Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 2 additions & 1 deletion .claude/settings.local.json
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,8 @@
"Read(//Volumes/PRO-G40/Code/omnibase_spi/src/omnibase_spi/protocols/**)",
"Read(//Volumes/PRO-G40/Code/omnibase_spi/src/**)",
"mcp__serena__onboarding",
"Read(//Volumes/PRO-G40/Code/omnibase_spi/**)"
"Read(//Volumes/PRO-G40/Code/omnibase_spi/**)",
"Read(//Users/jonah/Library/Caches/pypoetry/virtualenvs/omnibase-infra-12tLMu6n-py3.12/lib/python3.12/site-packages/omnibase_core/validation/**)"
],
"deny": [],
"ask": []
Expand Down
9 changes: 4 additions & 5 deletions .github/workflows/claude-code-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,14 +17,14 @@ jobs:
# github.event.pull_request.user.login == 'external-contributor' ||
# github.event.pull_request.user.login == 'new-developer' ||
# github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR'

runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
issues: read
id-token: write

steps:
- name: Checkout repository
uses: actions/checkout@v4
Expand All @@ -44,12 +44,11 @@ jobs:
- Performance considerations
- Security concerns
- Test coverage

Use the repository's CLAUDE.md for guidance on style and conventions. Be constructive and helpful in your feedback.

Use `gh pr comment` with your Bash tool to leave your review as a comment on the PR.

# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://docs.anthropic.com/en/docs/claude-code/sdk#command-line for available options
claude_args: '--allowed-tools "Bash(gh issue view:*),Bash(gh search:*),Bash(gh issue list:*),Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr list:*)"'

3 changes: 1 addition & 2 deletions .github/workflows/claude.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}

# This is an optional setting that allows Claude to read CI results on PRs
additional_permissions: |
actions: read
Expand All @@ -47,4 +47,3 @@ jobs:
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://docs.anthropic.com/en/docs/claude-code/sdk#command-line for available options
# claude_args: '--model claude-opus-4-1-20250805 --allowed-tools Bash(gh pr:*)'

2 changes: 1 addition & 1 deletion .github/workflows/quality-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -89,4 +89,4 @@ jobs:
echo "1. Fix import paths and add test dependencies"
echo "2. Address type safety issues"
echo "3. Migrate Pydantic validators"
echo "4. Remove continue-on-error flags progressively"
echo "4. Remove continue-on-error flags progressively"
60 changes: 18 additions & 42 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -87,58 +87,34 @@ repos:
# Exclude test files and examples
exclude: ^(tests/|src/omnibase_infra/examples|scripts/).*\.py$

# Infrastructure Validation
- id: validate-infrastructure-config
name: ONEX Infrastructure Config Validation
entry: poetry run python scripts/validate-infrastructure.py
# Available Infrastructure Validations (using existing scripts)
- id: validate-structure
name: ONEX Structure Validation
entry: poetry run python scripts/validation/validate_structure.py . omnibase_infra
language: system
pass_filenames: false
files: ^(terraform/|ansible/|kubernetes/|docker/).*$
stages: [commit]

# Docker Compose Validation
- id: validate-docker-compose
name: Docker Compose Validation
entry: docker compose config
language: system
files: ^docker-compose.*\.ya?ml$
stages: [commit]

# Kubernetes Manifest Validation
- id: validate-k8s-manifests
name: Kubernetes Manifest Validation
entry: poetry run python scripts/validate-k8s-manifests.py
language: system
pass_filenames: true
files: ^kubernetes/.*\.ya?ml$
stages: [commit]

# Security scanning for infrastructure
- id: infrastructure-security-scan
name: Infrastructure Security Scan
entry: poetry run python scripts/security-scan.py
- id: validate-naming
name: ONEX Naming Convention Validation
entry: poetry run python scripts/validation/validate_naming.py
language: system
pass_filenames: true
files: ^(terraform/|ansible/|kubernetes/|docker/).*$
pass_filenames: false
stages: [commit]

# String Version Validation (inherited from parent)
- id: validate-string-versions
name: ONEX String Version Validation
entry: poetry run python scripts/validate-string-versions.py
- id: audit-optional
name: ONEX Optional Usage Audit
entry: poetry run python scripts/validation/audit_optional.py
language: system
pass_filenames: true
files: ^.*\.(yaml|yml)$
pass_filenames: false
stages: [commit]

# Prevent Manual YAML Validation (inherited from parent)
- id: validate-no-manual-yaml
name: ONEX Prevent Manual YAML Validation
entry: poetry run python scripts/validate-no-manual-yaml.py
# Docker Compose Validation (if file exists)
- id: validate-docker-compose
name: Docker Compose Validation
entry: docker compose config
language: system
pass_filenames: true
files: ^.*\.py$
exclude: ^scripts/validate-.*\.py$
files: ^docker-compose.*\.ya?ml$
stages: [commit]

# Configuration
Expand All @@ -149,4 +125,4 @@ ci:
for more information, see https://pre-commit.ci
autofix_prs: true
autoupdate_schedule: weekly
submodules: false
submodules: false
2 changes: 1 addition & 1 deletion .serena/memories/code_standards.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,4 +37,4 @@
- **Connection Pooling**: Database connections via dedicated managers
- **Event-Driven**: Infrastructure events through Kafka adapters
- **Security-First**: All components must pass security audits
- **Observability**: All tools must include monitoring/metrics
- **Observability**: All tools must include monitoring/metrics
68 changes: 34 additions & 34 deletions .serena/memories/configuration_consolidation_specs.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ from omnibase_core.core.core_error_codes import CoreErrorCode

class CentralizedConfigValidator:
"""Centralized configuration validation for infrastructure components."""

@classmethod
def validate_startup_configuration(cls) -> Dict[str, Any]:
"""Validate all infrastructure configuration at startup."""
Expand All @@ -27,15 +27,15 @@ class CentralizedConfigValidator:
'circuit_breaker_config': cls._validate_circuit_breaker_config(),
'kafka_producer_config': cls._validate_kafka_producer_config()
}

# Aggregate validation errors
errors = [result for result in validation_results.values() if 'error' in result]
if errors:
raise OnexError(
code=CoreErrorCode.CONFIGURATION_ERROR,
message=f"Configuration validation failed: {errors}"
)

return validation_results
```

Expand All @@ -55,31 +55,31 @@ async def validate_event_bus_connectivity(self) -> Dict[str, Any]:
'authentication_status': 'unknown',
'ssl_verification': 'unknown'
}

try:
# Test basic connectivity
start_time = time.time()
# ... connectivity test implementation ...
response_time = (time.time() - start_time) * 1000

validation_result.update({
'connectivity_status': 'connected',
'response_time_ms': response_time,
'authentication_status': 'authenticated',
'ssl_verification': 'verified'
})

# Validate topic accessibility
validation_result['topic_accessibility'] = await self._validate_topic_access()

except Exception as e:
validation_result['connectivity_status'] = 'failed'
validation_result['error'] = str(e)
raise OnexError(
code=CoreErrorCode.EXTERNAL_SERVICE_ERROR,
message=f"Event bus connectivity validation failed: {e}"
) from e

return validation_result
```

Expand All @@ -98,30 +98,30 @@ async def validate_database_connectivity(self) -> Dict[str, Any]:
'permissions_check': 'unknown',
'performance_baseline': {}
}

try:
# Test basic connectivity
async with self.acquire_connection() as conn:
# Validate database version compatibility
db_version = await conn.fetchval("SELECT version()")
validation_result['database_version'] = db_version

# Validate schema accessibility
schema_tables = await conn.fetch(
"SELECT table_name FROM information_schema.tables WHERE table_schema = $1",
self.config.schema
)
validation_result['schema_tables'] = [row['table_name'] for row in schema_tables]

# Test basic operations permissions
await conn.execute("SELECT 1") # Read permission
validation_result['permissions_check'] = 'validated'

