Skip to content

ci: add main CI Slack alerts - #5863

Merged
think-in-universe merged 2 commits into
mainfrom
codex/main-ci-slack-alerts
Jul 9, 2026
Merged

think-in-universe merged 2 commits into
mainfrom
codex/main-ci-slack-alerts

Conversation

@think-in-universe

@think-in-universe think-in-universe commented Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add a workflow_run Slack alert workflow for failed push-to-main CI workflows.
  • Send alerts only through the dedicated MAIN_CI_SLACK_WEBHOOK_URLS secret, which can contain one or more Slack webhook URLs.
  • Document the main branch alerting contract and update instructions for newly added push-to-main workflows.
  • Harden webhook fan-out so individual delivery failures do not skip later webhooks, zero successful sends fail the alert job, webhook URLs are trimmed, and temp files are cleaned up.

Change Type

  • CI / workflow alerting
  • Documentation

Linked Issue

None.

Security Impact

This introduces a new repository secret, MAIN_CI_SLACK_WEBHOOK_URLS, for Slack incoming webhook URLs. The workflow does not print webhook values, removes the temporary file containing them on exit, and uses the dedicated secret rather than reusing the canary/nightly Slack webhook.

Rollback Plan

Disable or delete .github/workflows/main-ci-slack-alerts.yml, or unset MAIN_CI_SLACK_WEBHOOK_URLS to stop delivery. The change does not affect test execution or merge-gating workflows themselves.

Validation

  • Parsed the workflow YAML locally.
  • Ran bash -n on the embedded alert script.
  • Ran git diff --check for the changed workflow files.

actionlint is not installed in this workspace, so it was not run.

@ironloopai

ironloopai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: bbeef5b6b8e6b5d768cd0ec0bd3feb4c12ef034b
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-09T07:20:55.273Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-09T07:00:39.562Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 8efccf2. Previous verdict: Approved.
Recent activity
Time Reviewer State Detail
2026-07-09T06:53:28.137Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-09T06:53:28.140Z ironloop/common-reviewer (reviewer) Queued Added to the local review work handoff.
2026-07-09T06:53:29.145Z ironloop/common-reviewer (reviewer) Started Reviewer worker started attempt 1.
2026-07-09T06:53:31.786Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 482a547.
2026-07-09T06:58:20.508Z ironloop/common-reviewer (reviewer) Superseded Old-head reviewer is still running after newer head 8efccf2 replaced it. Codex is reviewing; process live; elapsed 4m 50s; timeout in 15m 10s; last heartbeat 2026-07-09T06:58:20.508Z. Codex emitted stderr output at 2026-07-09T06:58:06.864Z.
2026-07-09T06:58:26.028Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-09T06:58:26.028Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-09T07:00:39.562Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (8efccf2).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5863 July 9, 2026 06:43 Destroyed
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

An error occurred during the review process. Please try again later.

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added automatic Slack notifications for selected CI workflow results on push events to the main branch.
    • Alerts trigger on failure-like outcomes and include workflow name, conclusion, branch/commit reference, triggering actor, and a short list of failed jobs (or a fallback message).
  • Documentation

    • Documented the “Main branch alerting” setup, including which workflows are monitored and how to provide the Slack webhook destinations via configuration.

Walkthrough

Adds a main-ci-slack-alerts.yml watcher for selected main-branch CI runs, posts Slack alerts for failure-like conclusions using MAIN_CI_SLACK_WEBHOOK_URLS, and documents the watcher in .github/workflows/README.md.

Changes

Main CI Slack alerting

Layer / File(s) Summary
Workflow trigger and permissions
.github/workflows/main-ci-slack-alerts.yml
Adds the workflow_run trigger for named CI workflows on main and sets read-only actions/contents permissions.
Alert job gating and Slack notification script
.github/workflows/main-ci-slack-alerts.yml
Adds the alert job condition, passes run metadata into the step environment, queries failed jobs via gh api, builds the Slack payload with jq, requires MAIN_CI_SLACK_WEBHOOK_URLS, and posts to each comma-separated webhook with curl.
README documentation for alerting
.github/workflows/README.md
Adds the “Main branch alerting” section covering watched workflows, trigger conclusions, webhook configuration, and the registration requirement for new push-to-main workflows.

Estimated code review effort: 2 (Simple) | ~10 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions as GitHub Actions
  participant MainCIWatcher as main-ci-slack-alerts.yml
  participant GitHubAPI as GitHub API
  participant SlackWebhook as Slack webhook URL(s)

  GitHubActions->>MainCIWatcher: emits completed workflow_run for watched main-branch CI
  MainCIWatcher->>GitHubAPI: gh api jobs for the workflow run
  GitHubAPI-->>MainCIWatcher: job conclusions
  MainCIWatcher->>MainCIWatcher: build payload and validate MAIN_CI_SLACK_WEBHOOK_URLS
  MainCIWatcher->>SlackWebhook: POST alert payload to each webhook
  SlackWebhook-->>MainCIWatcher: delivery result
Loading
🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers summary and validation, but it omits many template sections like change type, linked issue, security impact, and rollback plan. Add the missing template sections, especially Change Type, Linked Issue, Security Impact, Rollback Plan, and the remaining required checklist fields.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and clearly matches the added CI Slack alert workflow.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 9, 2026
@think-in-universe think-in-universe changed the title [codex] Add main CI Slack alerts ci: add main CI Slack alerts Jul 9, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 d487a95fde45

Head: d487a95fde4567fa3c231094109b01b2a2440ba8
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

No concrete actionable issues found in the main CI Slack alert workflow or README update.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/failed/superseded state while reviewers run.

@think-in-universe
think-in-universe force-pushed the codex/main-ci-slack-alerts branch from d487a95 to 81be944 Compare July 9, 2026 06:50
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5863 July 9, 2026 06:50 Destroyed
@think-in-universe
think-in-universe marked this pull request as ready for review July 9, 2026 06:53
Copilot AI review requested due to automatic review settings July 9, 2026 06:53
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/main-ci-slack-alerts.yml:
- Around line 90-94: The webhook fan-out loop in the Slack alerts workflow stops
on the first failed `curl` because `set -euo pipefail` and `curl -f` make a
single 4xx/5xx abort the whole job. Update the loop that reads `webhook_file` so
each webhook send is isolated from failures and later URLs still run, and add a
bounded timeout to the `curl` call so an unresponsive endpoint cannot hang the
workflow. Keep the fix localized around the webhook posting logic and its
`posted` counter.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: e4651362-3e26-4161-8f3c-2ccb02469f7c

📥 Commits

Reviewing files that changed from the base of the PR and between 7b79f35 and 81be944.

📒 Files selected for processing (2)
  • .github/workflows/README.md
  • .github/workflows/main-ci-slack-alerts.yml

Comment thread .github/workflows/main-ci-slack-alerts.yml
@railway-app

railway-app Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5863 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 9, 2026 at 7:00 am

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 81be9440d0c0

Head: 81be9440d0c0ce8657b975c3401bf1b9795acd1e
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

No concrete actionable issues found in the main CI Slack alert workflow or the accompanying workflow README update.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/failed/superseded state while reviewers run.

@think-in-universe
think-in-universe force-pushed the codex/main-ci-slack-alerts branch from 81be944 to 8efccf2 Compare July 9, 2026 07:00
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5863 July 9, 2026 07:00 Destroyed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/main-ci-slack-alerts.yml:
- Line 87: The webhook URL handling in the CI Slack alerts workflow only removes
blank lines after splitting on commas, so entries with surrounding spaces are
still passed through untrimmed. Update the shell pipeline that writes to
webhook_file so each value from webhooks is whitespace-trimmed after the comma
split, ensuring names/URLs like "url1, url2" are normalized before later curl
usage.
- Around line 86-87: The temp file created for secret webhook URLs in the
workflow is not cleaned up after use. Update the shell block around webhook_file
creation and consumption to register a trap that removes the mktemp file when
the step exits, so the cleanup happens even on failure.
- Around line 89-99: The alert posting loop in the main CI Slack workflow should
fail the job when no webhook receives the message. Keep the per-webhook curl
handling in the posting block, but after the loop in the script section that
uses posted and webhook_file, add a check for posted being zero and exit
non-zero with a clear error so the workflow is red when every Slack delivery
fails.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6fcd952f-2e73-4e28-a0e0-569b231ad3d8

📥 Commits

Reviewing files that changed from the base of the PR and between 81be944 and 8efccf2.

📒 Files selected for processing (2)
  • .github/workflows/README.md
  • .github/workflows/main-ci-slack-alerts.yml

Comment thread .github/workflows/main-ci-slack-alerts.yml Outdated
Comment thread .github/workflows/main-ci-slack-alerts.yml Outdated
Comment thread .github/workflows/main-ci-slack-alerts.yml
Copilot AI review requested due to automatic review settings July 9, 2026 07:20
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5863 July 9, 2026 07:20 Destroyed
HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
ACTOR: ${{ github.event.workflow_run.actor.login }}
MAIN_CI_SLACK_WEBHOOK_URLS: ${{ secrets.MAIN_CI_SLACK_WEBHOOK_URLS }}

@think-in-universe think-in-universe Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAIN_CI_SLACK_WEBHOOK_URLS secret has been configured in the repo.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

@think-in-universe
think-in-universe added this pull request to the merge queue Jul 9, 2026
Merged via the queue into main with commit a0dafa8 Jul 9, 2026
43 checks passed
@think-in-universe
think-in-universe deleted the codex/main-ci-slack-alerts branch July 9, 2026 07:36

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5863 — bbeef5b6 Deployed Jul 9, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants