majordomo now ships qwen and kimi as built-ins that ARE the openai client at their own base URL, so "qwen/qwen3.8-max" works as a GADFLY_MODELS entry once the key reaches the container. This wires up the parts that key has to pass through. Two provider switches had to learn the names, not one. resolveModel's GADFLY_BASE_URL override was the obvious one; endpointProvider's GADFLY_ENDPOINT_* parser is its sibling, and I fixed the first and missed the second on the first pass — a config that resolves one way and errors the other for no reason a user could guess. TestOpenAICompatProvidersResolveOnBothPaths now asserts both from one table so the pair fails together; break-checked in both directions. QWEN_API_KEY (and KIMI_API_KEY) are declared as workflow_call secrets and forwarded to the container, with gadfly's own stub forwarding QWEN_API_KEY so a qwen entry can join the default swarm by editing GADFLY_DEFAULT_MODELS alone — no workflow edit, no re-release. The run.sh credential pre-flight is now a provider→variable table instead of an ollama-cloud special case. Without it a forgotten key surfaces as five identical per-lens agent failures naming no variable, and the operator reads a stack trace to find out which secret they missed. Google stays out of the table on purpose: it accepts either GOOGLE_API_KEY or GEMINI_API_KEY, and a one-var entry would wrongly skip a correctly-configured run. Verified across 17 provider x key-state combinations, including that a wrong-provider key never satisfies qwen (majordomo refuses cross-provider fallback) and that unkeyed providers are never blocked. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
64 lines
2.7 KiB
YAML
64 lines
2.7 KiB
YAML
# Gadfly reviewing its OWN PRs — a thin CALLER of the reusable workflow
|
|
# (.gitea/workflows/review-reusable.yml), dogfooding the "subscribe" path. The
|
|
# reusable holds the image pin, env plumbing, AND the default swarm; this file
|
|
# holds only the triggers, the actor gate, secret forwarding, and allow-list.
|
|
#
|
|
# Advisory only — never blocks a merge. It inherits the default swarm: 3 cloud
|
|
# models + Claude Code (sonnet, opus, opus:max), 5-lens suite (claude models run
|
|
# one at a time, each with all 5 lenses at once).
|
|
|
|
name: Adversarial Review (Gadfly)
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, reopened, ready_for_review]
|
|
issue_comment:
|
|
types: [created]
|
|
workflow_dispatch:
|
|
inputs:
|
|
pr_number:
|
|
description: "PR number to review"
|
|
required: true
|
|
|
|
permissions:
|
|
contents: read
|
|
issues: write
|
|
pull-requests: write
|
|
|
|
concurrency:
|
|
group: gadfly-${{ github.event.issue.number || github.event.pull_request.number || github.event.inputs.pr_number }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
review:
|
|
# Security: only trusted users may trigger a secret-bearing run via a PR
|
|
# comment (pull_request + workflow_dispatch are already trusted). Mirrors
|
|
# the allowed_users input below, the in-container belt-and-suspenders check.
|
|
if: >-
|
|
github.event_name != 'issue_comment'
|
|
|| (github.event.issue.pull_request
|
|
&& (github.actor == 'steve'
|
|
|| github.actor == 'fizi'
|
|
|| github.actor == 'dazed'))
|
|
uses: ./.gitea/workflows/review-reusable.yml
|
|
# Least privilege: forward ONLY the secrets this swarm uses (cloud + Claude
|
|
# Code + findings telemetry), not `secrets: inherit`. GITEA_TOKEN is auto.
|
|
secrets:
|
|
OLLAMA_CLOUD_API_KEY: ${{ secrets.OLLAMA_CLOUD_API_KEY }}
|
|
CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
|
# Forwarded so a "qwen/<model>" entry can join the swarm by editing the
|
|
# GADFLY_DEFAULT_MODELS var alone — no workflow edit, no re-release.
|
|
# Empty until the repo secret exists: that's a 401 on that one model,
|
|
# not a broken review.
|
|
QWEN_API_KEY: ${{ secrets.QWEN_API_KEY }}
|
|
GADFLY_FINDINGS_URL: ${{ secrets.GADFLY_FINDINGS_URL }}
|
|
GADFLY_FINDINGS_TOKEN: ${{ secrets.GADFLY_FINDINGS_TOKEN }}
|
|
with:
|
|
# Inherit the default swarm (3 cloud + Claude Code sonnet/opus/opus:max,
|
|
# 5-lens suite) from review-reusable.yml. Only the consumer-specific
|
|
# allow-list is set here.
|
|
allowed_users: "steve,fizi,dazed"
|
|
# Gitea >= 1.27 does not propagate dispatch inputs into a called workflow's
|
|
# github.event — thread the PR number explicitly (empty on non-dispatch events).
|
|
pr_number: ${{ github.event.inputs.pr_number }}
|