ci: add main CI Slack alerts - #5863
Conversation
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
|
Caution Review failedAn error occurred during the review process. Please try again later. 📝 WalkthroughSummary by CodeRabbit
WalkthroughAdds a ChangesMain CI Slack alerting
Estimated code review effort: 2 (Simple) | ~10 minutes Sequence Diagram(s)sequenceDiagram
participant GitHubActions as GitHub Actions
participant MainCIWatcher as main-ci-slack-alerts.yml
participant GitHubAPI as GitHub API
participant SlackWebhook as Slack webhook URL(s)
GitHubActions->>MainCIWatcher: emits completed workflow_run for watched main-branch CI
MainCIWatcher->>GitHubAPI: gh api jobs for the workflow run
GitHubAPI-->>MainCIWatcher: job conclusions
MainCIWatcher->>MainCIWatcher: build payload and validate MAIN_CI_SLACK_WEBHOOK_URLS
MainCIWatcher->>SlackWebhook: POST alert payload to each webhook
SlackWebhook-->>MainCIWatcher: delivery result
🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
There was a problem hiding this comment.
✅ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| ✅ Approved | 0 | 0 | 0 | d487a95fde45 |
Head: d487a95fde4567fa3c231094109b01b2a2440ba8
Next: No reviewer action needed.
Run details
Status: Current
Needs human: no
Needs validation: no
Summary
No concrete actionable issues found in the main CI Slack alert workflow or README update.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas. - Use
@ironloopai statusto check queued/running/completed/failed/superseded state while reviewers run.
d487a95 to
81be944
Compare
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/main-ci-slack-alerts.yml:
- Around line 90-94: The webhook fan-out loop in the Slack alerts workflow stops
on the first failed `curl` because `set -euo pipefail` and `curl -f` make a
single 4xx/5xx abort the whole job. Update the loop that reads `webhook_file` so
each webhook send is isolated from failures and later URLs still run, and add a
bounded timeout to the `curl` call so an unresponsive endpoint cannot hang the
workflow. Keep the fix localized around the webhook posting logic and its
`posted` counter.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e4651362-3e26-4161-8f3c-2ccb02469f7c
📒 Files selected for processing (2)
.github/workflows/README.md.github/workflows/main-ci-slack-alerts.yml
|
🚅 Deployed to the ironclaw-pr-5863 environment in ironclaw-ci-preview
|
There was a problem hiding this comment.
✅ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| ✅ Approved | 0 | 0 | 0 | 81be9440d0c0 |
Head: 81be9440d0c0ce8657b975c3401bf1b9795acd1e
Next: No reviewer action needed.
Run details
Status: Current
Needs human: no
Needs validation: no
Summary
No concrete actionable issues found in the main CI Slack alert workflow or the accompanying workflow README update.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas. - Use
@ironloopai statusto check queued/running/completed/failed/superseded state while reviewers run.
81be944 to
8efccf2
Compare
There was a problem hiding this comment.
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/main-ci-slack-alerts.yml:
- Line 87: The webhook URL handling in the CI Slack alerts workflow only removes
blank lines after splitting on commas, so entries with surrounding spaces are
still passed through untrimmed. Update the shell pipeline that writes to
webhook_file so each value from webhooks is whitespace-trimmed after the comma
split, ensuring names/URLs like "url1, url2" are normalized before later curl
usage.
- Around line 86-87: The temp file created for secret webhook URLs in the
workflow is not cleaned up after use. Update the shell block around webhook_file
creation and consumption to register a trap that removes the mktemp file when
the step exits, so the cleanup happens even on failure.
- Around line 89-99: The alert posting loop in the main CI Slack workflow should
fail the job when no webhook receives the message. Keep the per-webhook curl
handling in the posting block, but after the loop in the script section that
uses posted and webhook_file, add a check for posted being zero and exit
non-zero with a clear error so the workflow is red when every Slack delivery
fails.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 6fcd952f-2e73-4e28-a0e0-569b231ad3d8
📒 Files selected for processing (2)
.github/workflows/README.md.github/workflows/main-ci-slack-alerts.yml
| HEAD_SHA: ${{ github.event.workflow_run.head_sha }} | ||
| HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }} | ||
| ACTOR: ${{ github.event.workflow_run.actor.login }} | ||
| MAIN_CI_SLACK_WEBHOOK_URLS: ${{ secrets.MAIN_CI_SLACK_WEBHOOK_URLS }} |
There was a problem hiding this comment.
MAIN_CI_SLACK_WEBHOOK_URLS secret has been configured in the repo.
Summary
workflow_runSlack alert workflow for failed push-to-main CI workflows.MAIN_CI_SLACK_WEBHOOK_URLSsecret, which can contain one or more Slack webhook URLs.Change Type
Linked Issue
None.
Security Impact
This introduces a new repository secret,
MAIN_CI_SLACK_WEBHOOK_URLS, for Slack incoming webhook URLs. The workflow does not print webhook values, removes the temporary file containing them on exit, and uses the dedicated secret rather than reusing the canary/nightly Slack webhook.Rollback Plan
Disable or delete
.github/workflows/main-ci-slack-alerts.yml, or unsetMAIN_CI_SLACK_WEBHOOK_URLSto stop delivery. The change does not affect test execution or merge-gating workflows themselves.Validation
bash -non the embedded alert script.git diff --checkfor the changed workflow files.actionlintis not installed in this workspace, so it was not run.