The mobile repos don't appear in SonarQube because they were never wired into the scan infrastructure — no sonar-scan.yml workflow, no sonar-project.properties, no OpenBao CI AppRoles (provision-ci-approles.sh only covers backend/artpipe/angular/infrastructure), and no BAO_ROLE_ID/BAO_SECRET_ID Actions secrets on either repo.
Fix (three PRs):
spikersoft-infrastructure: ci-ios.hcl + ci-android.hcl policies, extend provision-ci-approles.sh with ios android, new provision-mobile-sonar-secrets.sh writing secret/ci/{ios,android}/sonar (token only — host stays pinned in workflows per the #632 lesson).
spikersoft-android: sonar-scan.yml (main-push + dispatch, no PR trigger per #632 rationale) + sonar-project.properties (projectKey spikersoft-android, Kotlin sources/tests split, non-blocking gate).
spikersoft-ios: same shape (projectKey spikersoft-ios, games.pck/audio excluded).
Runbook after merge (Joey):
bash openbao/provision-ci-approles.sh → set BAO_ROLE_ID/BAO_SECRET_ID Actions secrets on BOTH mobile repos from its output.
Mint a SonarQube Global Analysis Token (My Account → Security) and run bash openbao/provision-mobile-sonar-secrets.sh.
Push to main (or workflow_dispatch) on each repo → projects appear.
⚠️ Swift caveat: official Swift analysis requires a commercial edition (Developer+). The stack image is tagged sonar-scanner-datacenter:2026.2.0, but the backend workflow (2026-07) observed Community-Edition behavior ("no branch/PR analysis") — check Administration → System for the actual edition. On CE the iOS project will appear but .swift files are skipped (only secrets/text/JSON rules run); options then are the community sonar-apple plugin (server-side install) or a commercial license. Kotlin/Android is fully supported on every edition.
The mobile repos don't appear in SonarQube because they were never wired into the scan infrastructure — no `sonar-scan.yml` workflow, no `sonar-project.properties`, no OpenBao CI AppRoles (`provision-ci-approles.sh` only covers backend/artpipe/angular/infrastructure), and no `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets on either repo.
Fix (three PRs):
- **spikersoft-infrastructure**: `ci-ios.hcl` + `ci-android.hcl` policies, extend `provision-ci-approles.sh` with `ios android`, new `provision-mobile-sonar-secrets.sh` writing `secret/ci/{ios,android}/sonar` (token only — host stays pinned in workflows per the #632 lesson).
- **spikersoft-android**: `sonar-scan.yml` (main-push + dispatch, no PR trigger per #632 rationale) + `sonar-project.properties` (projectKey `spikersoft-android`, Kotlin sources/tests split, non-blocking gate).
- **spikersoft-ios**: same shape (projectKey `spikersoft-ios`, games.pck/audio excluded).
**Runbook after merge (Joey):**
1. `bash openbao/provision-ci-approles.sh` → set `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets on BOTH mobile repos from its output.
2. Mint a SonarQube **Global Analysis Token** (My Account → Security) and run `bash openbao/provision-mobile-sonar-secrets.sh`.
3. Push to main (or workflow_dispatch) on each repo → projects appear.
**⚠️ Swift caveat**: official Swift analysis requires a commercial edition (Developer+). The stack image is tagged `sonar-scanner-datacenter:2026.2.0`, but the backend workflow (2026-07) observed Community-Edition behavior ("no branch/PR analysis") — check Administration → System for the actual edition. On CE the iOS project will appear but `.swift` files are skipped (only secrets/text/JSON rules run); options then are the community `sonar-apple` plugin (server-side install) or a commercial license. Kotlin/Android is fully supported on every edition.
Edition question resolved: the server is Enterprise Edition (Joey, 2026-08-06). So:
The Swift caveat is moot — the official Swift analyzer will fully analyze spikersoft-ios out of the box. iOS PR #9 updated to drop the Community-Edition note.
The backend sonar-scan.yml comment claiming "Community Edition (no branch/PR analysis)" is wrong — worth knowing that the whole fleet-wide "no PR trigger" stance (here and in #632's aftermath) was built on that belief. Enterprise supports branch + PR analysis, so PR-event scans would create proper separate PR analyses instead of clobbering the main baseline. Filed as a separate enhancement: #991.
Remaining before the mobile projects appear: merge the three PRs (infra #161, android #7, ios #9) and run the provisioning runbook in #161's description.
Edition question resolved: the server is **Enterprise Edition** (Joey, 2026-08-06). So:
- The Swift caveat is moot — the official Swift analyzer will fully analyze `spikersoft-ios` out of the box. iOS PR #9 updated to drop the Community-Edition note.
- The backend `sonar-scan.yml` comment claiming "Community Edition (no branch/PR analysis)" is **wrong** — worth knowing that the whole fleet-wide "no PR trigger" stance (here and in #632's aftermath) was built on that belief. Enterprise supports branch + PR analysis, so PR-event scans would create proper separate PR analyses instead of clobbering the main baseline. Filed as a separate enhancement: #991.
Remaining before the mobile projects appear: merge the three PRs (infra #161, android #7, ios #9) and run the provisioning runbook in #161's description.
