Skip to content

feat(OMN-13226): GitHub Action publisher for onex.evt.github.pr-merged.v1 - #1264

Merged
jonahgabriel merged 3 commits into
devfrom
jonahgabriel/omn-13226-t2-github-action-publisher-pr-merged
Jun 18, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
jonahgabriel/omn-13226-t2-github-action-publisher-pr-merged

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Implements T2 of the merge-triggered worktree reaper epic (OMN-13008 child OMN-13226).

  • New GHA workflow .github/workflows/pr-merged-publisher.yml fires on pull_request: closed with merged == true, publishing {repo, branch, pr_number, ticket, merged_at} to onex.evt.github.pr-merged.v1 via the same SASL_SSL Kafka transport as OMN-8917 / trigger_rebuild_on_merge.py.
  • New publisher script scripts/publish_pr_merged_event.py — modelled exactly on trigger_rebuild_on_merge.py; a thin Kafka producer with --dry-run support; unit tests with a mocked Producer assert the correct topic + payload shape.
  • Topic registered in src/omnimarket/events/topics.py as PR_MERGED_TOPIC_V1 (onex.evt.github.pr-merged.v1).
  • Consuming-node contract node_pr_merged_projection/contract.yaml declares subscribe_topics: [onex.evt.github.pr-merged.v1] so the topic registry and node-drift gate are green. The materializing projection handler (read via GET /projection/onex.evt.github.pr-merged.v1 at :3002) is the scope of T3 (OMN-13227).
  • Golden-chain contract tests verify topic naming, node_type, and runtime_dispatch shape; unit tests cover the publisher payload.

F3 broker decision (plan §6 F3) — resolved by verified reachability

Decision: publish to the canonical bus via SASL_SSL using KAFKA_BOOTSTRAP_SERVERS resolved from the runner Infisical environment (exactly the OMN-8917 transport); the T3 projection node bridges/materializes onto the .201 lane so /projection/... is served at :3002.

Evidence:

  • The OMN-8917 template (runtime-rebuild-trigger.yml / trigger_rebuild_on_merge.py:81,98,271) publishes via security.protocol=SASL_SSL to KAFKA_BOOTSTRAP_SERVERS. pr-review-bot.yml:108 documents that KAFKA_BOOTSTRAP_SERVERS is pre-mounted in the runner's Infisical environment.
  • This PR's pr-merged-publisher.yml reuses that transport verbatim rather than reinventing a broker path. Whichever runner placement the org's OMNI_TRUSTED_CI_RUNS_ON_JSON selects, the publisher emits to the canonical bus the Infisical KAFKA_BOOTSTRAP_SERVERS points at.
  • Because repo workflows default to cloud (ubuntu-latest) runners that cannot reach the private LAN broker directly, the materialization onto the .201 lane that feeds GET /projection/onex.evt.github.pr-merged.v1 at :3002 is performed by the T3 projection node (OMN-13227) — i.e. the "publish to the canonical bus AND bridge/materialize onto the .201 lane" arm of F3. T2 ships the producer + topic + consuming-node contract; T3 makes the :3002 projection materialize.

DoD evidence

  • uv run pytest tests/unit/scripts/test_publish_pr_merged_event.py tests/test_golden_chain_pr_merged_projection.py -q → 15 passed
  • pre-commit run --all-files → all hooks pass
  • Topic onex.evt.github.pr-merged.v1 registered in events/topics.py as PR_MERGED_TOPIC_V1 and declared in node_pr_merged_projection/contract.yaml subscribe_topics
  • All functional CI green (Tests 1-20/20, Golden Chain Suite, Runtime Sweep, Contract Compliance, node-drift-gate, topic-naming-lint, imperative-contract-guard)

OCC receipt

Paired OCC receipt PR: OmniNode-ai/onex_change_control#2746 adds contracts/OMN-13226.yaml + PASS DoD receipts (dod-001-publisher-implementation, dod-002-deploy-evidence carrying the rpk topic produce deploy evidence, and pr-occ-binding). Local proof: receipt-gate PASSED (3/3), OCC eligibility eligible=true.

Evidence-Source: a1d578a1ee58a3c26d49fc63431e7b9ac4029648
Evidence-Ticket: OMN-13226

…d.v1

Adds the T2 thin-publisher layer for the merge-triggered worktree reaper
(OMN-13008 sub-ticket OMN-13226).

Changes:
- scripts/publish_pr_merged_event.py: thin Confluent Cloud publisher
  modelled on trigger_rebuild_on_merge.py (OMN-8917); publishes
  {repo, branch, pr_number, ticket, merged_at} to canonical topic
  onex.evt.github.pr-merged.v1 on every PR merge
- .github/workflows/pr-merged-publisher.yml: GHA workflow on
  pull_request: closed + merged==true; ubuntu-latest (cloud runner)
- src/omnimarket/events/topics.py: registers PR_MERGED_TOPIC_V1
- src/omnimarket/nodes/node_pr_merged_projection/: contract stub
  (runtime_dispatch.addressable=false, handler_routing forward-declared
  for T3 OMN-13227); registers subscribe_topics for topic registry green
- tests/unit/scripts/test_publish_pr_merged_event.py: 8 unit tests
  with mocked Producer asserting correct topic + payload shape
- tests/test_golden_chain_pr_merged_projection.py: 7 contract tests
- tests/test_market_node_runtime_dogfood.py: node count 311→312,
  skipped 3→4, stub in non_addressable set
- pyproject.toml: registers node_pr_merged_projection entry point
- .pre-commit-config.yaml: excludes scripts/publish_pr_merged_event.py
  from no-hardcoded-topics (same pattern as trigger_rebuild_on_merge.py)

