Skip to content

feat(webhooks): forward repository, installation_repositories and push to colby-maestro - #532

Merged
jmbish04 merged 1 commit into
mainfrom
feat/forward-repo-events-to-maestro
Sep 30, 2026
Merged

jmbish04 merged 1 commit into
mainfrom
feat/forward-repo-events-to-maestro

Conversation

@jmbish04

Copy link
Copy Markdown
Owner

What

core-github-api now also forwards repository, installation_repositories and push webhooks to colby-maestro's POST /api/github/webhook. It uses the existing MAESTRO service binding, which has no entrypoint, so the default export's fetch handles it.

  • Raw, unchanged body plus x-hub-signature-256, x-github-event, x-github-delivery and content-type: application/json. Maestro checks the App signature itself, so re-serialising the body would break it.
  • Fire-and-forget in executionCtx.waitUntil. A non-2xx response or a thrown error is logged and never changes this Worker's response to GitHub.
  • All pushes are forwarded. Maestro filters to the default branch itself.
  • The existing trimmed pull_request forward to /api/github/events/pull-request is untouched.
  • Deliveries for repos outside jmbish04/ are still dropped earlier by the existing scope check.

Merge order

Do not merge until colby-maestro binds GITHUB_APP_WEBHOOK_SECRET to the WORKER_API_KEY value and deploys. Until then Maestro would return 401 on these App-signed deliveries. That is harmless here because the forward is fire-and-forget, but it is noise in the logs.

Tests

tests/unit/maestro-raw-forward.test.ts has 7 tests: the three events forward byte-for-byte with all headers, issues, pull_request and check_run are not forwarded, and a 401 or thrown error never propagates. I broke the code five ways on purpose and each one turned the tests red: a re-serialised body, a dropped event filter, a dropped signature header, push removed from the set, and a thrown error.

tsc --noEmit shows 27 errors and vitest shows 1 failed suite (planning-health, which can't load a cloudflare: import under Node). Both are identical on clean origin/main, so this PR adds no new errors. The new tests call the forward function directly; they do not go through the full webhook handler.

🤖 Generated with Claude Code

…h to colby-maestro

colby-maestro's POST /api/github/webhook now handles repo creation, repos
added to the App installation, and default-branch pushes. These three events
are forwarded raw and unchanged, with x-hub-signature-256, x-github-event and
x-github-delivery, over the existing MAESTRO service binding, because Maestro
verifies the signature itself. Fire-and-forget in waitUntil; a Maestro error
is logged and never affects this Worker's own handling. The existing trimmed
pull_request forward is untouched.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jmbish04
jmbish04 merged commit f9d09ea into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant