le miroir GitHub : tous les projets kadans sont clonables par une session Claude cloud #65

Open
arcodange wants to merge 1 commits from arcodange/kadans-github-mirrors into main
3 changed files with 17 additions and 6 deletions
@@ -10,9 +10,13 @@
gitea_secret_propagation_users:
- arcodange
# Dépôts mis en miroir vers GitHub (et GitLab) par playbooks/06_mirrors.yml.
# Dépôts mis en miroir vers GitHub (et GitLab) par playbooks/07_mirrors.yml.
# Gitea reste la source ; les forges publiques ne reçoivent qu'une copie poussée.
#
# ⚠ Le miroir pousse en `git push --mirror` : toute branche qui n'existe QUE sur
# GitHub — celle qu'une session Claude cloud vient d'y pousser, par exemple — est
# SUPPRIMÉE au push suivant (à chaque commit sur Gitea, et toutes les 8 h).
#
# `gitea_sync` ne balaie qu'UN propriétaire à la fois et déduit les manques en
# comparant les forges : utile pour l'organisation, inadapté ici, où l'on choisit
# dépôt par dépôt ce qui sort du homelab. D'où cette liste, explicite et relue.
@@ -39,6 +43,10 @@ gitea_mirrored_repos:
owner: arcodange
github_owner: arcodange
github_owner_is_org: false
- name: kadans-admin
owner: arcodange
github_owner: arcodange
github_owner_is_org: false
- name: video_analysis
owner: arcodange
github_owner: arcodange
@@ -6,7 +6,7 @@
# 8 h ET à chaque commit. Les dépôts créés en face le sont en PRIVÉ.
#
# uv run ansible-playbook -i ansible/arcodange/factory/inventory \
# ansible/arcodange/factory/playbooks/06_mirrors.yml
# ansible/arcodange/factory/playbooks/07_mirrors.yml
#
# GitHub seulement (tant que l'espace GitLab personnel n'est pas renseigné) :
# … -e gitea_mirror_gitlab=false
@@ -3,7 +3,7 @@
# 07 · Mirrors — Gitea → GitHub / GitLab
> [!NOTE]
> **Status:** ✅ active · **Last Updated:** 2026-07-27
> **Status:** ✅ active · **Last Updated:** 2026-10-03
> **Upstream:** [Ansible sub-hub](README.md) · [Factory provisioning hub](../README.md)
> **Downstream:** [Roles reference](roles.md) — `gitea_repo`, `gitea_sync`, `gitea_token`
> **Related:** [Inventory & variables](inventory.md) · [03 · CI/CD](03-cicd.md)
@@ -12,6 +12,9 @@ Gitea is the **source of truth**; GitHub and GitLab hold a pushed copy. [`playbo
Nothing is pulled back. A mirror only ever pushes Gitea → forge, so a change made on GitHub is overwritten at the next sync.
> [!CAUTION]
> Gitea pushes with `git push --mirror` (`Mirror: true, Force: true` in `services/mirror/mirror_push.go`): every ref that exists **only on GitHub is deleted** at the next sync — on any commit to the Gitea repo, and every 8 h. A branch pushed to GitHub by a **Claude cloud session** (`claude/*`) is therefore short-lived: fetch it back to Gitea, or pull the result locally, before the next commit lands on Gitea.
```sh
uv run ansible-playbook -i ansible/arcodange/factory/inventory \
ansible/arcodange/factory/playbooks/07_mirrors.yml
@@ -55,14 +58,14 @@ A Gitea repo owned by the **user** `arcodange` does not belong on the GitHub **o
---
## Current state (2026-07-27)
## Current state (2026-10-03)
| Owner | Repos mirrored | Target |
| --- | --- | --- |
| `arcodange-org` | 10 (`factory`, `tools`, `erp`, `cms`, `webapp`, `url-shortener`, `docker.tofu`, `docker-build-workflow`, `super-linter-workflow`, `vault-action`) | `github.com/arcodange-org/*` + GitLab |
| `arcodange` (user) | 5 (`kadans`, `kadans-api`, `kadans-dossier`, `kadans-jobs`, `video_analysis`) — all **private** | `github.com/arcodange/*` |
| `arcodange` (user) | 6 (`kadans`, `kadans-api`, `kadans-admin`, `kadans-dossier`, `kadans-jobs`, `video_analysis`) — all **private** | `github.com/arcodange/*` |
Not mirrored, deliberately left out of `gitea_mirrored_repos`: `documents`, `studio`, `prospection`, `kissmetrics_contract_proposal` (org) and `.profile`, `DanceVideos`, `SecondBrain`, `dance-lessons-coach`, `frame-sdk`, `telegram-gateway` (user).
Not mirrored, deliberately left out of `gitea_mirrored_repos`: `documents`, `studio`, `prospection`, `kissmetrics_contract_proposal` (org) and `.profile`, `DanceVideos`, `SecondBrain`, `dance-lessons-coach`, `frame-sdk`, `telegram-gateway`, `mediabunny` (user). `mediabunny` stays home because `kadans` resolves it from the npm registry (`mediabunny@^1.56.1`), not from the fork — a cloud session cloning `kadans` does not need it.
> [!NOTE]
> The personal repos have **no GitLab mirror yet**: `gitlab_personal_namespace_id` is still `~`. Fill it with the numeric namespace ID of the `arcodange` account on gitlab.com, otherwise creation would land the project in the `arcodange-org` group.