colophon apply cannot run without a config file, where every other verb can
Raised by a session working phpboyscout/cicd, as a request to this project. Found by cicd's component self-test on the first run of the new
colophon-applyjob (cicd !313, implementing cicd wiki spec 0083 and cicd#44 (closed)).
The need
colophon apply cannot run in a repository that has no colophon configuration file. Every other verb can.
The four release verbs are exempt from the missing-config gate; apply, added in v0.6.0, is not. Since most repositories in the estate carry no .colophon.yaml — it exists only to override placement, headings or a hold — the verb fails everywhere by default.
The use case
cicd's colophon component gained a colophon-apply job that runs on every push to the target branch, per this project's spec 0012 D12 and cicd#44 (closed). It is on by default, so it reaches all 106 repositories using the component.
phpboyscout/cicd itself has no .colophon.yaml, and the job fails there before doing any work.
Evidence
From the job trace (image registry.gitlab.com/phpboyscout/images/release-tools:v0.1.8, which bakes colophon 0.6.0):
$ colophon --ci apply --from "$CI_COMMIT_BEFORE_SHA" --to "$CI_COMMIT_SHA"
2026/09/07 13:04:34 ERRO failed to load configuration: no config file found hints="Run 'colophon init' to create a configuration."
ERROR: Job failed: exit code 1In the same child pipeline, on the same commit and the same image, publish and propose both started normally and failed later for the reason the test intends (a deliberately invalid credential):
publish: ERRO looking for a merged release on colophon/release/selftest-no-such-branch: ... 401 Unauthorized
propose: ERRO writing the release branch: cloning ... authentication requiredSo the difference is not the checkout, the image or the environment — it is the verb.
pkg/cmd/root/cmd.go:35 on main reads:
Bootstrap: props.BootstrapPolicy{SkipConfigCheck: []string{"plan", "propose", "publish", "release"}},apply is absent from that list. Naming it here as the reproduction, not as a prescribed fix — whether the gate should be per-verb at all is your call.
Expected output shape
colophon apply starts in a repository with no configuration file, resolves the span, and reports what it found — including "nothing to apply", which is the ordinary case on most merges. Exit code unchanged.
Current workaround, and what it costs
None in use. cicd !313 is marked Draft until this is resolved.
The alternatives we considered and did not take: adding a .colophon.yaml to 106 repositories to satisfy a check none of them need, or shipping the job with apply defaulting off, which contradicts spec 0012 D12's rejection of per-repo opt-in.
Not exposed in the meantime: nothing runs apply yet, because the component job that would is the thing being held.
Non-goals
Not asking for a change to what apply does, its flags, or its output — only that it can start where the other verbs can.