Skip to content

Commit 9b4dcde

Browse files
mzxchandraclaude
andcommitted
feat(forks): opt-in fork sync for new workflows
Workspace forks gain a lineage-wide policy for whether a NEWLY created workflow joins fork sync. Today a workflow joins the moment it is deployed, so deploying something experimental in a parent pushes it into every fork on the next sync with no step where anyone chose that. Opt-out remains the default, so no existing or new workspace changes behaviour until someone flips the toggle. The policy lives on workspace.fork_sync_new_workflows_excluded (default false, the historical behaviour); workflow.fork_sync_excluded is untouched including its default. It is uniform across a fork lineage: settable from any member, fanning out to every ancestor and descendant under an advisory lock keyed on the lineage root, which fork creation and unlink also take. It is forward-only - flipping it never rewrites an existing workflow's sync state - and each changed member records its own audit entry naming where the change was issued from. Genuinely new workflows (create, duplicate, admin/superuser import, a fork's starter) take the workspace policy. A copy (fork creation, promote-create) inherits the SOURCE workflow's flag, because it is the same logical workflow in another workspace; without that an opted-in workflow would copy into a fork already excluded and never sync again. The fork modal gains "Copy unsynced workflows" (off by default, shown only when the source has unsynced deployed workflows, disabled when the combined set would exceed the fork ceiling) so forking an opt-in workspace cannot silently produce an empty fork. The settings section becomes "Synced workflows" with the polarity flipped - checked means the workflow syncs - above a "Sync new workflows by default" toggle row that states its lineage-wide reach. The wire field stays forkSyncExcluded, so the tree owns the single inversion. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent a0c93d6 commit 9b4dcde

44 files changed

Lines changed: 31043 additions & 128 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎apps/docs/content/docs/platform/enterprise/forks.mdx‎

Lines changed: 38 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -54,10 +54,12 @@ Everything under **Copy resources** starts **selected**. That is usually what yo
5454

5555
<Image src="/static/enterprise/forks-create-warning.png" alt="Fork workspace modal showing a warning that deselected resources will clear references in the fork" width={900} height={953} className="mx-auto h-auto w-full max-w-md" />
5656

57+
If the source has deployed workflows that are **not** in fork sync (see [Synced workflows](#synced-workflows)), a **Workflows** section appears with a **Copy unsynced workflows** toggle. It is **off**, so a fork carries exactly what the Forks page shows as synced. Turn it on to copy every deployed workflow instead — the unsynced ones arrive in the child still unsynced, so they never sync back. Either way the line under the toggle names the counts.
58+
5759
Click **Fork**. The child workspace is created immediately. Deployed workflows land as **drafts** in the child. Large content (table rows, knowledge base files, file blobs) may finish copying in the background — watch **Activity** on the source workspace.
5860

5961
<Callout type="info">
60-
Only **deployed** workflows are forked. Drafts and undeployed work stay in the parent. If the parent has nothing deployed, the child starts with a blank starter workflow.
62+
Only **deployed** workflows are forked, and by default only the ones that are [synced](#synced-workflows). Drafts and undeployed work stay in the parent. If there is nothing to copy, the child starts with a blank starter workflow.
6163
</Callout>
6264

6365
### 3. Open the parent edge (from the child)
@@ -117,16 +119,35 @@ On success you will see a toast such as **Pushed to "…"** or **Pulled from "
117119

118120
---
119121

120-
## Excluded workflows
122+
## Synced workflows
123+
124+
The **Synced workflows** section on the Forks page lists this workspace's deployed workflows in their sidebar folder structure, each with a checkbox. **Checked means the workflow syncs.** Uncheck one — or a whole folder at once — to keep it out of forking entirely. Think of an unchecked workflow as `.gitignore`d:
125+
126+
- **Never sent** — pushes from this workspace do not carry it, the other side pulling from this workspace does not receive it, and creating a new fork does not copy it (unless you turn on **Copy unsynced workflows** in the fork modal)
127+
- **Never touched** — a sync into this workspace will not overwrite or archive it, even if its counterpart was deleted on the other side. It stays deployed and keeps serving, and a previously-synced counterpart on the other side keeps running on its last deployed version.
128+
129+
The checkbox list belongs to **this workspace's copy** only. Unchecking a workflow here does not unsync its counterpart in the parent or a fork — each workspace manages its own list. If the pair has synced before, the link between them is kept, so re-checking later resumes updating the same counterpart instead of creating a duplicate.
130+
131+
On the sync page, unsynced workflows still appear in the **Deployed workflows** list, greyed out, with a tooltip naming which workspace they are unsynced in. The sync will not touch them.
132+
133+
**Example:** a staging fork leaves `Scratch experiment` unchecked so it can never reach production, and production leaves `Billing hotfix` unchecked so no push from staging can ever overwrite it.
134+
135+
### Sync new workflows by default
136+
137+
Above the list, **Sync new workflows by default** decides where a **newly created** workflow starts:
121138

