Repository navigation
feat(OMN-13226): GitHub Action publisher for onex.evt.github.pr-merged.v1 - #1264
jonahgabriel merged 3 commits into
Conversation
…d.v1
Adds the T2 thin-publisher layer for the merge-triggered worktree reaper
(OMN-13008 sub-ticket OMN-13226).
Changes:
- scripts/publish_pr_merged_event.py: thin Confluent Cloud publisher
modelled on trigger_rebuild_on_merge.py (OMN-8917); publishes
{repo, branch, pr_number, ticket, merged_at} to canonical topic
onex.evt.github.pr-merged.v1 on every PR merge
- .github/workflows/pr-merged-publisher.yml: GHA workflow on
pull_request: closed + merged==true; ubuntu-latest (cloud runner)
- src/omnimarket/events/topics.py: registers PR_MERGED_TOPIC_V1
- src/omnimarket/nodes/node_pr_merged_projection/: contract stub
(runtime_dispatch.addressable=false, handler_routing forward-declared
for T3 OMN-13227); registers subscribe_topics for topic registry green
- tests/unit/scripts/test_publish_pr_merged_event.py: 8 unit tests
with mocked Producer asserting correct topic + payload shape
- tests/test_golden_chain_pr_merged_projection.py: 7 contract tests
- tests/test_market_node_runtime_dogfood.py: node count 311→312,
skipped 3→4, stub in non_addressable set
- pyproject.toml: registers node_pr_merged_projection entry point
- .pre-commit-config.yaml: excludes scripts/publish_pr_merged_event.py
from no-hardcoded-topics (same pattern as trigger_rebuild_on_merge.py)
F3 broker decision (per plan §6 F3): workflow runs on ubuntu-latest
(cloud runner) and cannot reach the private .201 LAN broker. We publish
to Confluent Cloud exactly like OMN-8917. T3 (OMN-13227) bridges
Confluent → .201 Redpanda so GET /projection/onex.evt.github.pr-merged.v1
materialises locally for the reaper (T4, OMN-13228) to poll.
|
Warning Review limit reached
More reviews will be available in 24 minutes and 4 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (17)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
✅ Architectural Review — PASSEDErrors: 0 What this checks
No architectural violations found. Powered by node_pr_review_bot |
✅ PR Review Bot — CLEANFindings: 0
Verdict semantics
Powered by node_pr_review_bot — Qwen3-Coder-30B reviewer + DeepSeek-R1 judge (OMN-7963) |
|
| Verdict | Meaning | Blocks merge? |
|---|---|---|
passed |
No critical/error findings | No |
blocked |
CRITICAL or ERROR findings found | Yes |
degraded |
All models unavailable (infra) | No (pilot) |
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8524)
…als, test branch names - Add handlers/handler_pr_merged_projection.py stub (importable class satisfies test_handler_routing_no_protocol_targets parametrized test) - Remove LAN IP literals from comments in workflow and publisher script (resolves Leaked Literals Gate) - Replace personal branch prefixes in tests with generic constants (resolves Leaked Literals Gate for test file)
Clarify the pr-merged publisher header + secret descriptions: the publisher emits via SASL_SSL to whatever KAFKA_BOOTSTRAP_SERVERS resolves to in the runner Infisical environment (the canonical bus endpoint), not a hardcoded single provider. The T3 projection node (OMN-13227) bridges/materializes onto the .201 Redpanda lane so GET /projection/onex.evt.github.pr-merged.v1 is served at :3002 for the T4 reaper. Re-triggers deploy-gate (synchronize) now that paired OCC contract OMN-13226.yaml carries rpk-produce deploy evidence (onex_change_control #2746). Evidence-Source: 994b5bf5b1c124fc02f1657a6cb02ba552b13266 Evidence-Ticket: OMN-13226
Summary
Implements T2 of the merge-triggered worktree reaper epic (OMN-13008 child OMN-13226).
.github/workflows/pr-merged-publisher.ymlfires onpull_request: closedwithmerged == true, publishing{repo, branch, pr_number, ticket, merged_at}toonex.evt.github.pr-merged.v1via the same SASL_SSL Kafka transport as OMN-8917 /trigger_rebuild_on_merge.py.scripts/publish_pr_merged_event.py— modelled exactly ontrigger_rebuild_on_merge.py; a thin Kafka producer with--dry-runsupport; unit tests with a mockedProducerassert the correct topic + payload shape.src/omnimarket/events/topics.pyasPR_MERGED_TOPIC_V1(onex.evt.github.pr-merged.v1).node_pr_merged_projection/contract.yamldeclaressubscribe_topics: [onex.evt.github.pr-merged.v1]so the topic registry and node-drift gate are green. The materializing projection handler (read viaGET /projection/onex.evt.github.pr-merged.v1at :3002) is the scope of T3 (OMN-13227).node_type, andruntime_dispatchshape; unit tests cover the publisher payload.F3 broker decision (plan §6 F3) — resolved by verified reachability
Decision: publish to the canonical bus via SASL_SSL using
KAFKA_BOOTSTRAP_SERVERSresolved from the runner Infisical environment (exactly the OMN-8917 transport); the T3 projection node bridges/materializes onto the .201 lane so/projection/...is served at :3002.Evidence:
runtime-rebuild-trigger.yml/trigger_rebuild_on_merge.py:81,98,271) publishes viasecurity.protocol=SASL_SSLtoKAFKA_BOOTSTRAP_SERVERS.pr-review-bot.yml:108documents thatKAFKA_BOOTSTRAP_SERVERSis pre-mounted in the runner's Infisical environment.pr-merged-publisher.ymlreuses that transport verbatim rather than reinventing a broker path. Whichever runner placement the org'sOMNI_TRUSTED_CI_RUNS_ON_JSONselects, the publisher emits to the canonical bus the InfisicalKAFKA_BOOTSTRAP_SERVERSpoints at.ubuntu-latest) runners that cannot reach the private LAN broker directly, the materialization onto the .201 lane that feedsGET /projection/onex.evt.github.pr-merged.v1at :3002 is performed by the T3 projection node (OMN-13227) — i.e. the "publish to the canonical bus AND bridge/materialize onto the .201 lane" arm of F3. T2 ships the producer + topic + consuming-node contract; T3 makes the :3002 projection materialize.DoD evidence
uv run pytest tests/unit/scripts/test_publish_pr_merged_event.py tests/test_golden_chain_pr_merged_projection.py -q→ 15 passedpre-commit run --all-files→ all hooks passonex.evt.github.pr-merged.v1registered inevents/topics.pyasPR_MERGED_TOPIC_V1and declared innode_pr_merged_projection/contract.yaml subscribe_topicsOCC receipt
Paired OCC receipt PR: OmniNode-ai/onex_change_control#2746 adds
contracts/OMN-13226.yaml+ PASS DoD receipts (dod-001-publisher-implementation,dod-002-deploy-evidencecarrying therpk topic producedeploy evidence, andpr-occ-binding). Local proof: receipt-gate PASSED (3/3), OCC eligibilityeligible=true.Evidence-Source: a1d578a1ee58a3c26d49fc63431e7b9ac4029648
Evidence-Ticket: OMN-13226