Skip to content

#12 CI on GitHub Actions: lint and the full suite against the broker's Redis (7.0.15) - #13

Merged
gregoryfoster merged 9 commits into
mainfrom
12-ci
Oct 2, 2026
Merged

gregoryfoster merged 9 commits into
mainfrom
12-ci

Conversation

@gregoryfoster

@gregoryfoster gregoryfoster commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Adds .github/workflows/ci.yml, modelled on Watcher's. Closes #12.

  • Wheelhouse: keyless via WIF (vars.GCP_WIF_PROVIDER → the read-only co-pypi-reader SA), synced before any project-aware uv command.
  • lint: ruff check, ruff format --check, uv lock --locked.
  • test: the whole suite, integration included, against a redis:7.0.15 service container, the broker's exact version (broker deploy/redis-acl.conf) and the same as co-processor's scratch server.
  • Checkout with submodules, because tests/test_skills.py walks skills-vendor/. The id-token permission is job-scoped.
  • tests/test_ci.py pins these choices. PyYAML joins the dev group; uv.lock gains pyyaml 6.0.3 only.

Locally: 225 passed. CI: 221 passed, 4 skipped (the live-Tailscale checks), ruff clean, uv lock --locked clean.

Getting to green:

  • The org variable GCP_WIF_PROVIDER was shared with this repo.
  • co-pypi-reader gained a roles/iam.workloadIdentityUser binding for CannObserv/processor; the provider's condition already admitted it.
  • The wheelhouse sync now runs with --no-config (6af4d79). --no-project alone still read [tool.uv] find-links on a fresh checkout, and the same bug was in AGENTS.md's bootstrap.
  • An early version pinned redis:7.2, misread from the broker's notes on a future upgrade. On 7.2, redis-py's CLIENT SETINFO is an ACL denial the broker cannot grant before upgrading (4e4bb38).

🤖 Generated with Claude Code

@gregoryfoster gregoryfoster changed the title #12 CI on GitHub Actions: lint and the full suite against redis:7.2 #12 CI on GitHub Actions: lint and the full suite against the broker's Redis (7.0.15) Oct 2, 2026
gregoryfoster and others added 9 commits October 2, 2026 17:44
…s:7.2

.github/workflows/ci.yml, modelled on Watcher's:
- wheelhouse keyless via WIF (vars.GCP_WIF_PROVIDER, the read-only
  co-pypi-reader SA), synced before any project-aware uv command;
- lint: ruff check, ruff format --check, uv lock --locked;
- test: the whole suite, integration included, against a redis:7.2 service
  container (the broker's version; co-processor's scratch server is 7.0.15);
- checkout with submodules (tests/test_skills.py walks skills-vendor/);
- job-scoped id-token; superseded PR runs cancelled, main runs never.

tests/test_ci.py pins those choices; PyYAML joins the dev group for it
(uv.lock adds pyyaml 6.0.3 only).

Closes #12

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CI's first authenticated run failed at the sync: `uv run --no-project`
still reads [tool.uv] find-links, and a fresh checkout has no ./.wheelhouse
yet ("Failed to read --find-links directory"). The documented bootstrap in
AGENTS.md had the same bug for any fresh clone; it worked here only because
the directory already existed. Watcher avoids it with a tracked
.wheelhouse/.gitkeep, which would break this repo's worktree recipe (it
symlinks .wheelhouse), so the sync runs with --no-config instead.

Guard: every documented `uv run ... sync_wheelhouse.py` (AGENTS.md, docs/,
the script's own usage) and both CI steps carry --no-config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The broker runs Redis 7.0.15 (broker deploy/redis-acl.conf). 7.2 came from
its notes on a future upgrade, misread as the current version. On 7.2,
redis-py sends CLIENT SETINFO on connect, and broker#75's grant has no
+client|setinfo: the broker cannot hold it before 7.2 ("Unknown command ... in
ACL" takes every user down), and lists granting it as a required step of
that upgrade. So the 7.2 container failed our ACL-LOG-empty capture on a
denial the real broker never produces. The live ensure-group at 22:09Z left
no such entry either, for the same reason.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… 20's

Run 36962791709 warned both were being forced onto Node 24.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… it reads the script's docstring

The docstring splits the command across a continuation, so no physical line held
both 'uv run' and 'sync_wheelhouse.py' and the guard never saw it. It now also
asserts the docstring was scanned, and reads docs/ recursively.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A new test holds SKILLS.md's selection lists, its count and its 'Not linked'
line to the actual links.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A run takes ~2 minutes; the integration suite blocks on Redis reads, so a hang
would otherwise bill six hours.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t depends on

The org variable shared with this repo and co-pypi-reader's
workloadIdentityUser binding were CI's two first failures; neither was
recorded in the repo.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nfig

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gregoryfoster
gregoryfoster merged commit 60aedc8 into main Oct 2, 2026
2 checks passed
@gregoryfoster
gregoryfoster deleted the 12-ci branch October 2, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: lint and the full test suite on GitHub Actions (WIF wheelhouse, the broker's Redis)

1 participant