fix(git-sync): poll app-backed repos in auto/polling mode

The auto-pull poller skipped app-backed repos (the ls-remote head check
can't authenticate a tokenless URL), so auto- and polling-mode app repos
never synced when their webhook wasn't live. Wire the poller to fetch the
head via the GitHub API for app repos and reconcile. Bump the EE ref.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
hugocasa
2026-06-30 18:23:08 +02:00
parent 2e9a3c57bd
commit a317cf302d
2 changed files with 30 additions and 4 deletions
+1 -1
View File
@@ -1 +1 @@
9b63de906b4d64b79ae29a3e78a99f508f9ec285
520325a09bd41a20ae61ccd54c155aff66484ccd
+29 -3
View File
@@ -3127,13 +3127,40 @@ async fn poll_git_auto_pull_inner(db: &Pool<Postgres>) -> error::Result<()> {
continue;
}
match windmill_store::resources::get_git_repo_head_for_autopull(
let head = match windmill_store::resources::get_git_repo_head_for_autopull(
db,
&row.workspace_id,
&repo.git_repo_resource_path,
)
.await
{
Ok(Some(h)) => Ok(Some(h)),
// App-backed repos store a tokenless URL, so the ls-remote head
// check can't authenticate and returns None. Poll the head over
// the GitHub API with a minted installation token instead. This
// is the polling fallback/safety-net for auto- and polling-mode
// app repos whose webhook isn't live (unreachable instance,
// missing permission, or a dropped delivery). `webhook`-mode
// repos are skipped above and stay webhook-only.
Ok(None) => {
#[cfg(feature = "enterprise")]
{
windmill_common::git_sync_ee::get_app_repo_head_for_autopull(
db,
&row.workspace_id,
&repo.git_repo_resource_path,
)
.await
}
#[cfg(not(feature = "enterprise"))]
{
Ok(None)
}
}
Err(e) => Err(e),
};
match head {
Ok(Some((git_ref, sha))) => {
// Shared reconcile (also used by the webhook receiver):
// checks should_pull, enqueues, and records status/failure.
@@ -3153,7 +3180,6 @@ async fn poll_git_auto_pull_inner(db: &Pool<Postgres>) -> error::Result<()> {
);
}
}
// GitHub-App repo: synced via webhook (phase 2), nothing to poll.
Ok(None) => {}
Err(e) => {
windmill_git_sync::record_auto_pull_failure(
@@ -3161,7 +3187,7 @@ async fn poll_git_auto_pull_inner(db: &Pool<Postgres>) -> error::Result<()> {
&row.workspace_id,
&repo.git_repo_resource_path,
&auto_pull.last_synced_sha,
format!("ls-remote failed: {e}"),
format!("head check failed: {e}"),
)
.await;
}