Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
* text=auto eol=lf

# Generated agentic workflow lock files
.github/workflows/*.lock.yml linguist-generated=true merge=ours
.github/workflows/*.lock.yml linguist-generated=true

# Binary assets
*.png binary
Expand Down
6 changes: 3 additions & 3 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,10 +5,10 @@
"version": "v9.0.0",
"sha": "3a2844b7e9c422d3c10d287c895573f7108da1b3"
},
"github/gh-aw-actions/setup@v0.77.5": {
"github/gh-aw-actions/setup@v0.89.21": {
"repo": "github/gh-aw-actions/setup",
"version": "v0.77.5",
"sha": "3ea13c02d765410340d533515cb31a7eef2baaf0"
"version": "v0.89.21",
"sha": "924af5fdc64061cfbf66fb584c8b07e2ac230c60"
}
}
}
1,267 changes: 847 additions & 420 deletions .github/workflows/ci-doctor.lock.yml

Large diffs are not rendered by default.

60 changes: 25 additions & 35 deletions .github/workflows/ci-doctor.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ on:
branches:
- main

if: github.event.workflow_run.conclusion == 'failure'

permissions:
contents: read
actions: read
Expand All @@ -15,55 +17,43 @@ permissions:
engine: copilot
network: defaults

inlined-imports: true
imports:
- DevOpsDerek/workflows/.github/workflows/shared/agentic/ci-failure-diagnosis.md@dac4b81c298cb3ea6821ea312efa5375f42d5ccb

tools:
github:
toolsets: [default]

safe-outputs:
create-issue:
max: 1
title-prefix: "[CI diagnosis] "
labels: []
add-comment:
max: 1
missing-tool:
create-issue: false
---

# CI Doctor Agent

You diagnose failing CI/CD runs so engineers get a head start on the fix.
Follow the imported CI failure diagnosis policy for this repository's CI and CD.

## Trigger context

This workflow ran because another workflow finished — run number
**#${{ github.event.workflow_run.number }}**. Use the GitHub tools to look up that
workflow run by its number to discover its name, branch, and conclusion.

## What to do

1. **Stop immediately if the run did not fail.** Fetch the triggering run and read
its `conclusion`. If it is anything other than `failure` (e.g. `success`,
`cancelled`, `skipped`), take no action and end the run.
2. For a failed run, use the GitHub tools to fetch the workflow run, its failed
jobs, and the relevant log excerpts.
3. Determine the **most likely root cause**. Categorise it, for example:
- Build / compilation error
- Failing or flaky test, or coverage gate
- Linting / formatting failure (dotnet format, tflint, actionlint, markdownlint)
- Security gate (Trivy / CodeQL) finding
- Terraform validate/plan/apply failure
- Deployment or Azure authentication failure
4. Produce a concise diagnosis with: the failing job/step, the key error lines,
the probable cause, and **concrete suggested fixes** (commands or code changes).

## Output

- If a tracking issue for this failure does not obviously already exist, open
**one** issue titled
`CI failure: <workflow> on <branch> (run #<run_number>)` with your diagnosis,
the linked run URL, and suggested next steps. Apply a `ci/cd` label if available.
- Keep the report focused and skimmable using short sections and bullet points.

## Guardrails

- Never re-run, cancel, or modify workflows.
- Do not speculate beyond the evidence in the logs; if logs are inconclusive, say
what additional information is needed.
The triggering run ID is **${{ github.event.workflow_run.id }}**, run number
**#${{ github.event.workflow_run.run_number }}**, conclusion
**${{ github.event.workflow_run.conclusion }}**. Use the ID (not the display
number) to fetch its jobs and logs.

Stop immediately unless the conclusion is `failure`. Relevant checks include
the .NET solution build, xUnit/60% coverage gate, Terraform validation, TFLint,
actionlint, markdownlint, gh-aw compilation, Trivy, and OIDC deployment.
Diagnose authentication or deployment failures from existing logs only: do not
request credentials, rerun or cancel jobs, deploy, promote, or apply Terraform.

The local safe-output configuration deliberately specifies no labels; diagnosis
must not invent labels that do not exist in this repository.
Do not create labels, assign issues, or change project status. Include the
workflow, branch, and run number in the diagnostic title after its shared prefix.
17 changes: 17 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -175,4 +175,21 @@ jobs:
globs: |
**/*.md
!.github/workflows/**
!.github/aw/imports/**
!**/node_modules/**

- name: Validate agentic sources and locks
uses: DevOpsDerek/workflows/.github/actions/validate-agentic-workflows@dac4b81c298cb3ea6821ea312efa5375f42d5ccb
with:
gh-aw-version: v0.89.21
workflows-directory: .github/workflows

- name: Verify generated action pins are current
shell: bash
run: |
set -euo pipefail
if [[ -n "$(git status --porcelain -- .github/aw/actions-lock.json)" ]]; then
echo "::error::gh-aw action pins are out of date. Recompile and commit .github/aw/actions-lock.json with the workflow locks."
git status --short -- .github/aw/actions-lock.json
exit 1
fi
Loading
Loading