Skip to content

Alert live-canary Slack channel on merge queue failures - #7007

Merged
serrrfirat merged 1 commit into
mainfrom
codex/merge-queue-slack-alerts
Aug 2, 2026
Merged

serrrfirat merged 1 commit into
mainfrom
codex/merge-queue-slack-alerts

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • watch failed merge_group workflow runs in the existing external CI alert workflow
  • post merge-queue failures to the live-canary Slack channel with the queued PR, failed jobs and steps, and available check annotations
  • add a workflow contract test and document the merge-queue alerting path

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

None.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo build
  • Relevant tests pass: bash scripts/ci/test-main-ci-slack-alerts.sh
  • cargo test --features integration if database-backed or integration behavior changed
  • Manual testing: parsed both changed workflow YAML files and replayed the notifier against failed merge-queue run 30644625064 with Slack delivery mocked
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Test Strategy

User behavior:

A failed merge-queue workflow posts an alarm to the existing live-canary Slack channel. The alarm identifies the queued PR and reports failed jobs/steps plus check annotations when GitHub publishes them.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: scripts/ci/test-main-ci-slack-alerts.sh locks the queue branch filter, event gate, least-privilege permissions, live-canary webhook routing, PR lookup, failure detail fields, and its own Code Style execution path.
  • Reborn integration: Not applicable: no Reborn runtime behavior changes.
  • Recorded fixture: Not applicable: no model/provider behavior changes.
  • Browser E2E: Not applicable: no browser or frontend behavior changes.
  • Backend or runtime: Not applicable: no backend/runtime code changes.
  • Live canary: Not applicable: this reuses the live-canary Slack destination but does not change or execute a canary lane.

What the tests prove:

The alert workflow observes merge_group runs, resolves the PR from the repository's queue ref, routes queue failures through SLACK_WEBHOOK_URL, includes structured failure metadata, and remains covered whenever the workflow changes.

Commands run:

  • bash scripts/ci/test-main-ci-slack-alerts.sh
  • bash -n scripts/ci/test-main-ci-slack-alerts.sh
  • Ruby YAML parse for .github/workflows/main-ci-slack-alerts.yml and .github/workflows/code_style.yml
  • git diff origin/main...HEAD --check
  • notifier replay against run 30644625064 with curl mocked; no Slack message sent

Security Impact

The alert job gains checks: read and pull-requests: read so it can fetch failure annotations and PR metadata. It continues to use repository-scoped GITHUB_TOKEN access and the existing SLACK_WEBHOOK_URL secret. PR titles, job names, and annotation text are Slack-escaped and bounded before posting; arbitrary workflow logs are not forwarded.

Reborn Trust-Boundary Checklist

N/A: this changes GitHub Actions alerting only and does not modify Reborn runtime, policy, evidence, persistence, or trust-bearing types.

Database Impact

None.

Blast Radius

Limited to the external CI Slack alert workflow and the Code Style self-test list. A notifier regression could omit or duplicate an alert, but cannot affect the required workflow run that it observes.

Rollback Plan

Revert this commit to restore push-only main CI alerts. The existing live-canary and nightly Slack reporting paths remain independent.

Review Follow-Through

Please verify that routing merge-queue failures to the shared live-canary channel matches the desired notification volume. The PR is draft pending normal CI and review.


Review track: C (CI)

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@railway-app

railway-app Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-7007 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Aug 1, 2026 at 9:16 am

@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6b544da5-9846-4851-8f76-9aed54562a4e

📥 Commits

Reviewing files that changed from the base of the PR and between a50ad06 and e9ee94e.

📒 Files selected for processing (4)
  • .github/workflows/README.md
  • .github/workflows/code_style.yml
  • .github/workflows/main-ci-slack-alerts.yml
  • scripts/ci/test-main-ci-slack-alerts.sh

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added Slack notifications for merge-queue workflow failures alongside main-branch failures.
    • Alerts now include failed job steps, failure annotations, and relevant pull-request details.
    • Notifications use event-specific webhook configurations and clearly identify the triggering workflow event.
  • Documentation

    • Updated alerting documentation to describe main-branch and merge-queue notifications.
  • Tests

    • Added automated checks to verify workflow triggers, permissions, webhook settings, and failure-reporting behavior.

Walkthrough

The CI Slack alert workflow now handles push and merge_group events. It reports failed jobs, steps, annotations, and merge-queue pull-request details. Separate webhook secrets support main-branch and merge-queue alerts. A Bash contract test validates the workflow configuration.

Changes

CI alerting

Layer / File(s) Summary
Workflow events and permissions
.github/workflows/main-ci-slack-alerts.yml
The workflow monitors main-branch pushes and merge-queue runs. It adds checks and pull-requests read permissions.
Event-specific failure reporting
.github/workflows/main-ci-slack-alerts.yml
The alert script collects failed jobs, steps, annotations, and merge-queue pull-request details. It formats Slack payloads and selects the event-specific webhook.
Alerting documentation and contract validation
.github/workflows/README.md, .github/workflows/code_style.yml, scripts/ci/test-main-ci-slack-alerts.sh
The README documents the expanded alerts. Static checks detect workflow changes and run the workflow contract test.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant GitHubAPI
  participant SlackWebhook
  GitHubActions->>GitHubAPI: Retrieve failed jobs and annotations
  GitHubAPI-->>GitHubActions: Return CI and merge-queue details
  GitHubActions->>SlackWebhook: Send event-specific failure alert
Loading

