Skip to content

Adopt central agentic validation and shared policies - #35

Merged
DevOpsDerek merged 3 commits into
mainfrom
devopsderek-adopt-centralized-workflows-agentic-devo
Oct 4, 2026
Merged

DevOpsDerek merged 3 commits into
mainfrom
devopsderek-adopt-centralized-workflows-agentic-devo

Conversation

@DevOpsDerek

@DevOpsDerek DevOpsDerek commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adopt central validation and shared agentic policies for #34. Keep this PR draft for human review; no merge, deployment, promotion, infrastructure apply, publishing, issue assignment or project-status changes.

All five central references pin dac4b81c298cb3ea6821ea312efa5375f42d5ccb, merged through DevOpsDerek/workflows#2 and verified green on central main.

Exact changes and fit

  • .github/workflows/ci.yml: central .github/actions/validate-agentic-workflows in existing meta-lint, gh-aw-version: v0.89.21, workflows-directory: .github/workflows, contents:read. Preserve existing checks/names/triggers/permissions/artifacts. Exclude generated import cache from Markdown lint. Additional drift check covers .github/aw/actions-lock.json.
  • .github/workflows/{issue-triage,doc-updater,ci-doctor,test-improver}.md and matching .lock.yml: immutable inline central imports of issue-triage/documentation-upkeep/ci-failure-diagnosis/test-quality; retain local triggers/context/scoped output constraints. Shared instructions remain central, not local copies.
  • CI Doctor has executable failure-only activation and proper workflow-run ID; compiled pre_activation/activation guards retain repository/fork protection. Test Improver has a single-line executable validation command.
  • .github/aw/actions-lock.json, .gitattributes: compiler-generated v0.77.5 → v0.89.21 refresh. No handwritten locks.
  • .gitignore: ignore remote-import compilation cache.
  • README.md: exact revision, safety/behavior changes, fit/no-fit and regeneration/drift guidance.
  • src/Api/Api.csproj: separate security prerequisite commit 3b54844, identical one-line explicit Microsoft.OpenApi 2.7.5 reference proposed by open dependency Bump Microsoft.OpenApi from 2.0.0 to 2.7.5 #13. Resolves pre-existing NU1903 restore failures without major-version migration, application changes, warning/audit suppression or relaxed gates. Leave Bump Microsoft.OpenApi from 2.0.0 to 2.7.5 #13 for human deduplication/sequencing; it was not merged or closed.

The catalog checked-script helper is deliberately not used: it cannot replace solution format/build/test/coverage/artifact or Terraform/security gates. Existing .NET quality and 60% coverage gate, artifacts, Terraform/TFLint, Trivy SARIF/hard gate, CodeQL and CD remain intact. cd.yml, deploy.yml, codeql.yml, application source/tests and infrastructure are unchanged apart from the explicit dependency override above.

Safety and deliberate behavior changes

Triage proposes label/type in one triggering comment rather than mutating them. Doc/test agents produce at most one draft PR, no issue fallback, with allowlists: README/docs/copilot instructions/AGENTS Markdown and tests/** respectively. CI doctor permits one diagnostic issue/one comment, no invented labels. Compiled manifests/handler configs—not just source or compile success—were asserted: exact intended tools, max1, draft=true, fallback_as_issue=false, exact file allowlists, disabled reporting issue fallbacks, global permissions:{} and read-only agent jobs. Write output jobs stay isolated.

OIDC/environment state/sequential promotion/reviewer requirements remain unchanged. Live environments API returned no configured environments, so protection is documented prerequisite, not a claim of verified live setup. No cloud operations occurred.

Validation — current head 3b54844979a5b108eff5fd75e79709501d2116a8

All hosted checks green:

Check Result
Build, format & test (.NET) SUCCESS, coverage gate and artifacts retained
Terraform lint & validate SUCCESS
Trivy IaC & filesystem scan SUCCESS, SARIF/hard gate retained
Lint workflows & docs SUCCESS, central validator AND action-pin drift check
Analyze (csharp) / CodeQL SUCCESS
Automatic dependency submission SUCCESS

CI run, CodeQL run, dependency submission.

Local:

  • .NET restore, format verification, Release build: pass, zero warnings/errors.
  • Tests: 8 passed, 92.8% line coverage, >=60% enforced; no bypass.
  • gh-aw compile --validate --actionlint --no-check-update: four workflows, zero warnings/errors; repeated/post-commit compile has no workflow-lock or action-pin drift.
  • Exact generated output-policy/permission assertions pass; review fixes leave safe-output handler config unchanged.
  • Exact caller drift script fixture: clean accepted, unstaged/staged/untracked action-pin changes rejected.
  • Hand-authored actionlint, Markdown lint, Terraform 1.15.6 recursive fmt/backend-disabled init/validate/TFLint, git diff --check pass.

The previous Microsoft.OpenApi 2.0.0 NU1903 blocker is resolved by the minimal prerequisite. No remaining failing CI checks; retain draft until human review/acceptance.

Preserve existing CI and OIDC deployment gates; compile shared instructions into bounded local gh-aw callers for human review.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 4, 2026 18:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Three moderate findings remain unresolved, along with two documentation nits.

Review effort: Lite
Findings: None

What changed in this PR

Adopts centralized, SHA-pinned gh-aw policies and validation while preserving repository-specific CI/CD safety controls.

Changes:

  • Adds shared agentic workflow imports and regenerated locks.
  • Adds centralized validation to CI.
  • Documents adoption, regeneration, and behavior changes.
File Summary
README.md Documents centralized automation; update setup guidance and Markdown-lint scope wording.
.gitignore Ignores the gh-aw import cache.
.github/​workflows/​test-improver.md Adds shared test-quality policy; fix the split validation command.
.github/​workflows/​issue-triage.md Adds shared triage policy and bounded outputs.
.github/​workflows/​doc-updater.md Adds shared documentation policy and bounded outputs.
.github/​workflows/​ci.yml Adds centralized validation; include actions-lock.json in generated-state checks.
.github/​workflows/​ci-doctor.md Adds shared CI diagnosis policy; add a failure-only activation guard.
.github/​workflows/​ci-doctor.lock.yml Regenerated CI Doctor workflow lock.
.github/​aw/​actions-lock.json Refreshes pinned gh-aw action metadata.
.gitattributes Updates generated lock-file attributes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Gate CI doctor on failures, check generated action-pin drift, and keep the test command on one executable line.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 4, 2026 19:00
@DevOpsDerek

Copy link
Copy Markdown
Owner Author

Addressed the three moderate overview findings in d647c8a:

  • .github/workflows/ci-doctor.md: executable frontmatter if limits activation to failed workflow runs. Regenerated lock gates both pre_activation and activation; existing repository/fork guards are preserved.
  • .github/workflows/ci.yml: after central compilation, reject unstaged, staged or untracked drift in .github/aw/actions-lock.json. The central action still checks the workflow source/lock directory. README documents the additional pin-cache check.
  • .github/workflows/test-improver.md: complete validation command is now one line in a shell code block; regenerated prompt contains that same executable command.

Validation: gh-aw compile/schema/actionlint passes for all four workflows, repeat/post-commit compilation leaves locks and action-pin cache unchanged, hand-authored actionlint and Markdown lint pass. Tested the exact CI drift step in an isolated fixture: clean state succeeds; unstaged, staged and untracked action-pin changes fail. Safe-output handler configurations remain unchanged. Executing the corrected test command still fails the pre-existing NU1903 Microsoft.OpenApi 2.0.0 restore gate; no suppression or dependency changes. PR remains draft; no merge or deployment.

Apply the identical minimal same-major override proposed by dependency PR #13; retain NuGet audit and warnings-as-errors.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@DevOpsDerek

Copy link
Copy Markdown
Owner Author

Included the security prerequisite in separate commit 3b54844: the identical one-line fix from open dependency PR #13 (Microsoft.OpenApi 2.7.5 explicit reference in src/Api/Api.csproj). No major-version/code migration, audit suppression or weakened warnings/security gates. Leave #13 for human deduplication/sequencing; neither PR was merged.

Current local validation now passes: restore, format verification, Release build (0 warnings/errors), all 8 tests, and 92.8% line coverage (60% gate preserved). The prior NU1903 baseline blocker is resolved on this branch. Hosted CI/CodeQL/dependency checks are running for the new commit; PR remains draft and issue #34 open pending acceptance.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Configure an allowed-labels list so CI diagnosis cannot request arbitrary labels.

Review effort: Lite
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity Restrict agent-requested labels with an allowed-labels list

.github/​workflows/​ci-doctor.md:32

labels: [] only specifies that no fixed labels are added; it does not restrict labels supplied by the agent. The compiled create_issue schema still accepts a labels array (see ci-doctor.lock.yml:656-660), and because no allowed-labels is configured, the agent can request arbitrary/new labels, contradicting the no-invented-labels guardrail in this source and the PR description. Configure an allowed-labels list containing the repository's existing labels so the safe-output handler filters agent requests.

Copilot AI lite review requested due to automatic review settings October 4, 2026 19:04
@DevOpsDerek
DevOpsDerek marked this pull request as ready for review October 4, 2026 19:05
@DevOpsDerek
DevOpsDerek merged commit f304639 into main Oct 4, 2026
9 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

CI Doctor does not enforce the no-label policy in its safe-output handler, allowing arbitrary labels.

Review effort: Lite
Findings: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants