fix(automation): harden hourly maintenance credentials - #69
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review Please review exact current head |
|
I will review only the current
|
|
Superseded by the live protected-main governance gap tracked in #157. Fresh protected main |
Scope
This Draft is the repository-local scheduler hardening replacement for superseded #67. It is limited to hourly maintenance credentials, concurrency, RCA/feasibility behavior, and writer-lease recovery. Exact-source CI governance remains independently owned by #88.
Scheduler and trust boundary
queue: maxandcancel-in-progress: false;60de3e6b6e8363c0aa3de8276f42a67597b2599cfor Draft verification only;contents: readandid-token: write;GITHUB_TOKENwithout repository-write authority;PR_REVIEW_MERGE_TOKENandOPENCODE_APPROVE_TOKENfallbacks, neversecrets: inheritin the review-fix plane;NVIDIA_NIM_API_KEYinside the separately reviewed central worker and keepCOPILOT_GITHUB_TOKENout of the product caller; andNo temporary repair workflow, generated coverage database, release/publication, new long-lived credential, or new model credential is introduced.
RCA -> remedy -> proof
The previous Draft candidate pin became stale when read-only central #782 advanced. The leaf-owned workflow was correctly moved to
60de3e6b6e8363c0aa3de8276f42a67597b2599c, but sourcee535bf940dfcae701103c7937a90c1738a8a8bfeexposed a repository-owned regression in the general workflow contract:tests/test_workflow_contracts.pystill hard-coded predecessor candidate17bd5e4a98a718012dcb82d5028aa697a4ca8077.CI
31518697857failed exactly that mismatch: Python 3.10 reported1 failed, 354 passed, 3 deselected; the failed test wastest_hourly_workflow_repairs_revalidates_and_merges_pull_requests. The dedicated scheduler credential-boundary test already expected60de3e6b6e8363c0aa3de8276f42a67597b2599c, so the first failing boundary was the stale shared test rather than the workflow or central candidate.Current source
b27c0c4ac27996581ead3f1ba766e303113a1cdbapplies the smallest root-cause repair: the shared workflow contract now expects the same exact immutable candidate as the permanent scheduler workflow and dedicated boundary test. It does not change the workflow, permissions, central source, credentials, or production package behavior.Current exact state
b27c0c4ac27996581ead3f1ba766e303113a1cdb.main:bf2cc2e140dc3ff4a56c3203f80f41bb9fed5d10.31526608108: completed / success.31526607995: completed / success.31526607894: completed / success.The predecessor CI failure is retained as RCA evidence only and does not transfer to this head. These current PR-triggered successes are still staged merge-compatibility evidence because protected
mainhas not yet integrated #88 exact-source checkout governance; they are not final exact contributor-head acceptance.Read-only central prerequisites
OPENCODE_REPOSITORY_DISPATCH_TARGETSauthorization remains an external configuration-evidence boundary because this writer cannot read the relevant organization/repository variable through the connected credential; do not infer membership or weaken the allow-list;Central movement is dependency drift, not a pg-llm-batch writer conflict.
Promotion / merge boundary
Keep #69 Draft until central scheduler prerequisite #782 reaches protected
.github/main, caller-visible dispatch authorization forContextualWisdomLab/pg-llm-batchis proven, and current leaf evidence is regenerated under protected exact-source governance. Then replace the temporary candidate pin with the exact protected integration SHA and reacquire affected CI/security/coverage/package/provenance/review/branch/release gates.Merge only with zero valid unresolved findings and every approval requirement actually imposed by live policy. Predecessor, generated-merge-only, queued, pending, cancelled, skipped-required, absent, neutral-required, status-only, author-only, infrastructure-only, or failed evidence is not final acceptance.