Webhooks Level Up
github.com
github.com
I hope you know that feature came out this week...
I'm surprised there's not a SaaS that handles the distribution, security, retries, and introspection for you...
I'm a little surprised they still don't offer any auth configuration for webhooks the way they do for most external services, so you're stuck with basic auth on the post-receive URL.
I ended up writing an independent service for it[1], but it'd be cool to let someone else deal. Also, to make receipts nice, and so on.
I wish they'd do similarly for the services. Currently, editing multiple services across repos is a bit of a pain, due to the length of the list and how it jumps you to the top on any interactions. (Originally, I thought this announcement meant they'd revamped that as well)
Out of curiosity, is there a generally-accepted best practice for rate-limiting / authenticating webhook pushes? I'm planning to run a daemon that listens for them, and while the effect of somebody finding the URL and hammering it isn't likely to be catastrophic, I'd still like to rate limit it if I can. Alternately, are GitHub's webhook-sending IPs static enough to put in an IP set and add to my firewall?
Having said that, I'm pretty sure GitHub publish a list of their public IPs, so you could also limit what is allowed to call your API.
This new feature will make things so much easier to set up and debug, I'm thrilled. Before, you could not create a pull request hook without using the API, and this caused a lot of people confusion. We set up the hook automatically in Leeroy, but this will allow people to set it up manually if they want, and debug when it doesn't work.
+refs/pull/*:refs/remotes/origin/pr/*
The major Jenkins plugins have their respective build-on-new-commits, so you can automate these builds and just treat these like feature branches.'Named after the software that powers the wiki.
However, I think running a test suite before deploying is a much safer option as it stops you from accidentally deploying something you haven't properly tested.