Files
orca/cloud/dev/scripts/relay-repository.mjs
T
Jinwoo-H 25e31c931d chore(cloud): add the relay fence broker, ops console, Terraform root, and scripts
Copies the private repository's relay side: the IAM-only fence broker, the
operations console and incident monitor, the relay Terraform root with its
backend configuration and tfvars, and the deploy/capacity/admission/rehome/
monitoring scripts the workflows call, with their contract tests, contracts,
and fixtures.

The foundation and apps Terraform roots and the API and auth services stay
private. Four surfaces that spanned both trees are narrowed to the relay side
rather than left with a dangling read: the infra runner and the root-partition
and workload-identity-condition renderers now declare only the relay root, and
the Cloud SQL rollout census drops the six app workflows that are not here.
2026-09-03 06:20:32 -04:00

30 lines
1.2 KiB
JavaScript

import { readFileSync } from 'node:fs'
// Single place naming the repository the Relay workflows live in and where their files sit. The
// public-repo copy moves this tree under cloud/, prefixes every workflow filename, and changes the
// owning repository, so only this module changes: nothing else may restate any of the three.
export const RELAY_GITHUB_REPOSITORY = 'stablyai/orca'
export const RELAY_WORKFLOW_FILE_PREFIX = 'cloud-'
// Where .github/workflows sits relative to this file. Workflows stay at the repository root while
// this tree moves under cloud/, so the depth changes at the copy even though the layout does not.
export const RELAY_WORKFLOW_DIRECTORY = new URL('../../../.github/workflows/', import.meta.url)
export function relayWorkflowFile(name) {
return `${RELAY_WORKFLOW_FILE_PREFIX}${name}`
}
// Repository-relative path, the shape GitHub reports in workflow_ref and evidence payloads.
export function relayWorkflowPath(name) {
return `.github/workflows/${relayWorkflowFile(name)}`
}
export function relayWorkflowUrl(name) {
return new URL(relayWorkflowFile(name), RELAY_WORKFLOW_DIRECTORY)
}
export function readRelayWorkflow(name) {
return readFileSync(relayWorkflowUrl(name), 'utf8')
}