122-
The **Excluded workflows** section on the Forks page lists this workspace's deployed workflows in their sidebar folder structure. Check a workflow — or a whole folder at once — to keep it out of forking entirely. Think of it as a `.gitignore` for syncs:
139+
| Setting | A new workflow… |
140+
|---------|-----------------|
141+
| **On** (default) | joins fork sync — it arrives checked and syncs as soon as you deploy it |
142+
| **Off** | starts outside fork sync — it arrives unchecked and only syncs after you check it |
123143

124-
- **Never sent** — pushes from this workspace do not carry it, the other side pulling from this workspace does not receive it, and creating a new fork does not copy it
125-
- **Never touched** — a sync into this workspace will not overwrite or archive it, even if its counterpart was deleted on the other side
144+
Three things to know:
126145

127-
The setting belongs to **this workspace's copy** only. Excluding a workflow here does not exclude its counterpart in the parent or a fork — each workspace manages its own list. If the pair has synced before, the link between them is kept, so un-excluding later resumes updating the same counterpart instead of creating a duplicate.
146+
- **It applies to the whole fork lineage.** The toggle writes every workspace in the lineage — the root, every ancestor, every descendant — so a parent and its forks can never disagree about what "new" means. Any workspace admin in the lineage can change it, and each member gets its own audit entry naming the workspace the change came from. A new fork inherits the value at creation.
147+
- **It is forward-only.** Flipping it never moves an existing workflow in or out of sync. The checkbox list above stays the record of what syncs.
148+
- **"New" means genuinely new.** Creating, duplicating, or importing a workflow takes this setting, as does the blank starter workflow a fork gets when there is nothing to copy. A workflow that arrives as a **copy** — from a fork, or from a push or pull — inherits its source's own checkbox instead, so a workflow you deliberately synced never lands unsynced in the child.
128149

129-
**Example:** a staging fork excludes `Scratch experiment` so it can never reach production, and production excludes `Billing hotfix` so no push from staging can ever overwrite it.
150+
**Example:** a template workspace turns this off so every scratch workflow the team creates stays local, then checks only the handful meant to reach the forks.
130151

131152
---
132153

@@ -155,6 +176,8 @@ Expand a row for names of workflows and resources that were created, updated, or
155176
|--------|-----|
156177
| See Forks / create a fork | Admin on this workspace (+ feature available) |
157178
| Sync / edit mappings | Admin on **both** sides of the edge |
179+
| Check / uncheck **Synced workflows** | Admin on the workspace those workflows live in |
180+
| Change **Sync new workflows by default** | Admin on any one workspace in the lineage — the change applies to every member |
158181
| Rollback | Admin on the workspace the sync landed in |
159182
| Disconnect | Admin on **this** side only (you can disconnect even without access to the other workspace) |
160183
| Open the other workspace | You must be a member of that workspace |
@@ -169,9 +192,9 @@ How each resource behaves at **fork** time vs **sync** time. Use this when you a
169192

170193
| Resource | Fork | Sync |
171194
|----------|------|------|
172-
| Deployed workflows | Copied as drafts (unless excluded) | Updated / created / archived (force overwrite) |
195+
| Deployed workflows | Copied as drafts when [synced](#synced-workflows) | Updated / created / archived (force overwrite) |
173196
| Undeployed workflows | Not copied | Not synced |
174-
| [Excluded workflows](#excluded-workflows) | Never | Never — not sent, not overwritten, not archived |
197+
| [Unsynced workflows](#synced-workflows) | Only via **Copy unsynced workflows**, and the copy lands unsynced | Never — not sent, not overwritten, not archived |
175198
| Files | Optional copy (default on) | Map or copy |
176199
| File folders referenced by workflows | Mirrored with their ancestor folders, even when empty | Map by canonical path |
177200
| Tables | Optional copy (default on) | Map or copy |
@@ -191,11 +214,11 @@ How each resource behaves at **fork** time vs **sync** time. Use this when you a
191214

192215
### Workflows
193216

194-
Only **deployed** workflows move. Deploy is the commit; sync is the force push/pull of those commits. Workflows marked [excluded](#excluded-workflows) never move in either direction.
217+
Only **deployed** workflows move, and only the ones checked under [Synced workflows](#synced-workflows). An unsynced workflow never moves in either direction — the one exception is the fork modal's **Copy unsynced workflows** override, which copies it once and leaves it unsynced in the child.
195218

196219
| Feature | Behavior |
197220
|---|----------|
198-
| **Fork** | Each deployed workflow becomes a **draft** in the child. Run history is not copied. Only folders that contain a copied workflow are kept. |
221+
| **Fork** | Each synced deployed workflow becomes a **draft** in the child. Run history is not copied. Only folders that contain a copied workflow are kept. |
199222
| **Sync** | The change list shows what will be updated, created, or archived. The target is overwritten for those workflows. |
200223

201224
**Example:** Parent has `Support triage` deployed and `WIP experiment` as a draft. The fork gets only `Support triage` as a draft. A later push updates the child from the parent’s latest deploy of `Support triage`.
@@ -370,13 +393,16 @@ Schedules, webhooks, and triggers are not live in the child until you **deploy**
370393
- **Rollback ≠ undo copies** — Workflow versions roll back; copied resources can remain as orphans.
371394
- **Disconnect is permanent** — You cannot “reconnect” the same edge; you would fork again into a new workspace.
372395
- **No grandparent sync** — Only the direct parent↔child pair.
396+
- **The sync default is lineage-wide** — **Sync new workflows by default** is one shared setting for the whole lineage, so changing it from a fork also changes it in the parent and every sibling fork.
373397

374398
---
375399

376400
<FAQ items={[
377401
{ question: "Why is Sync greyed out?", answer: "Usually a blocking reference, an unmapped credential or secret, or a required dependent field (label, channel, document, …) still empty. Open Blocking sync and the mapping sections — each row explains what to fix. Sync also stays disabled while details are loading or if loading failed (reload the page)." },
378402
{ question: "Is sync a merge?", answer: "No. Deploy is like a commit; sync is a force push or force pull of deployed workflows onto the target. Use Rollback only for the last sync into a workspace, and remember copied resources may remain." },
379-
{ question: "Who can disconnect a fork I cannot open?", answer: "Any admin on your side of the edge. Disconnect does not require access to the other workspace — so you are not stuck if the other side lost membership." }
403+
{ question: "Who can disconnect a fork I cannot open?", answer: "Any admin on your side of the edge. Disconnect does not require access to the other workspace — so you are not stuck if the other side lost membership." },
404+
{ question: "I deployed a new workflow and sync ignored it. Why?", answer: "Sync new workflows by default is off for this fork lineage, so the workflow was created outside fork sync. Open Settings → Organization → Workspace forks and check it under Synced workflows. Turning the toggle back on only affects workflows created after that — it never moves an existing one." },
405+
{ question: "Does turning Sync new workflows by default off stop my current syncs?", answer: "No. It is forward-only and never rewrites an existing workflow's checkbox, so everything already synced keeps syncing. It also applies to every workspace in the fork lineage, not just the one you changed it from." }
380406
]} />
381407

382408
---

‎apps/sim/app/api/superuser/import-workflow/route.ts‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ import {
1818
} from '@/lib/workflows/persistence/utils'
1919
import { sanitizeForExport } from '@/lib/workflows/sanitization/json-sanitizer'
2020
import { deduplicateWorkflowName } from '@/lib/workflows/utils'
21+
import { resolveForkSyncExclusionForNewWorkflow } from '@/ee/workspace-forking/lib/sync-default'
2122

2223
const logger = createLogger('SuperUserImportWorkflow')
2324

@@ -149,6 +150,9 @@ export const POST = withRouteHandler(async (request: NextRequest) => {
149150
isDeployed: false, // Never copy deployment status
150151
runCount: 0,
151152
variables: sourceWorkflow.variables || {},
153+
// An imported workflow is a NEW workflow in the target workspace, so it takes that
154+
// workspace's fork-sync policy rather than the column default.
155+
forkSyncExcluded: await resolveForkSyncExclusionForNewWorkflow(db, targetWorkspaceId),
152156
})
153157

154158
// Save using existing persistence logic

‎apps/sim/app/api/v1/admin/workflows/import/route.ts‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,7 @@ import {
4141
notFoundResponse,
4242
} from '@/app/api/v1/admin/responses'
4343
import { extractWorkflowMetadata, type WorkflowImportRequest } from '@/app/api/v1/admin/types'
44+
import { resolveForkSyncExclusionForNewWorkflow } from '@/ee/workspace-forking/lib/sync-default'
4445

4546
const logger = createLogger('AdminWorkflowImportAPI')
4647

@@ -128,6 +129,10 @@ export const POST = withRouteHandler(
128129
isDeployed: false,
129130
runCount: 0,
130131
variables: {},
132+
// An imported workflow is a NEW workflow in this workspace, so it takes the
133+
// workspace's fork-sync policy. Without this it lands on the column default and
134+
// silently joins fork sync in a workspace that opted out.
135+
forkSyncExcluded: await resolveForkSyncExclusionForNewWorkflow(db, workspaceId),
131136
})
132137

133138
/**

‎apps/sim/app/api/v1/admin/workspaces/[id]/import/route.ts‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,7 @@ import type {
6262
WorkspaceImportRequest,
6363
WorkspaceImportResponse,
6464
} from '@/app/api/v1/admin/types'
65+
import { resolveForkSyncExclusionForNewWorkflow } from '@/ee/workspace-forking/lib/sync-default'
6566

6667
const logger = createLogger('AdminWorkspaceImportAPI')
6768

@@ -363,6 +364,10 @@ async function importSingleWorkflow(
363364
isDeployed: false,
364365
runCount: 0,
365366
variables: {},
367+
// An imported workflow is a NEW workflow in this workspace, so it takes the
368+
// workspace's fork-sync policy. Without this it lands on the column default and
369+
// silently joins fork sync in a workspace that opted out.
370+
forkSyncExcluded: await resolveForkSyncExclusionForNewWorkflow(db, workspaceId),
366371
})
367372

368373
/**
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
import { updateForkSyncDefaultContract } from '@/lib/api/contracts/workspace-fork'
2+
import {
3+
defineInternalJsonRoute,
4+
internalRateLimits,
5+
internalSessionAuth,
6+
} from '@/lib/api/server/routes'
7+
import { internalForkErrorPolicy } from '@/ee/workspace-forking/api/route-policies'
8+
import { forkOperations } from '@/ee/workspace-forking/application/operations'
9+
import { setForkSyncDefault } from '@/ee/workspace-forking/application/sync-default'
10+
11+
export const PUT = defineInternalJsonRoute({
12+
contract: updateForkSyncDefaultContract,
13+
auth: internalSessionAuth,
14+
operation: forkOperations.syncDefault,
15+
/**
16+
* Rated, unlike its sibling fork routes. This is the one that writes workspaces the
17+
* caller may not administer, under the feature's coarsest advisory lock, so an admin of
18+
* any single lineage member could otherwise loop it and starve fork creation across the
19+
* whole lineage.
20+
*/
21+
rateLimit: internalRateLimits.user({ bucketName: 'workspace-fork-sync-default' }),
22+
errorPolicy: internalForkErrorPolicy,
23+
mapInput: ({ params, body }) => ({ workspaceId: params.id, ...body }),
24+
present: ({ excludeNewWorkflows, workspacesUpdated }) => ({
25+
excludeNewWorkflows,
26+
workspacesUpdated,
27+
}),
28+
useCase: setForkSyncDefault,
29+
})

‎apps/sim/ee/workspace-forking/application/create-and-sync.ts‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,8 @@ export interface ForkInput {
2525
workspaceId: string
2626
name?: string
2727
copy?: Partial<ForkResourceSelection>
28+
/** Also copy deployed workflows the source has not opted into fork sync. */
29+
copyUnsyncedWorkflows?: boolean
2830
requestId?: string
2931
previewFingerprint?: string
3032
}
@@ -60,6 +62,7 @@ function forkChoices(input: ForkInput) {
6062
workflowMcpServers: input.copy.workflowMcpServers ?? [],
6163
}
6264
: undefined,
65+
copyUnsyncedWorkflows: input.copyUnsyncedWorkflows ?? false,
6366
}
6467
}
6568

@@ -103,12 +106,15 @@ export const previewWorkspaceFork = defineForkUseCase({
103106
operation: forkOperations.preview,
104107
async execute({ input, context }: { input: ForkInput; context: ForkApplicationContext }) {
105108
await creationPolicy(context.workspace, context.userId)
109+
const choices = forkChoices(input)
106110
const revision = await loadForkPreviewRevision(
107111
db,
108112
{ sourceWorkspaceId: context.workspaceId },
109-
forkChoices(input)
113+
choices
110114
)
111-
const { deployedWorkflows } = await loadSourceDeployedStates(context.workspaceId)
115+
const { deployedWorkflows } = await loadSourceDeployedStates(context.workspaceId, {
116+
includeSyncExcluded: choices.copyUnsyncedWorkflows,
117+
})
112118
return {
113119
previewFingerprint: revision.fingerprint,
114120
sourceWorkspaceId: context.workspaceId,
@@ -159,6 +165,7 @@ export const forkWorkspace = defineForkUseCase<
159165
actorName: await loadActorName(context.userId),
160166
name: input.name,
161167
selection: choices.copy,
168+
copyUnsyncedWorkflows: choices.copyUnsyncedWorkflows,
162169
requestId: input.requestId ?? request?.headers.get('x-request-id') ?? generateShortId(),
163170
admission,
164171
})

‎apps/sim/ee/workspace-forking/application/discovery.ts‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -155,7 +155,12 @@ export const listWorkspaceForkResources = defineForkUseCase({
155155
async execute({
156156
input,
157157
}: {
158-
input: PageInput & { kind: keyof Omit<ForkCopyableResources, 'deployedWorkflowCount'> }
158+
input: PageInput & {
159+
kind: keyof Omit<
160+
ForkCopyableResources,
161+
'deployedWorkflowCount' | 'unsyncedDeployedWorkflowCount'
162+
>
163+
}
159164
}) {
160165
const cursor = readCursor(input, { collection: 'copyable_resources', kind: input.kind })
161166
const rows = await listForkCopyableResourcePage(db, input.workspaceId, input.kind, {

‎apps/sim/ee/workspace-forking/application/lineage-details.ts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ import { eq } from 'drizzle-orm'
44
import { getEffectiveWorkspacePermission } from '@/lib/workspaces/permissions/utils'
55
import { getForkChildren, getForkParent } from '@/ee/workspace-forking/lib/lineage/lineage'
66
import { getUndoableRunForTarget } from '@/ee/workspace-forking/lib/promote/promote-run-store'
7+
import { resolveForkSyncExclusionForNewWorkflow } from '@/ee/workspace-forking/lib/sync-default'
78

89
/**
910
* Annotates a lineage node with whether the viewer holds any access to it (explicit
@@ -34,10 +35,12 @@ export const getWorkspaceForkLineageDetails = defineForkUseCase({
3435
context: { userId: string }
3536
}) {
3637
const { workspaceId } = input
37-
const [rawParent, rawChildren, run] = await Promise.all([
38+
const [rawParent, rawChildren, run, forkSyncNewWorkflowsExcluded] = await Promise.all([
3839
getForkParent(workspaceId),
3940
getForkChildren(workspaceId),
4041
getUndoableRunForTarget(db, workspaceId),
42+
// Lineage-uniform, so this workspace's own value is the lineage's value.
43+
resolveForkSyncExclusionForNewWorkflow(db, workspaceId),
4144
])
4245

4346
const [parent, children] = await Promise.all([
@@ -71,6 +74,7 @@ export const getWorkspaceForkLineageDetails = defineForkUseCase({
7174
createdAt: child.createdAt.toISOString(),
7275
})),
7376
undoableRun,
77+
forkSyncNewWorkflowsExcluded,
7478
}
7579
},
7680
})

‎apps/sim/ee/workspace-forking/application/operations.ts‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,4 +98,20 @@ export const forkOperations = {
9898
id: 'workspaces.fork.exclusions',
9999
oauthScope: 'api:write',
100100
}),
101+
/**
102+
* Admin on the CALLING workspace is sufficient, and the write then fans out to every
103+
* ancestor and descendant, because the default is meaningless unless it is uniform
104+
* across a lineage. Flipping it to "sync new workflows" restores the historical
105+
* behaviour rather than granting anything new, and it never moves an existing workflow
106+
* in or out of sync - so each member records its own audit entry rather than the write
107+
* being restricted to one workspace.
108+
*
109+
* permission-group-exempt: the new-workflow fork-sync default is workspace configuration governed by the admin role.
110+
*/
111+
syncDefault: defineWorkspaceOperation({
112+
...adminPolicy,
113+
capability: 'none',
114+
id: 'workspaces.fork.sync_default',
115+
oauthScope: 'api:write',
116+
}),
101117
} as const

0 commit comments

Comments
 (0)