Files
devops-lib-gcp/docs/wiki/pages/concepts/whitelists.md
T
2026-08-26 02:02:24 +05:30

2.9 KiB
Raw Blame History

Generated 2026-05-21 at base-sha 5399a5ddc36b. Type: concept. 1 source.

The five whitelist gates

constructParam.groovy runs five independent whitelist checks against Meesho/whitelists. Each one does a fresh git clone — there is no caching. A build that hits all five clones the whitelist repo five times.

The five gates

Gate What it controls Function Read at
skip-sonar-whitelist Blocks skip_sonar=true for Maven on prd unless repo is allowlisted skipSonarCheckForbidden constructParam.groovy:40-57
app-config-disabled Blocks appConfig=false on stg for Maven/Gradle unless allowlisted appConfigDisabledForbidden constructParam.groovy:62-72
multizone-enabled-repos Gates the multi-zone deploy path isMultizoneEnabled constructParam.groovy:29-35
allowedNonDevelopPrDeploymentToInt Allows non-develop PRs to deploy to int allowedNonDevelopPrDeploymentToIntRepos constructParam.groovy:77-83
ValidateCacConfig Gates CAC validation on PR build ValidateCacConfigForRepo constructParam.groovy:88-95

Why fresh-clone every time

This is intentional. The whitelist is the live, authoritative source of which repos opt out of which check. By re-cloning on every call, a DevOps change to the whitelist takes effect on the next build in the org without needing a devops-lib release. The cost is ~5× clone latency under GitHub rate-limiting; the benefit is zero release coordination.

Do NOT add caching

The single most tempting refactor in this code is to cache the clone across the five calls in a single build. Don't — the freshness guarantee is the load-bearing property. See docs/tribal-knowledge.md §1. If you must improve clone performance, do it inside the clone itself (shallow clone, single-branch fetch) without touching the per-call invocation pattern.

Where the whitelist lives

https://github.com/Meesho/whitelists.git (cloned via gitActions.groovy helpers). The repo contains one YAML per whitelist name, e.g. skip-sonar-whitelist.yaml, multizone-enabled-repos.yaml. Each is a flat list of repo names.

To add a repo to a whitelist: open a PR on Meesho/whitelists, get a DevOps reviewer to approve, merge. The next pipeline run picks up the change automatically.