Tool / proxy

Stacksona for GitHub Actions

Check the exact deployment, release, migration, or production operation immediately before the job performs it.

Where Gate goes

In the job or script directly before the production side effect.

Keep the platform's normal reasoning and orchestration. Gate only the exact action at the last safe point before execution.

Job prepares operationGate checks exact operationDeploy, migrate, or release executes or job stops

Start here

  1. 1
    Build the final action.

    Let GitHub Actions choose the action and produce the arguments it intends to execute.

  2. 2
    Check the exact action with Gate.

    Send tool_name and the final payload immediately before the side effect.

  3. 3
    Follow one of four outcomes.

    Continue, wait, revise, or stop. You do not need the advanced features to get this basic path working.

Minimal setup

A request is not an approval.

Posting a decision request to Gate does not authorize the next deployment step. The job must receive an executable decision before the production command runs.

Handle the decision

OutcomeGate statusWhat GitHub Actions should do
Continueallow or approvedExecute the exact proposed action. If signed proof is required, validate it first.
Waitpending_reviewStore thread_id and resume that exact review later.
Revisechanges_requestedReturn reviewer feedback to the part of the runtime that can revise the proposal.
Stopreject or rejectedDo not execute. Replan, fall back, or end the action.
Unknown or failed decision = stop.

Fail closed if Gate cannot be reached, returns an unknown state, or required approval proof is missing or invalid.

Platform notes

  • Keep cloud credentials, artifacts, scripts, and deployment tooling in the CI runner.
  • Persist thread_id between jobs when review can outlive one runner.
  • For long reviews, split request and continuation rather than holding a runner open.
Advanced: review threads, revisions, proof, and audit

task_id is your grouping ID. thread_id identifies the exact Gate review and should be persisted whenever work can pause.

For changes_requested, revise on the same review thread using the revision event contract. For high-impact actions that require signed proof, validate the returned approval token before execution. Log execution success or failure when you need complete audit evidence.

For long reviews, use the platform's durable continuation mechanism instead of keeping a process, workflow, or runner open.

Advanced runtime patterns Full Gate API Exact decision states