Skip to content

feat: implement issue #894 — [Fleet Monitor] petry-projects/.github — .github/workflows/ci.yml - #895

Merged
don-petry merged 4 commits into
mainfrom
dev-lead/issue-894-20260724-0907
Jul 24, 2026
Merged

don-petry merged 4 commits into
mainfrom
dev-lead/issue-894-20260724-0907

Conversation

@don-petry

@don-petry don-petry commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #894

Implemented by dev-lead agent. Please review.


CodeAnt-AI Description

Reduce flaky CI workflow failures when downloading Actionlint

What Changed

  • The CI workflow now retries the Actionlint download instead of failing immediately on temporary network or GitHub release errors
  • Added a test suite that checks the CI workflow keeps bounded retry settings on every curl download
  • Added workflow test automation so this protection runs when the CI workflow or its tests change

Impact

✅ Fewer flaky CI failures
✅ More reliable workflow linting
✅ Lower chance of false build failures during dependency downloads

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Bug Fixes
    • Improved reliability of CI workflow downloads by adding bounded retries and safer failure handling.
  • Tests
    • Added automated checks to verify that workflow downloads consistently use retry safeguards.
    • Added validation that the CI workflow is present and can be tested from any working directory.
  • Chores
    • Added an automated workflow for running CI-related tests on relevant changes.

@don-petry
don-petry requested a review from a team as a code owner July 24, 2026 09:15
@codeant-ai

codeant-ai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR efb39e5 Jul 24, 2026 · 09:15 09:18

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 47 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 040b7f56-7148-4dd6-bbf3-b700c133e552

📥 Commits

Reviewing files that changed from the base of the PR and between efb39e5 and 3486ab8.

📒 Files selected for processing (3)
  • .github/workflows/ci-tests.yml
  • .github/workflows/ci.yml
  • test/workflows/ci/install-resilience.bats
📝 Walkthrough

Walkthrough

The CI workflow now downloads actionlint with bounded curl retries. New Bats tests validate this behavior, and a GitHub Actions workflow runs those tests for relevant CI changes.

Changes

CI install resilience

Layer / File(s) Summary
Resilient download contract and regression test
.github/workflows/ci.yml, test/workflows/ci/helpers/setup.bash, test/workflows/ci/install-resilience.bats
The actionlint download adds bounded retry flags, and Bats scans workflow curl commands to enforce those options.
Automated workflow test execution
.github/workflows/ci-tests.yml
A new workflow runs the CI Bats tests on relevant pull requests and pushes to main, with restricted permissions and cancellable concurrency.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly points to issue #894 and the ci.yml workflow change, matching the main purpose of the PR.
Linked Issues check ✅ Passed The PR addresses #894 by hardening ci.yml downloads and adding regression tests for the workflow warning and failure risk.
Out of Scope Changes check ✅ Passed The added workflow and Bats tests are directly tied to validating and stabilizing .github/workflows/ci.yml.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-894-20260724-0907

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Jul 24, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #895
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-07-24T09:46:24Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-07-24T09:46:24Z

@don-petry
don-petry enabled auto-merge (squash) July 24, 2026 09:16
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Harden CI actionlint download with bounded curl retries + regression tests

🐞 Bug fix 🧪 Tests ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add bounded curl retries to actionlint download to reduce CI flakiness (issue #894).
• Introduce a bats test that enforces retry flags on every ci.yml curl download.
• Add a dedicated GitHub Actions workflow to run the bats suite on workflow changes.
Diagram

graph TD
  A["PR/Push event"] --> B["CI (ci.yml)"] --> C["Lint job"] --> D["Download actionlint (curl)"] --> E["GitHub Releases"]
  A --> F["CI workflow tests (ci-tests.yml)"] --> G["bats suite"] --> H["Parse ci.yml"] --> I["Assert curl retries"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Vendor actionlint binary (or cache artifact)
  • ➕ Eliminates network flakiness entirely for actionlint install
  • ➕ Reduces dependency on GitHub Releases availability
  • ➖ Adds binary/large artifacts to the repo or requires artifact management
  • ➖ More process/maintenance overhead when bumping versions and checksums
2. Install actionlint via package manager (apt/homebrew)
  • ➕ Avoids direct GitHub Releases download and redirect chain
  • ➕ Often benefits from OS mirror resiliency
  • ➖ Version may not be pinned/reproducible across runner images
  • ➖ May not match desired version/checksum verification model
3. Use gh release download instead of curl
  • ➕ Potentially better handling of GitHub auth/redirects and retries
  • ➕ More consistent download UX across workflows already using gh
  • ➖ Introduces dependency on GitHub CLI presence/configuration in the job
  • ➖ Still network-dependent; needs explicit resiliency settings/guard tests

Recommendation: The chosen approach (bounded curl retries + a bats regression guard) is the best tradeoff: it keeps the existing pinned version + checksum model, directly targets the observed failure mode, and adds an automated policy test so the reliability fix cannot be accidentally removed. Vendoring or switching install mechanisms could further reduce network risk but increases maintenance and/or reduces reproducibility.

Files changed (4) +112 / -1

Bug fix (1) +6 / -1
ci.ymlAdd bounded curl retries to actionlint download in Lint job +6/-1

Add bounded curl retries to actionlint download in Lint job

• Replaces the bare actionlint tarball download with a curl invocation that fails on errors and retries transient failures with a bounded budget. This addresses intermittent CI failures caused by GitHub Releases/redirect flakiness (issue #894).

.github/workflows/ci.yml

Tests (3) +106 / -0
ci-tests.ymlAdd workflow to run bats tests for ci.yml resilience rules +44/-0

Add workflow to run bats tests for ci.yml resilience rules

• Introduces a dedicated GitHub Actions workflow that runs on changes to ci.yml and related test files. Installs bats and executes the test suite under test/workflows/ci/ to enforce workflow invariants.

.github/workflows/ci-tests.yml

setup.bashAdd shared bats setup for locating repo root and ci.yml +10/-0

Add shared bats setup for locating repo root and ci.yml

• Adds a small helper that exports the repository root and the path to the ci.yml workflow for use by bats tests. Enables tests to run reliably regardless of invocation directory.

test/workflows/ci/helpers/setup.bash

install-resilience.batsAdd bats regression test enforcing curl retry flags in ci.yml +52/-0

Add bats regression test enforcing curl retry flags in ci.yml

• Adds a bats suite that parses ci.yml (including backslash-continued lines) to find curl invocations and assert required retry flags are present. Ensures future edits cannot reintroduce non-resilient downloads.

test/workflows/ci/install-resilience.bats

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new Bats test suite (install-resilience.bats and its setup helper) to ensure that all curl commands in the CI workflow (ci.yml) use robust retry flags (--retry, --retry-connrefused, and --retry-all-errors) to prevent flaky CI runs. The review feedback highlights two key improvement opportunities in the test logic: first, refining the curl command detection to exclude YAML metadata fields (like name or uses containing the word 'curl') to prevent false positives, and second, using a regular expression to match the --retry flag more robustly (e.g., supporting --retry=5 instead of just space-separated arguments).

Comment thread test/workflows/ci/install-resilience.bats Outdated
Comment thread test/workflows/ci/install-resilience.bats Outdated
@don-petry
don-petry disabled auto-merge July 24, 2026 09:17
@qodo-code-review

qodo-code-review Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 87 rules

Grey Divider


Remediation recommended

1. Missing apt install retries ✓ Resolved 🐞 Bug ☼ Reliability
Description
The new CI Workflow Tests job installs bats with a single apt-get update/apt-get install
attempt, so transient apt mirror/CDN/network issues can fail the job and undermine the reliability
this PR is trying to improve. This is avoidable by using a bounded retry+backoff loop (as already
done in other workflow tests).
Code

.github/workflows/ci-tests.yml[R37-42]

+      - name: Install bats
+        run: |
+          set -euo pipefail
+          sudo apt-get update -qq
+          sudo apt-get install -y --no-install-recommends bats
+
Relevance

⭐⭐⭐ High

Repo recently accepted bounded apt retry/backoff for workflow tests to reduce CI flakiness (same
failure mode).

PR-#890

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The new workflow performs a single-shot apt install (no retries), while an existing workflow test
job in the repo already uses a bounded retry+backoff pattern explicitly to avoid transient apt
failures skewing CI reliability metrics.

.github/workflows/ci-tests.yml[37-44]
.github/workflows/standards-deploy-tests.yml[66-89]
PR-#890

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`.github/workflows/ci-tests.yml` installs bats via a single `apt-get update` + `apt-get install` attempt. On GitHub-hosted runners, apt can fail transiently (mirror/CDN 5xx, DNS hiccups), which makes this new workflow flaky and can block PRs.

### Issue Context
The repo already contains an example of a bounded retry+backoff apt install loop (including improved logging on the final attempt) in another workflow test job. Reuse that pattern here to keep CI deterministic.

### Fix Focus Areas
- .github/workflows/ci-tests.yml[37-42]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread .github/workflows/ci-tests.yml
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) July 24, 2026 09:18
Comment thread .github/workflows/ci.yml Fixed
@don-petry
don-petry disabled auto-merge July 24, 2026 09:20

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci-tests.yml:
- Around line 34-35: Add the checkout action input persist-credentials: false
beneath the existing actions/checkout configuration in the workflow, preserving
the current repository checkout behavior while disabling GitHub credential
persistence.

In @.github/workflows/ci.yml:
- Around line 62-64: Add explicit curl timeout options to the actionlint archive
download command, including connection and overall/retry duration limits
compatible with the 63-second p95 target. Preserve the existing retry behavior
and download URL while ensuring stalled transfers cannot hold the workflow
indefinitely.
- Around line 62-64: Update the actionlint download command to restrict both
protocols and redirects to HTTPS by adding curl’s --proto '=https' and
--proto-redir '=https' options alongside the existing retry flags. Preserve the
current URL, output path, and download behavior.

In `@test/workflows/ci/install-resilience.bats`:
- Around line 44-50: Update the retry-option assertion in the curl command loop
to extract the numeric value following --retry and validate that it is a
positive budget, preferably within 1..3, rather than only checking the option’s
presence. Keep the existing --retry-connrefused and --retry-all-errors
assertions unchanged.
- Around line 29-32: Update the continuation check in the line-processing loop
to match exactly one trailing backslash, using the appropriate unescaped
backslash glob pattern instead of the current two-character quoted pattern.
Preserve the existing removal of the continuation marker and command-joining
behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b0f305f0-78b7-40f4-9ddd-d16e6c56dd25

📥 Commits

Reviewing files that changed from the base of the PR and between 097c01e and efb39e5.

📒 Files selected for processing (4)
  • .github/workflows/ci-tests.yml
  • .github/workflows/ci.yml
  • test/workflows/ci/helpers/setup.bash
  • test/workflows/ci/install-resilience.bats

Comment thread .github/workflows/ci-tests.yml
Comment thread .github/workflows/ci.yml Outdated
Comment thread test/workflows/ci/install-resilience.bats
Comment thread test/workflows/ci/install-resilience.bats
Comment thread test/workflows/ci/install-resilience.bats Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 24, 2026
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (applied)

Changes committed and pushed.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 24, 2026
@don-petry
don-petry disabled auto-merge July 24, 2026 09:25
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge July 24, 2026 09:28
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) July 24, 2026 09:34

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: 3486ab83284bc92be76487432d5f6e6983681f45
Review mode: triage-approved (single reviewer)

Summary

Hardens the flaky actionlint download in ci.yml (issue #894, 14.3% failure rate) with bounded curl retries (--retry 3, --retry-connrefused, --retry-all-errors) plus HTTPS-only protocol enforcement, while preserving the existing pinned version + SHA-256 checksum verification. Adds a bats regression suite that asserts every curl download in ci.yml carries bounded retries, and a path-filtered ci-tests.yml workflow to run it.

Linked issue analysis

Closes #894 ([Fleet Monitor] ci.yml WARNING — 14.3% failure rate). The root cause (bare curl aborting on transient GitHub Releases errors) is directly fixed with a finite retry budget, and the regression test prevents silent reintroduction. Substantively addressed.

Findings

  • ci.yml: retry flags are bounded (fails fast if the mirror is truly down); checksum verification unchanged, so integrity guarantees are preserved. No security regression.
  • ci-tests.yml: least-privilege permissions (top-level {}, job-level contents: read), persist-credentials: false, 10-minute timeout, concurrency cancellation. actions/checkout pin 9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 verified via the GitHub API as the v7.0.0 tag commit.
  • install-resilience.bats: continuation-line joining correctly treats multi-line curl commands as single invocations; asserts a finite retry budget and transient-error coverage.
  • Secret scan: run_secret_scanning MCP tool not available in this session; gitleaks CI check passed and no secrets appear in the diff.
  • Prior CodeRabbit CHANGES_REQUESTED was resolved (dismissed, later approved); no unresolved review threads remain.

CI status

All checks green at 3486ab8: Lint, bats (x2), ShellCheck, CodeQL, Analyze (actions), Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud, npm audit, CodeRabbit, Graphite AI Reviews. Two CANCELLED dev-lead relay entries are superseded duplicates of successful runs.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry merged commit b58e090 into main Jul 24, 2026
26 of 28 checks passed
@don-petry
don-petry deleted the dev-lead/issue-894-20260724-0907 branch July 24, 2026 09:37

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: 3486ab83284bc92be76487432d5f6e6983681f45
Review mode: triage-approved (single reviewer)

Summary

Adds bounded curl retries to the actionlint download in ci.yml (fixing the ~14% flaky failure rate from issue #894), plus a bats regression suite and a ci-tests.yml workflow to run it. The change improves security posture (--proto '=https' enforcement added; sha256 checksum verification retained) and the triage low-risk assessment is confirmed correct.

Linked issue analysis

Issue #894 (Fleet Monitor: ci.yml 14.3% failure rate, WARNING) is substantively addressed: the bare curl download that aborted on transient GitHub Releases errors now has --retry 3 with bounded timeouts, --retry-connrefused, and --retry-all-errors. A regression test asserts every curl in ci.yml keeps bounded retries, preventing silent reintroduction.

Findings

  • No blocking findings.
  • Security checks pass: actions/checkout pin 9c091bb2… verified via GitHub API as the genuine v7.0.0 tag commit; ci-tests.yml uses top-level permissions: {}, job-scoped contents: read, persist-credentials: false, timeout, and concurrency cancellation.
  • The ci.yml curl hardening adds --proto '=https' --proto-redir '=https' and keeps sha256 verification, so --retry-all-errors cannot smuggle a corrupted artifact past the checksum.
  • Test quality: the bats parser joins backslash-continued lines and the --retry[[:space:]=][1-9] assertion correctly rejects --retry 0 and does not false-match --retry-connrefused.
  • All 9 review threads (gemini, qodo, GHAS/Sonar, CodeRabbit, Graphite) are resolved; CodeRabbit's earlier changes-requested was dismissed and superseded by its approval. Review decision is APPROVED (coderabbitai + donpetry-bot). don-petry review entries are dev-lead automation status posts with no open questions.
  • MCP secret scanning tool not available in this run; noted per protocol — gitleaks CI check passed and the diff contains no credential material.

CI status

All substantive checks green: Lint, bats (×2), Analyze (actions)/CodeQL, ShellCheck, Secret scan (gitleaks), Agent Security Scan, npm audit, SonarCloud, agent-shield, CodeRabbit, Graphite. Skipped audits (pip/cargo/govulncheck/pnpm) are ecosystem-detection skips. Two CANCELLED dev-lead dispatch/ci-relay entries are superseded agent-orchestration runs with later SUCCESS duplicates of the same checks — not build failures.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Fleet Monitor] petry-projects/.github — .github/workflows/ci.yml

3 participants