Possibly related PRs

Suggested reviewers: think-in-universe

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes merge-queue Slack failure alerting, although it does not use the preferred Conventional Commits format.
Description check ✅ Passed The description covers the required sections, change scope, validation, security impact, blast radius, rollback, and review follow-through.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7007 August 1, 2026 09:15 Destroyed
@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Aug 1, 2026
@ironloopai

ironloopai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #7007

🟢 Completed · Review submitted

Submitted review →

Reviewed the complete trusted base-to-head comparison. The merge-queue alert routing, permissions, payload construction, Slack escaping and bounds, existing main-branch behavior, documentation, and Code Style integration are coherent. No concrete actionable defects were found.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 43s

Run details
  • Repository: nearai/ironclaw
  • Base: main at a50ad06
  • Head: codex/merge-queue-slack-alerts at e9ee94e
  • Created: Aug 1, 2026, 9:20 AM UTC
  • Updated: Aug 1, 2026, 9:22 AM UTC
  • Run: 08108289-8cfa-43ff-aae0-5f1a360dae99
  • Latest attempt: 1 · Completed · becbe31f-ec3e-4908-996f-4ca3947a8e9e

@serrrfirat
serrrfirat marked this pull request as ready for review August 1, 2026 09:21
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #7007

✅ No actionable findings

Reviewed the complete trusted base-to-head comparison. The merge-queue alert routing, permissions, payload construction, Slack escaping and bounds, existing main-branch behavior, documentation, and Code Style integration are coherent. No concrete actionable defects were found.

Validation and technical details
  • Inspected all four changed files and surrounding workflow code across refs/ironloop/base..refs/ironloop/head.
  • Ran bash scripts/ci/test-main-ci-slack-alerts.sh successfully.
  • Ran bash -n scripts/ci/test-main-ci-slack-alerts.sh successfully.
  • Ran git diff --check refs/ironloop/base..refs/ironloop/head successfully.
  • Verified the workflow retains event/conclusion gating, separates main and merge-queue webhook destinations, grants read-only permissions, escapes and bounds externally sourced Slack content, and handles API/webhook failures.
  • Base: main
  • Head: codex/merge-queue-slack-alerts at e9ee94e
  • Run: 08108289-8cfa-43ff-aae0-5f1a360dae99

@ironloopai

ironloopai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #7007

🟢 Completed · Review submitted

1 actionable findings →

The workflow implementation is plausibly correct and preserves least-privilege permissions, event gating, Slack escaping, and webhook separation. However, the newly added automated test does not exercise the notifier’s behavior, leaving this substantial CI side effect effectively untested.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 40s

Run details
  • Repository: nearai/ironclaw
  • Base: main at a50ad06
  • Head: codex/merge-queue-slack-alerts at e9ee94e
  • Created: Aug 1, 2026, 9:26 AM UTC
  • Updated: Aug 1, 2026, 9:28 AM UTC
  • Run: e5849c80-99e1-441e-a4a9-c6e87ee8d91b
  • Latest attempt: 1 · Completed · 5529128b-212e-45ab-a615-32b4405652d0

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #7007

⚠️ 1 finding · 1 blocking

The workflow implementation is plausibly correct and preserves least-privilege permissions, event gating, Slack escaping, and webhook separation. However, the newly added automated test does not exercise the notifier’s behavior, leaving this substantial CI side effect effectively untested.

Findings

  1. 🟠 Medium · Notifier behavior is not covered by the contract test — scripts/ci/test-main-ci-slack-alerts.sh:16-24
    Details are attached to the relevant diff.
Validation and technical details
  • Inspected the complete trusted comparison refs/ironloop/base (a50ad06) through refs/ironloop/head (e9ee94e), covering all four changed files.
  • git diff --check refs/ironloop/base refs/ironloop/head passed.
  • bash scripts/ci/test-main-ci-slack-alerts.sh passed.
  • bash -n scripts/ci/test-main-ci-slack-alerts.sh passed.
  • Reviewed the full embedded notifier command and surrounding workflow permissions, triggers, event filtering, GitHub API pagination, Slack escaping and truncation, webhook selection, and error handling.
  • YAML parsing could not be independently rerun because neither Ruby nor Python's PyYAML module is installed in the checkout environment.
  • Base: main
  • Head: codex/merge-queue-slack-alerts at e9ee94e
  • Run: e5849c80-99e1-441e-a4a9-c6e87ee8d91b

Comment on lines +16 to +24
assert_contains "- gh-readonly-queue/main/**"
assert_contains "contains(fromJSON('[\"push\",\"merge_group\"]'), github.event.workflow_run.event)"
assert_contains "checks: read"
assert_contains "pull-requests: read"
assert_contains 'LIVE_CANARY_SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}'
assert_contains 'if [[ "$HEAD_BRANCH" =~ ^gh-readonly-queue/main/pr-([0-9]+)- ]]; then'
assert_contains '"repos/${GITHUB_REPOSITORY}/pulls/${pr_number}"'
assert_contains '*Failed jobs / steps:*'
assert_contains '*Failure annotations (when available):*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Medium · Notifier behavior is not covered by the contract test

The test only searches the workflow text for several independent substrings. It never executes the embedded shell with mocked gh and curl, nor asserts the generated payload or selected webhook. Consequently, regressions such as reversing the push/merge-queue webhook routing, breaking the PR-ref parser, producing invalid Slack JSON, or introducing a shell runtime error can all pass while these strings remain somewhere in the file. Extract the notifier into a testable script or build a harness that runs the workflow command with representative push and merge-group fixtures and verifies API calls, payload escaping/bounds, routing, and failure behavior.

@serrrfirat
serrrfirat added this pull request to the merge queue Aug 2, 2026
Merged via the queue into main with commit cca2fc4 Aug 2, 2026
41 checks passed
@serrrfirat
serrrfirat deleted the codex/merge-queue-slack-alerts branch August 2, 2026 19:50
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-7007 — e9ee94e0 Deployed Aug 1, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants