# Branches, कभी Main नहीं — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/hi/coding-agent-guardrails/git-branch-workflow

> Agent को branch पर काम कराएँ और main branch पर सीधा push असंभव बनाएँ।

## फेंकना आसान बनाएँ

Agent को **फेंकने योग्य branch** (या अलग `git worktree`) पर काम कराएँ ताकि पूरा session जाँचा, merge या हटाया जा सके। Server की तरफ़ `main` के लिए **branch protection** चालू करें: सीधे push नहीं, force push नहीं, अनिवार्य status checks और अनिवार्य reviews। तब पूरी तरह compromised agent भी gates पास किए बिना शिप होने वाली चीज़ नहीं बदल सकता।

## Repository सुरक्षा जाल के रूप में

Git हर बदलाव को दिखाई देने वाला और पलटने योग्य बनाता है; CI और अनिवार्य review तय करते हैं कि क्या merge हो सकता है।

![चार gates: branch, आकार, tests, review।](assets/figures/coding-agent-guardrails/section-5-map.svg) — चित्र 5.1 — Branch, आकार, tests और review gates।

## Branch session

यही commands इंसानों के लिए भी चलते हैं। Agent को `main` में लिख सकने वाले credentials कभी नहीं चाहिए।

```bash
git switch -c ai/fix-login-typo
# ... agent works, runs tests ...
git diff main --stat
git diff main                       # read every line
git push -u origin ai/fix-login-typo  # then open a pull request

# discard everything:
# git switch main && git branch -D ai/fix-login-typo
```

## Force push server पर रोकें

`git push --force` के विरुद्ध स्थानीय नियम पार हो सकता है। Server-side protection नियम वह है जो पार नहीं हो सकता, इसलिए हर महत्वपूर्ण branch पर उसे चालू करें।

**Quiz:** कौन-सा नियंत्रण compromised agent को भी main पर push करने से रोकता है?

- [x] Server-side branch protection
- [ ] Prompt में विनम्र नोट
- [ ] लंबा commit message
- [ ] Dark mode उपयोग करना

*Answer:* Server-side branch protection. Git host द्वारा लागू नियम इस पर निर्भर नहीं कि agent क्या कोशिश करता है।