Verified complete 2026-08-07 — closing. All three PRs merged and the post-merge runbook was run: both mobile projects now exist in SonarQube with fresh analyses.
Both mobile projects exist and were analyzed today, which means the AppRoles, the BAO_ROLE_ID/BAO_SECRET_ID Actions secrets and the Sonar global analysis token were all provisioned — runbook steps 1–3 are done.
Swift caveat resolved: the server is Enterprise Edition (see the 2026-08-06 comment above), so .swift files are fully analyzed; the PR-analysis consequence was split out as #991.
Not migrated: nothing left to do.
— Opus 5 Agent
Verified complete 2026-08-07 — closing. All three PRs merged **and** the post-merge runbook was run: both mobile projects now exist in SonarQube with fresh analyses.
- **Code:**
- `spikersoft-infrastructure@fa8a4af` (PR #161) — `ci-ios.hcl` / `ci-android.hcl`, `provision-ci-approles.sh` extended, `provision-mobile-sonar-secrets.sh`.
- `spikersoft-android@caf3ddc` (PR #7) — `sonar-scan.yml` + `sonar-project.properties`.
- `spikersoft-ios@72b8218` (PR #9) — same shape.
- Follow-through since: Sonar findings cleanups (android PR #8, ios PR #10) and PR-event analysis on the Enterprise server (android PR #9, ios PR #11, per #991).
- **Live:** `GET https://sonarqube.spikersoft.com/api/projects/search` →
```
api.spikersoft.com 2026-08-07T11:09:34+0000
learn.spikersoft.com 2026-08-07T11:55:15+0000
spikersoft-android 2026-08-07T13:40:44+0000
spikersoft-ios 2026-08-07T13:36:09+0000
```
Both mobile projects exist and were analyzed **today**, which means the AppRoles, the `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets and the Sonar global analysis token were all provisioned — runbook steps 1–3 are done.
- **Swift caveat resolved:** the server is Enterprise Edition (see the 2026-08-06 comment above), so `.swift` files are fully analyzed; the PR-analysis consequence was split out as #991.
Not migrated: nothing left to do.
— Opus 5 Agent
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The mobile repos don't appear in SonarQube because they were never wired into the scan infrastructure — no
sonar-scan.ymlworkflow, nosonar-project.properties, no OpenBao CI AppRoles (provision-ci-approles.shonly covers backend/artpipe/angular/infrastructure), and noBAO_ROLE_ID/BAO_SECRET_IDActions secrets on either repo.Fix (three PRs):
ci-ios.hcl+ci-android.hclpolicies, extendprovision-ci-approles.shwithios android, newprovision-mobile-sonar-secrets.shwritingsecret/ci/{ios,android}/sonar(token only — host stays pinned in workflows per the #632 lesson).sonar-scan.yml(main-push + dispatch, no PR trigger per #632 rationale) +sonar-project.properties(projectKeyspikersoft-android, Kotlin sources/tests split, non-blocking gate).spikersoft-ios, games.pck/audio excluded).Runbook after merge (Joey):
bash openbao/provision-ci-approles.sh→ setBAO_ROLE_ID/BAO_SECRET_IDActions secrets on BOTH mobile repos from its output.bash openbao/provision-mobile-sonar-secrets.sh.⚠️ Swift caveat: official Swift analysis requires a commercial edition (Developer+). The stack image is tagged
sonar-scanner-datacenter:2026.2.0, but the backend workflow (2026-07) observed Community-Edition behavior ("no branch/PR analysis") — check Administration → System for the actual edition. On CE the iOS project will appear but.swiftfiles are skipped (only secrets/text/JSON rules run); options then are the communitysonar-appleplugin (server-side install) or a commercial license. Kotlin/Android is fully supported on every edition.Edition question resolved: the server is Enterprise Edition (Joey, 2026-08-06). So:
spikersoft-iosout of the box. iOS PR #9 updated to drop the Community-Edition note.sonar-scan.ymlcomment claiming "Community Edition (no branch/PR analysis)" is wrong — worth knowing that the whole fleet-wide "no PR trigger" stance (here and in #632's aftermath) was built on that belief. Enterprise supports branch + PR analysis, so PR-event scans would create proper separate PR analyses instead of clobbering the main baseline. Filed as a separate enhancement: #991.Remaining before the mobile projects appear: merge the three PRs (infra #161, android #7, ios #9) and run the provisioning runbook in #161's description.
Verified complete 2026-08-07 — closing. All three PRs merged and the post-merge runbook was run: both mobile projects now exist in SonarQube with fresh analyses.
spikersoft-infrastructure@fa8a4af(PR #161) —ci-ios.hcl/ci-android.hcl,provision-ci-approles.shextended,provision-mobile-sonar-secrets.sh.spikersoft-android@caf3ddc(PR #7) —sonar-scan.yml+sonar-project.properties.spikersoft-ios@72b8218(PR #9) — same shape.GET https://sonarqube.spikersoft.com/api/projects/search→BAO_ROLE_ID/BAO_SECRET_IDActions secrets and the Sonar global analysis token were all provisioned — runbook steps 1–3 are done..swiftfiles are fully analyzed; the PR-analysis consequence was split out as #991.Not migrated: nothing left to do.
— Opus 5 Agent