Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
94 commits
Select commit Hold shift + click to select a range
eae3722
docs: design hourly NVIDIA NIM OpenCode development
seonghobae Aug 5, 2026
346a31d
docs: plan hourly NVIDIA NIM OpenCode development
seonghobae Aug 5, 2026
0fd88ae
test(automation): define NIM OpenCode development contract
seonghobae Aug 5, 2026
e9ff9d3
test(automation): require bounded verified agent proposals
seonghobae Aug 5, 2026
1daa40e
ci(automation): schedule NVIDIA NIM OpenCode development
seonghobae Aug 5, 2026
f7af7fb
docs(automation): add hourly NIM development runbook
seonghobae Aug 5, 2026
a6b8703
docs(doctoring): record NIM OpenCode trust boundaries
seonghobae Aug 5, 2026
e3015d7
docs(readme): expose proposal-only hourly development loop
seonghobae Aug 5, 2026
9fe744c
docs(changelog): record NIM OpenCode proposal scheduler
seonghobae Aug 5, 2026
96691bd
test(automation): expose stale-base and metadata races
seonghobae Aug 5, 2026
b4beb5a
test(automation): define bounded PR metadata parser
seonghobae Aug 5, 2026
d4e73d8
feat(automation): add bounded PR metadata parser
seonghobae Aug 5, 2026
27cde2b
test(automation): require credential-separated proposal handoff
seonghobae Aug 5, 2026
b3e465c
ci(automation): isolate NIM proposals from repository writes
seonghobae Aug 5, 2026
eb8aafb
fix(automation): harden credential-separated proposal packaging
seonghobae Aug 5, 2026
365c75c
test(automation): align exact two-job proposal contract
seonghobae Aug 5, 2026
01e1241
docs(automation): document two-job proposal handoff
seonghobae Aug 5, 2026
3f53e1e
docs(doctoring): record two-job NIM trust boundary
seonghobae Aug 5, 2026
7993b5b
fix(ci): restrict workflow token and isolate publication credentials
seonghobae Aug 5, 2026
8c0c57c
test(ci): require least-privilege publication token boundary
seonghobae Aug 5, 2026
cb6bac4
docs(operations): document least-privilege Maintainer App publication
seonghobae Aug 5, 2026
c60fa18
docs(doctoring): record late-bound Maintainer App boundary
seonghobae Aug 5, 2026
218fe43
fix(docs): restore workflow contract wording
seonghobae Aug 5, 2026
006cb97
test(security): require fresh publication runner isolation
seonghobae Aug 5, 2026
514cd0f
test(security): require gitlink rejection in agent proposals
seonghobae Aug 5, 2026
33ad5c4
fix(security): isolate publication credentials on a third runner
seonghobae Aug 5, 2026
5c878af
fix(security): reject symlink and gitlink proposals
seonghobae Aug 5, 2026
f0aee66
test(security): cover three-runner Git object gates
seonghobae Aug 5, 2026
dc69f91
docs(operations): document three-runner publication isolation
seonghobae Aug 5, 2026
76f87b9
docs(doctoring): record runner isolation and artifact evidence
seonghobae Aug 5, 2026
7b3ee42
docs(changelog): record three-runner proposal isolation
seonghobae Aug 5, 2026
50be379
docs(doctoring): clarify isolated write-capable publisher
seonghobae Aug 5, 2026
ed5ab73
test(docs): require three-runner architecture alignment
seonghobae Aug 5, 2026
2eae6fb
docs(spec): align design with three-runner boundary
seonghobae Aug 5, 2026
ab58cfb
docs(plan): replace stale same-job packaging sequence
seonghobae Aug 5, 2026
4d863da
test(automation): tighten fallback and runner-boundary contracts
seonghobae Aug 5, 2026
d7ef1c1
test(security): require raw Git mode inspection
seonghobae Aug 5, 2026
79f18cb
ci: apply exact-head hourly development review fixes
seonghobae Aug 5, 2026
1db7981
ci: make CodeRabbit review repair deterministic
seonghobae Aug 5, 2026
7707292
ci: stage deterministic hourly review repair
seonghobae Aug 5, 2026
bad8c4c
fix(ci): simplify bounded review-fix runner
seonghobae Aug 5, 2026
a0ad30e
fix(ci): align doctoring timeout wording
seonghobae Aug 5, 2026
81c089a
ci: expose verified review-fix commit identity
seonghobae Aug 5, 2026
9182ca9
fix(ci): close hourly development review gaps
github-actions[bot] Aug 5, 2026
45ed94d
test(quality): require parser coverage and JSDoc
seonghobae Aug 5, 2026
9865707
fix(quality): document parser production contracts
seonghobae Aug 5, 2026
f5efee3
fix(quality): enforce parser production coverage
seonghobae Aug 5, 2026
17f36c7
refactor(quality): expose testable metadata boundaries
seonghobae Aug 5, 2026
2704bf7
test(quality): cover PR metadata safety branches
seonghobae Aug 5, 2026
3684f4e
refactor(quality): name production CLI seams
seonghobae Aug 5, 2026
7606e64
test(quality): cover named PR metadata CLI seams
seonghobae Aug 5, 2026
0c738b4
fix(quality): reject unsafe PR metadata limits
seonghobae Aug 5, 2026
fe3aec3
test(quality): preserve invalid CLI argument vectors
seonghobae Aug 5, 2026
112303e
fix(quality): validate missing CLI argument arrays
seonghobae Aug 5, 2026
76ca7bb
test(security): exercise Git mode boundary behavior
seonghobae Aug 5, 2026
e15dc64
docs(tests): document Git mode fixture helpers
seonghobae Aug 5, 2026
1c546b6
docs(tests): document metadata fixture helpers
seonghobae Aug 5, 2026
62958a9
test(ci): require bounded candidate cleanup reinstall
seonghobae Aug 5, 2026
fc64dbc
ci: verify bounded candidate cleanup repair
seonghobae Aug 5, 2026
3950a15
fix(ci): bound failed-candidate dependency reinstall
seonghobae Aug 5, 2026
b8667bb
docs(operations): record bounded cleanup budget
seonghobae Aug 5, 2026
74df51a
docs(plan): require bounded cleanup reinstalls
seonghobae Aug 5, 2026
318cae7
docs(design): separate candidate and cleanup timeouts
seonghobae Aug 5, 2026
748227a
chore(ci): remove superseded one-shot repair workflow
seonghobae Aug 5, 2026
d1dc35d
docs(changelog): record bounded cleanup timeout
seonghobae Aug 5, 2026
13f83ad
test(automation): expose final-candidate cleanup regression
seonghobae Aug 5, 2026
3896d74
fix(automation): retry final-candidate cleanup repair
seonghobae Aug 5, 2026
f14fcf1
fix(automation): apply structural final-candidate repair
seonghobae Aug 5, 2026
4e735b8
chore(automation): remove one-shot repair workflow
seonghobae Aug 5, 2026
5ab1da2
chore(automation): remove superseded repair workflow
seonghobae Aug 5, 2026
6c52daf
chore(automation): remove final one-shot repair workflow
seonghobae Aug 5, 2026
587a12f
ci(automation): publish verified final-candidate repair
seonghobae Aug 5, 2026
252eaee
test(automation): require inter-candidate cleanup only
seonghobae Aug 5, 2026
ec49b57
ci(automation): apply final candidate cleanup repair
seonghobae Aug 5, 2026
7c0b579
fix(automation): tolerate already absent one-shot workflows
seonghobae Aug 5, 2026
0ee9804
fix(automation): publish verified repair with one-shot branch token
seonghobae Aug 5, 2026
d9ea1dd
ci(automation): publish verified final candidate repair
seonghobae Aug 5, 2026
85b46e1
fix(automation): skip cleanup after final candidate
github-actions[bot] Aug 5, 2026
181da39
ci(automation): export verified final candidate repair bundle
seonghobae Aug 5, 2026
13c6f5e
chore(automation): remove one-shot repair exporter
seonghobae Aug 5, 2026
431fdc5
test(automation): require publication prerequisites before OpenCode
seonghobae Aug 5, 2026
c5d8365
docs(automation): document publication prerequisites
seonghobae Aug 5, 2026
f4a0ecf
docs(doctoring): record publication prerequisite boundary
seonghobae Aug 5, 2026
90a617e
test: fail closed on abnormal git mode gate exits
seonghobae Aug 5, 2026
26c1733
test(automation): centralize hourly workflow contracts
seonghobae Aug 5, 2026
c205162
test: cover metadata CLI argv boundaries
seonghobae Aug 5, 2026
5fba3cb
fix: guard metadata CLI entrypoint resolution
seonghobae Aug 5, 2026
ea303cf
test: bind candidate cleanup budget parsing
seonghobae Aug 5, 2026
06ae8c4
fix(automation): gate inference on publication readiness
seonghobae Aug 5, 2026
6c8b794
test: reuse bounded workflow contract helpers
seonghobae Aug 5, 2026
71a7121
docs: state publication prerequisite least privilege control
seonghobae Aug 5, 2026
900c57e
docs(changelog): record publication prerequisite gate
seonghobae Aug 5, 2026
4ce2286
test(coverage): expose metadata entry-path branches
seonghobae Aug 5, 2026
189cb19
fix(metadata): cover optional entrypoint resolution
seonghobae Aug 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
895 changes: 895 additions & 0 deletions .github/workflows/hourly-product-development.yml