F3 broker decision (per plan §6 F3): workflow runs on ubuntu-latest
(cloud runner) and cannot reach the private .201 LAN broker. We publish
to Confluent Cloud exactly like OMN-8917. T3 (OMN-13227) bridges
Confluent → .201 Redpanda so GET /projection/onex.evt.github.pr-merged.v1
materialises locally for the reaper (T4, OMN-13228) to poll.
@coderabbitai

coderabbitai Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@jonahgabriel, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 24 minutes and 4 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 8413052c-7c67-4a09-904f-e6e7bb8818cc

📥 Commits

Reviewing files that changed from the base of the PR and between 0f11655 and 2d0c45f.

📒 Files selected for processing (17)
  • .github/workflows/pr-merged-publisher.yml
  • .pre-commit-config.yaml
  • docs/evidence/dep-health-sweep/proof-of-life-001/findings.json
  • docs/evidence/dep-health-sweep/proof-of-life-001/projection_rows.json
  • docs/evidence/dep-health-sweep/proof-of-life-001/proof_summary.md
  • docs/evidence/dep-health-sweep/proof-of-life-001/run_manifest.json
  • pyproject.toml
  • scripts/publish_pr_merged_event.py
  • src/omnimarket/events/topics.py
  • src/omnimarket/nodes/node_pr_merged_projection/__init__.py
  • src/omnimarket/nodes/node_pr_merged_projection/contract.yaml
  • src/omnimarket/nodes/node_pr_merged_projection/handlers/__init__.py
  • src/omnimarket/nodes/node_pr_merged_projection/handlers/handler_pr_merged_projection.py
  • src/omnimarket/nodes/node_pr_merged_projection/metadata.yaml
  • tests/test_golden_chain_pr_merged_projection.py
  • tests/test_market_node_runtime_dogfood.py
  • tests/unit/scripts/test_publish_pr_merged_event.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonahgabriel/omn-13226-t2-github-action-publisher-pr-merged

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
github-actions Bot enabled auto-merge June 18, 2026 14:41
@github-actions

github-actions Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

✅ Architectural Review — PASSED

Errors: 0
Warnings: 0

What this checks

Rule Description
ARCH-TOPIC-001 No hardcoded Kafka topic strings in handler code
ARCH-DI-001 No event_bus=None bypass
ARCH-DI-002 No direct Handler instantiation outside workflow_runner/adapters
ARCH-DI-003 No reinvented DI containers
ARCH-TOPIC-002 contract.yaml topics follow `onex.{cmd

No architectural violations found.

Powered by node_pr_review_bot

@github-actions

github-actions Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

✅ PR Review Bot — CLEAN

Findings: 0
Run ID: ``

Required gate: This check blocks merge when verdict is blocking_issue.


Verdict semantics

Verdict Meaning
clean No blocking findings
risks_noted Findings noted; threads passed judge verification
blocking_issue MAJOR/CRITICAL findings not resolved — do not merge

Powered by node_pr_review_bot — Qwen3-Coder-30B reviewer + DeepSeek-R1 judge (OMN-7963)

@github-actions

github-actions Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

⚠️ Hostile Reviewer — DEGRADED (informational)

Blocking findings (critical/error): 0
Total findings: 0
Models succeeded: none

Note: All reviewer models failed or were unavailable. Degraded results are informational during the pilot phase (OMN-8524) and do not block merge. Error: cli_review exited non-zero (all models failed or binary error)


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical/error findings No
blocked CRITICAL or ERROR findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8524)

…als, test branch names

- Add handlers/handler_pr_merged_projection.py stub (importable class
  satisfies test_handler_routing_no_protocol_targets parametrized test)
- Remove LAN IP literals from comments in workflow and publisher script
  (resolves Leaked Literals Gate)
- Replace personal branch prefixes in tests with generic constants
  (resolves Leaked Literals Gate for test file)
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 18, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jun 18, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 18, 2026
Clarify the pr-merged publisher header + secret descriptions: the publisher
emits via SASL_SSL to whatever KAFKA_BOOTSTRAP_SERVERS resolves to in the
runner Infisical environment (the canonical bus endpoint), not a hardcoded
single provider. The T3 projection node (OMN-13227) bridges/materializes onto
the .201 Redpanda lane so GET /projection/onex.evt.github.pr-merged.v1 is
served at :3002 for the T4 reaper.

Re-triggers deploy-gate (synchronize) now that paired OCC contract
OMN-13226.yaml carries rpk-produce deploy evidence (onex_change_control #2746).

Evidence-Source: 994b5bf5b1c124fc02f1657a6cb02ba552b13266
Evidence-Ticket: OMN-13226
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jun 18, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 18, 2026
Merged via the queue into dev with commit 1ebbaef Jun 18, 2026
69 of 70 checks passed
@jonahgabriel
jonahgabriel deleted the jonahgabriel/omn-13226-t2-github-action-publisher-pr-merged branch June 18, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant