#12 CI on GitHub Actions: lint and the full suite against the broker's Redis (7.0.15) - #13
Merged
Merged
Conversation
…s:7.2 .github/workflows/ci.yml, modelled on Watcher's: - wheelhouse keyless via WIF (vars.GCP_WIF_PROVIDER, the read-only co-pypi-reader SA), synced before any project-aware uv command; - lint: ruff check, ruff format --check, uv lock --locked; - test: the whole suite, integration included, against a redis:7.2 service container (the broker's version; co-processor's scratch server is 7.0.15); - checkout with submodules (tests/test_skills.py walks skills-vendor/); - job-scoped id-token; superseded PR runs cancelled, main runs never. tests/test_ci.py pins those choices; PyYAML joins the dev group for it (uv.lock adds pyyaml 6.0.3 only). Closes #12 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CI's first authenticated run failed at the sync: `uv run --no-project`
still reads [tool.uv] find-links, and a fresh checkout has no ./.wheelhouse
yet ("Failed to read --find-links directory"). The documented bootstrap in
AGENTS.md had the same bug for any fresh clone; it worked here only because
the directory already existed. Watcher avoids it with a tracked
.wheelhouse/.gitkeep, which would break this repo's worktree recipe (it
symlinks .wheelhouse), so the sync runs with --no-config instead.
Guard: every documented `uv run ... sync_wheelhouse.py` (AGENTS.md, docs/,
the script's own usage) and both CI steps carry --no-config.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The broker runs Redis 7.0.15 (broker deploy/redis-acl.conf). 7.2 came from
its notes on a future upgrade, misread as the current version. On 7.2,
redis-py sends CLIENT SETINFO on connect, and broker#75's grant has no
+client|setinfo: the broker cannot hold it before 7.2 ("Unknown command ... in
ACL" takes every user down), and lists granting it as a required step of
that upgrade. So the 7.2 container failed our ACL-LOG-empty capture on a
denial the real broker never produces. The live ensure-group at 22:09Z left
no such entry either, for the same reason.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… 20's Run 36962791709 warned both were being forced onto Node 24. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… it reads the script's docstring The docstring splits the command across a continuation, so no physical line held both 'uv run' and 'sync_wheelhouse.py' and the guard never saw it. It now also asserts the docstring was scanned, and reads docs/ recursively. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A new test holds SKILLS.md's selection lists, its count and its 'Not linked' line to the actual links. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A run takes ~2 minutes; the integration suite blocks on Redis reads, so a hang would otherwise bill six hours. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t depends on The org variable shared with this repo and co-pypi-reader's workloadIdentityUser binding were CI's two first failures; neither was recorded in the repo. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nfig Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
.github/workflows/ci.yml, modelled on Watcher's. Closes #12.vars.GCP_WIF_PROVIDER→ the read-onlyco-pypi-readerSA), synced before any project-awareuvcommand.ruff check,ruff format --check,uv lock --locked.redis:7.0.15service container, the broker's exact version (brokerdeploy/redis-acl.conf) and the same asco-processor's scratch server.tests/test_skills.pywalksskills-vendor/. The id-token permission is job-scoped.tests/test_ci.pypins these choices. PyYAML joins the dev group;uv.lockgainspyyaml6.0.3 only.Locally: 225 passed. CI: 221 passed, 4 skipped (the live-Tailscale checks), ruff clean,
uv lock --lockedclean.Getting to green:
GCP_WIF_PROVIDERwas shared with this repo.co-pypi-readergained aroles/iam.workloadIdentityUserbinding forCannObserv/processor; the provider's condition already admitted it.--no-config(6af4d79).--no-projectalone still read[tool.uv] find-linkson a fresh checkout, and the same bug was in AGENTS.md's bootstrap.redis:7.2, misread from the broker's notes on a future upgrade. On 7.2, redis-py'sCLIENT SETINFOis an ACL denial the broker cannot grant before upgrading (4e4bb38).🤖 Generated with Claude Code