Skip to content

Add daily OSM postbox import workflow - #214

Merged
code418 merged 1 commit into
masterfrom
claude/busy-shannon-b8cgg0
Oct 5, 2026
Merged

code418 merged 1 commit into
masterfrom
claude/busy-shannon-b8cgg0

Conversation

@code418

@code418 code418 commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a GitHub Actions workflow that automatically syncs postbox data from OpenStreetMap (via Overpass API) to Firestore on a daily schedule. The workflow uses keyless Workload Identity Federation for secure credential-free authentication and includes comprehensive setup documentation.

Key changes

  • New workflow file (.github/workflows/osm-import.yml):
    • Scheduled daily import at 03:17 UTC (off-peak, clear of midnight rollover)
    • Manual dispatch with optional flags: --dry-run, --prune, --no-manifest
    • Keyless Workload Identity Federation authentication (no stored secrets)
    • Manifest caching via GitHub Actions cache to track which postboxes have changed since the last run
    • Incremental upsert: only writes postbox docs whose geohash changed, reducing Firestore write costs
    • Concurrency control: prevents simultaneous imports from racing on Firestore and the manifest
    • 90-minute timeout to accommodate Overpass query retries (up to 5×600s) and full re-import of ~115k docs
    • Artifact upload of rejected Overpass responses for debugging
    • Job summary extraction from import logs

Implementation details

  • Credentials: Uses google-github-actions/auth@v3 with Workload Identity Federation; the workflow includes complete one-time GCP setup instructions (service account, workload identity pool, OIDC provider, IAM bindings)
  • Manifest persistence: .last_import_manifest.json is cached with a unique key per run, restored by prefix (newest wins); losing the cache triggers a full re-import (still correct)
  • Safety: The OIDC attribute condition restricts credential minting to the master branch only, preventing PRs or branch dispatches from writing production data
  • Dry-run support: --dry-run flag skips Firestore writes and manifest updates for testing
  • Pruning: --prune soft-marks postbox docs whose OSM node has been deleted; scheduled runs prune by default; the importer fails if truncation would affect >5% of postboxes (safety check)
  • Logging: Import summary is extracted and posted to the GitHub job summary for visibility

Firestore remains the source of truth; the downloaded postboxes.json is discarded after import.

https://claude.ai/code/session_018ZVwVFLy92tTB2jsW8JeSW

New osm-import.yml runs osm_import.sh at 03:17 UTC every day (and on
manual dispatch with dry_run / prune / full_reimport inputs), keeping the
Firestore postbox collection in step with OpenStreetMap without a manual
run.

- Auth is keyless Workload Identity Federation via
  google-github-actions/auth, which feeds the importer's Application
  Default Credentials. It reads two repo variables; the one-time gcloud
  setup is in the workflow header. The provider condition admits only
  this repo on master, so branch or PR workflows can't write production
  data.
- Scheduled runs pass --prune; the importer's 5% guard fails the run
  rather than hide boxes on a truncated export.
- The incremental manifest persists in the Actions cache (new key per
  run, restored by prefix), so daily runs only write changed nodes.
- The refreshed postboxes.json is discarded, not committed back.
- Adds a job summary of the import counts, and uploads a rejected
  Overpass response as an artifact on failure.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018ZVwVFLy92tTB2jsW8JeSW
@code418
code418 merged commit e732d6a into master Oct 5, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants