repo-setup
Recipe card from the charly-internals plugin (Development — contributor internals).
repo-setup — the opencharly org, dotgithub config, and new-repo setup
Section titled “repo-setup — the opencharly org, dotgithub config, and new-repo setup”This skill is the companion to /charly-internals:git-workflow: git-workflow
owns the AUTHOR’s branch/PR discipline; repo-setup owns the ORG-LEVEL
configuration that discipline relies on and the checklist for standing up a
NEW repository.
The org model (verified against the live settings)
Section titled “The org model (verified against the live settings)”- The
opencharlyorg is on GitHub Team, so org rulesets and theworkflowsrule (“Require workflows to pass”) are available. - ONE organization branch ruleset named
org-wide required workflow & main protectionis the single source of main protection and the required workflow. It targets~ALLrepositories MINUS an explicit exclude set, onrefs/heads/main, and carries:workflows— requiresopencharly/.github/.github/workflows/org-wide-pr-validator-required.yml@refs/heads/main(read from the.githubrepo at the pinned ref);required_status_checks—strict: true, exactly ONE contextvalidate / validate;non_fast_forward,deletion,creation. The ONLY bypass actor is thecharly-auto-mergeGitHub App (its protected-main CHANGELOG writes must land). There is NO human bypass and NOpull_requestreview rule — the validator IS the gate.
- Owner script:
opencharly/.github/scripts/org-ruleset.sh(apply/verify). It creates/updates the ruleset, deletes redundant per-repo rulesets and any surviving legacy branch protection, and enforces the two settings that have NO org-level default:allow_auto_merge=trueanddelete_branch_on_merge=true. - The target set is
discover_reposinscripts/lib-org.sh: active, non-fork, default branchmain. Everything else isdiscover_excludes(forks, archived, non-maindefaults) and receives NEITHER the org workflow NOR CalVer tags — by design, not by omission.
What happens automatically on every PR (the landing chain)
Section titled “What happens automatically on every PR (the landing chain)”- A PR is opened/updated → the org ruleset runs
org-wide-pr-validator-required.ymlin the TARGET repo’s context (definition fromopencharly/.githubat the pinned ref) → it calls the reusablepr-validator.yml→ the single required checkvalidate / validate. - On a PASS verdict the validator enables GitHub native auto-merge (squash)
inline — there is NO separate auto-merge workflow.
mainis squash-only. - After the merge, the PER-REPO caller
.github/workflows/tag-on-merge.ymlfires (onworkflow_runofcharly/pr-validator+pushto main) → calls the org reusabletag-on-merge.yml, which mints the CalVer tagv<YYYY>.<DDD>.<HHMM>at the merge commit and writesCHANGELOG/<CalVer>.mdfrom the merged PR body (the body IS the changelog). Proxy-consumed root modules (sdk,spec,plugin-gh) get the Go-modulev0.<YYYYDDD>.<HHMM>form instead. - A body-only fix after the head was pushed needs NO empty commit: re-run the
failed run MANUALLY with
gh run rerun <run-id>(a re-run updates the same check run in place). The org-widererunlabel sweep was RETIRED.
Setting up a NEW repository (checklist)
Section titled “Setting up a NEW repository (checklist)”- Create
opencharly/<name>(non-fork; it must end up on default branchmain). The org ruleset then covers it automatically — no per-repo branch rules. - Add the per-repo
.github/workflows/tag-on-merge.ymlcaller — REQUIRED for CalVer tags and the CHANGELOG — plus the appropriatedeploy.yml. The org-required validator needs NO per-repo file (the oldpr-validator.ymldispatcher is retired byretire-per-repo-dispatchers.yml). - The org owner applies the ONE org ruleset (the
org-ruleset.showner script inopencharly/.github,applymode — an operator/CI action, not a charly user command) soallow_auto_mergeanddelete_branch_on_mergeare enforced for the new repo. - Land the first commit via a PR — never a direct push to
main. - Add it to the umbrella as a submodule and advance the pin via
charly task sync+ PR (see/charly-internals:git-workflowB8).
The measured gap this checklist prevents
Section titled “The measured gap this checklist prevents”A repo created WITHOUT the tag-on-merge.yml caller still MERGES (the org
workflow validates it) but NEVER gets a CalVer tag: measured on
layer-nerdctl and plugin-nerdctl (no .github directory at all; their two
v2026.266.* tags were minted manually). Excluded BY DESIGN (no tag expected):
gst-wayland-display (a fork), pixelflux (a vendored upstream on non-main
default av1), omarchy-eval-artifacts (a runs-branch artifact sink), and the
archived pi-review-action.
Cross-References
Section titled “Cross-References”/charly-internals:git-workflow— the author’s branch/PR/landing discipline and the after-merge close-out checklist (B8).opencharly/.github—scripts/org-ruleset.sh,scripts/lib-org.sh,scripts/retire-per-repo-dispatchers.sh, and the workflowsorg-wide-pr-validator-required.yml,pr-validator.yml,tag-on-merge.yml,tag-on-merge-dispatcher.yml,bootstrap-repo-main.yml.
When to Use This Skill
Section titled “When to Use This Skill”Invoke when creating or onboarding a repository in the opencharly org, when adding or changing CI/landing workflows, or when explaining what the org ruleset and dotgithub workflows do automatically versus what each repo must configure.