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
# Changelog

## Unreleased
- `hourly-product-development`가 `NVIDIA_NIM_API_KEY`뿐 아니라 `NOEMA_MAINTAINER_APP_CLIENT_ID`와 `NOEMA_MAINTAINER_APP_PRIVATE_KEY` 존재를 checkout·OpenCode 설치·NVIDIA 호출 전에 검증한다. 게시 경로가 준비되지 않았으면 `maintainer_app_unavailable`로 실패 폐쇄하여 알려진 실패에 추론 비용을 쓰지 않으며, `dry_run`은 credential 없이 queue와 task contract를 검토하는 경로로 유지한다. 기존 reviewer App 및 `NOEMA_LLM_API_KEY`·`contextual-orchestrator` reviewer credential 경계는 변경하지 않는다.
- zero open pull requests일 때만 `NVIDIA_NIM_API_KEY` 전용 OpenCode 1.17.13 세션을 실행하는 proposal-only `hourly-product-development` 루프를 추가. minute-47 schedule·non-cancelling single flight·OpenCode binary SHA-256 pin·NVIDIA NIM model fallback·후보 실패 시 clean reset·GitHub/OIDC credential 제거·reviewer key 비참조·full release verification·40-file/500,000-byte proposal budget·trusted one-PR packaging을 강제한다. 각 후보 실행은 900초와 30초 kill grace로 제한하고, 실패 후 `npm ci --ignore-scripts` 재설치는 별도 60초와 10초 kill grace로 제한한다. 재설치가 실패하거나 시간 초과되면 불완전한 dependency tree로 다음 후보를 실행하지 않고 실패 폐쇄한다. 세 후보의 실행·종료 2,790초, 두 번의 후보 간 재설치 140초, 300초 setup/diagnostic reserve를 합친 3,230초가 55분(3,300초) job budget에 들어가며 70초 여유를 남긴다. 마지막 후보가 실패하면 불필요한 reset·clean·재설치를 생략하고 안정적인 전체 후보 실패 진단으로 곧바로 종료한다. 모델 실행, 제안 코드 검증, publication credential을 각각 별도의 GitHub-hosted runner로 분리하고, immutable artifact의 exact ID·workflow-run ID·archive digest와 patch SHA-256·base SHA·file/byte count를 교차 검증하며 symlink(`120000`)와 gitlink(`160000`)를 세 경계 모두에서 차단한다. 제안 코드를 실행한 runner에는 Maintainer App secret/token을 절대 제공하지 않고, 세 번째 non-executing publisher에서만 late-bound repository-scoped App token을 발급한다. merge/release/deploy authority는 기존 `hourly-commercial-readiness` exact-head governance에 유지하며, 운영 Runbook과 OpenCode/NVIDIA/GitHub Actions/NIST SP 800-218 근거를 APA 7th doctoring에 기록했다. package version은 release·deployment·production KPI evidence를 발행하지 않으므로 유지한다.
- `/health` liveness와 분리된 unauthenticated `GET`/`HEAD /ready` runtime readiness endpoint를 추가. GitHub Actions OIDC issuer·audience·organization/workflow binding·exact workflow ref·GitHub Cloud API origin·GitHub App identifiers·PKCS#8 private key를 외부 호출 없이 검증하며, 불완전한 설정은 secret/config value를 반사하지 않는 deterministic failure codes와 `503 ERR_SERVICE_NOT_READY`, `Retry-After`, no-store/nosniff/trace/latency headers로 실패-폐쇄한다. exact workflow named ref는 Git `check-ref-format`의 모호성·유효성 경계(`..`, `//`, dot-leading/`.lock` component, revision-expression 문자, trailing dot/slash 등)를 만족해야 하므로 GitHub가 실제로 표현할 수 없는 ref에서 false-ready가 발생하지 않는다. 배포 smoke contract가 liveness·runtime readiness·unauthenticated exchange challenge를 모두 요구하도록 확장하고 Kubernetes probe separation, RFC 9110, NIST SSDF, Git ref-format 근거를 APA 7th doctoring에 기록했다.
- 공개 readiness probe의 반복 WebCrypto 비용을 줄이되 binding freshness를 보존하도록 exact unchanged PKCS#8 PEM의 importability decision만 `WeakMap`으로 재사용한다. App id·audience·workflow ref·API boundary 등 비키 binding은 매 요청 재검증하고, Cloudflare가 binding-only 변경 후 isolate를 재사용해도 key rotation은 재import되므로 이전 `ready` 결과가 새 설정을 가리지 않는다. 동일 probe·비키 binding update·key rotation 현실 회귀 테스트와 Cloudflare Workers CPU/binding lifecycle 근거를 APA 7th doctoring에 기록했다.
- 배포 smoke evidence를 exact canonical `/exchange` endpoint에 결합하고 userinfo·query·fragment·trailing/alternate path·noncanonical URL은 probe 전에 차단한다. production은 HTTPS만 허용하고 loopback test만 HTTP를 허용하며, 각 probe에 5초 connect·15초 total timeout과 1 MiB response ceiling을 적용한다. 14개 status/schema/header 판단은 `jq`의 structured JSON으로 직렬화하고 canonical endpoint와 timestamp에 결합해 owner-only mode로 보존하며 RFC 3986 근거와 현실 회귀 테스트를 doctoring에 기록했다.
Expand Down
7 changes: 5 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,7 @@ Set `NOEMA_EXCHANGE_URL` in `ContextualWisdomLab/.github` variables to the deplo
- [운영 Runbook](./docs/runbook.md)
- [Distributed Rate Limiting](./docs/distributed-rate-limiting.md)
- [Hourly Commercial-Readiness Loop](./docs/hourly-commercial-readiness-loop.md)
- [Hourly NVIDIA NIM Product Development](./docs/operations/hourly-product-development.md)
- [SLA/지원 정책](./docs/sla-and-support.md)
- [가격 초안](./docs/pricing-draft.md)
- [관측성 KPI](./docs/observability-kpi.md)
Expand All @@ -110,6 +111,8 @@ Set `NOEMA_EXCHANGE_URL` in `ContextualWisdomLab/.github` variables to the deplo
- [Transfer Readiness Plan](./docs/transfer-readiness-plan.md)
- [Library Boundary Decision](./docs/library-boundary-decision.md)

`hourly-product-development.yml` runs a proposal-only OpenCode session through the dedicated `NVIDIA_NIM_API_KEY` credential when the PR queue is empty. It cannot review, merge, release, or deploy; the existing hourly commercial-readiness loop retains exact-head governance and SHA-bound merge authority.

## KPI 계산

```bash
Expand Down Expand Up @@ -141,10 +144,10 @@ NOEMA_KPI_REQUIRE_WINDOW_DAYS=30 npm run kpi:verify:strict
NOEMA_EXCHANGE_URL=https://.../exchange npm run smoke:check
```

`npm run smoke:check`는 `/health` `/exchange`의 스키마, 추적/지연 헤더, 401 Bearer challenge, no-store/nosniff 보안 헤더를 확인하고 실패 내역을 JSON으로 출력하며,
`npm run smoke:check`는 `/health`, `/ready`, `/exchange`의 스키마, 추적/지연 헤더, runtime readiness, 401 Bearer challenge, no-store/nosniff 보안 헤더를 확인하고 실패 내역을 JSON으로 출력하며,
배포에서 `NOEMA_SMOKE_EVIDENCE_PATH`를 지정하면 `noema-smoke-evidence.json` 형태로 증빙을 저장할 수 있습니다.

CI/CD의 `cd` 워크플로우는 동일 스크립트를 실행해 `/health`/`/exchange` 계약을 검증합니다.
CI/CD의 `cd` 워크플로우는 동일 스크립트를 실행해 `/health`/`/ready`/`/exchange` 계약을 검증합니다.

운영 증빙 수집 전에는 다음 preflight로 production URL과 KPI 로그 수집 입력이 준비됐는지 확인합니다.

Expand Down
Loading
Loading