# Establish performance baseline
start_time = time.time()
await conn.execute("SELECT pg_sleep(0.001)") # 1ms sleep test
baseline_latency = (time.time() - start_time) * 1000

validation_result.update({
'connectivity_status': 'connected',
'connection_pool_status': 'healthy',
Expand All @@ -131,15 +131,15 @@ async def validate_database_connectivity(self) -> Dict[str, Any]:
'connection_acquire_time_ms': 0.0 # To be measured
}
})

except Exception as e:
validation_result['connectivity_status'] = 'failed'
validation_result['error'] = str(e)
raise OnexError(
code=CoreErrorCode.DATABASE_CONNECTION_ERROR,
message=f"Database connectivity validation failed: {e}"
) from e

return validation_result
```

Expand All @@ -156,28 +156,28 @@ def validate_circuit_breaker_thresholds(self) -> Dict[str, Any]:
'configuration_consistency': 'unknown',
'operational_parameters': {}
}

try:
# Validate failure threshold
if self.config.failure_threshold <= 0:
raise ValueError("Failure threshold must be positive")

# Validate recovery timeout
if self.config.recovery_timeout <= 0:
raise ValueError("Recovery timeout must be positive")

# Validate success threshold for half-open state
if self.config.success_threshold <= 0:
raise ValueError("Success threshold must be positive")

# Validate timeout consistency
if self.config.timeout_seconds >= self.config.recovery_timeout:
raise ValueError("Operation timeout should be less than recovery timeout")

# Validate queue size
if self.config.max_queue_size <= 0:
raise ValueError("Max queue size must be positive")

validation_result.update({
'threshold_validation': 'validated',
'configuration_consistency': 'consistent',
Expand All @@ -189,15 +189,15 @@ def validate_circuit_breaker_thresholds(self) -> Dict[str, Any]:
'estimated_recovery_cycles': self._calculate_recovery_cycles()
}
})

except Exception as e:
validation_result['threshold_validation'] = 'failed'
validation_result['error'] = str(e)
raise OnexError(
code=CoreErrorCode.CONFIGURATION_ERROR,
message=f"Circuit breaker threshold validation failed: {e}"
) from e

return validation_result
```

Expand Down Expand Up @@ -235,30 +235,30 @@ class InfrastructureValidationResult:

class InfrastructureConfigValidator:
"""Centralized validator for all infrastructure components."""

def __init__(self):
self.validation_results: List[InfrastructureValidationResult] = []
self.overall_status: str = 'unknown'
self.validation_start_time: Optional[datetime] = None
self.validation_duration_ms: float = 0.0

async def validate_all_infrastructure(self) -> Dict[str, Any]:
"""Validate all infrastructure components."""
self.validation_start_time = datetime.now()
start_time = time.time()

try:
# Run all validations in parallel for efficiency
validation_tasks = [
self._validate_postgres_infrastructure(),
self._validate_kafka_infrastructure(),
self._validate_kafka_infrastructure(),
self._validate_circuit_breaker_infrastructure(),
self._validate_observability_infrastructure()
]

# Wait for all validations to complete
results = await asyncio.gather(*validation_tasks, return_exceptions=True)

# Process results and handle any exceptions
for result in results:
if isinstance(result, Exception):
Expand All @@ -275,14 +275,14 @@ class InfrastructureConfigValidator:
)
else:
self.validation_results.extend(result)

# Determine overall status
self._determine_overall_status()

self.validation_duration_ms = (time.time() - start_time) * 1000

return self._generate_validation_report()

except Exception as e:
self.overall_status = 'critical_error'
raise OnexError(
Expand Down Expand Up @@ -318,4 +318,4 @@ class InfrastructureConfigValidator:
- All validation results must be observable
- Integration with existing monitoring infrastructure
- Alerting for configuration validation failures
- Historical tracking of validation performance
- Historical tracking of validation performance
2 changes: 1 addition & 1 deletion .serena/memories/observability_enhancement_specs.md
Original file line number Diff line number Diff line change
Expand Up @@ -160,4 +160,4 @@ class ConnectionLifecycleMetrics:
- <1% performance overhead from metrics collection
- Real-time visibility into all component performance
- Actionable alerts for performance degradation
- Trend analysis capability for capacity planning
- Trend analysis capability for capacity planning
Loading
Loading