# Gadfly — REUSABLE adversarial-review workflow (Gitea `workflow_call`). # # Centralizes the ~90-line consumer stub so a repo can subscribe to Gadfly with # a tiny caller. A consumer workflow does: # # jobs: # review: # if: ... # actor gate for the comment trigger # uses: steve/gadfly/.gitea/workflows/review-reusable.yml@ # secrets: # forward ONLY what the reviewer needs # OLLAMA_CLOUD_API_KEY: ${{ secrets.OLLAMA_CLOUD_API_KEY }} # CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # with: { models: "...", allowed_users: "..." } # all optional # # Inputs are all optional and default to "" — an empty env value makes the # image/entrypoint use its own built-in default, so the caller only sets what it # wants to override. Secrets are DECLARED below (workflow_call.secrets) so a # caller forwards only the credentials the reviewer actually uses — least # privilege — rather than `secrets: inherit`, which leaks every caller secret # (registry/deploy/db creds) into this workflow. `secrets: inherit` still works # if you accept that exposure; the explicit form is recommended. GITEA_TOKEN is # the automatic job token (no need to forward it). # # Advisory only — never blocks a merge. The image is pinned to an immutable # :sha- tag here (act_runner caches :latest); bump it per Gadfly release. # Consumers should likewise pin `uses: ...@` (not @main) so a push to this # repo can't silently change the code that runs with their forwarded secrets. name: Gadfly review (reusable) on: workflow_call: inputs: models: { type: string, default: "" } # GADFLY_MODELS (csv) specialists: { type: string, default: "" } # GADFLY_SPECIALISTS provider: { type: string, default: "" } # GADFLY_PROVIDER base_url: { type: string, default: "" } # GADFLY_BASE_URL provider_concurrency: { type: string, default: "" } # GADFLY_PROVIDER_CONCURRENCY provider_lens_concurrency: { type: string, default: "" } # GADFLY_PROVIDER_LENS_CONCURRENCY timeout_secs: { type: string, default: "" } # GADFLY_TIMEOUT_SECS (per lens) max_steps: { type: string, default: "" } # GADFLY_MAX_STEPS worker_model: { type: string, default: "" } # GADFLY_WORKER_MODEL allowed_users: { type: string, default: "" } # GADFLY_ALLOWED_USERS trigger_phrase: { type: string, default: "" } # GADFLY_TRIGGER_PHRASE # Job wall-clock cap. 45 > 30 as a default: a multi-model swarm or a slow # lens (e.g. claude-code with extended thinking) can exceed 30 minutes. timeout_minutes: { type: number, default: 45 } # Declared so callers can forward ONLY the secrets the reviewer needs # (least privilege) instead of `secrets: inherit`, which would hand this # workflow every secret in the caller's repo (registry/deploy/db creds the # review never touches). All optional — an unset/unpassed secret resolves to # empty, harmless for the providers a given consumer doesn't use. GITEA_TOKEN # is the automatic job token and need not be declared/forwarded. Consumers # with bespoke GADFLY_ENDPOINT_s beyond M1/M5 need the full stub. secrets: OLLAMA_CLOUD_API_KEY: { required: false } OPENAI_API_KEY: { required: false } ANTHROPIC_API_KEY: { required: false } GOOGLE_API_KEY: { required: false } GADFLY_API_KEY: { required: false } CLAUDE_CODE_OAUTH_TOKEN: { required: false } GADFLY_ENDPOINT_M1: { required: false } GADFLY_ENDPOINT_M5: { required: false } GADFLY_FINDINGS_URL: { required: false } GADFLY_FINDINGS_TOKEN: { required: false } # The reusable job posts the review comment, so it needs issues/PR write. Gitea # caps these by the caller's granted permissions; declaring them here is explicit. permissions: contents: read issues: write pull-requests: write jobs: review: runs-on: ubuntu-latest timeout-minutes: ${{ inputs.timeout_minutes }} steps: - uses: docker://gitea.stevedudenhoeffer.com/steve/gadfly:sha-c342bdb env: # --- event context (from the CALLER's github.*) ------------------- GITEA_API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} # github.token is the auto job token from the github CONTEXT (not a # secret), so it's present even without `secrets: inherit`. Using # secrets.GITEA_TOKEN here would be empty under explicit secret # forwarding, since the auto token isn't a forwarded workflow_call secret. GITEA_TOKEN: ${{ github.token }} EVENT_NAME: ${{ github.event_name }} PR: ${{ github.event.pull_request.number || github.event.issue.number || github.event.inputs.pr_number }} PR_BRANCH: ${{ github.head_ref }} IS_DRAFT: ${{ github.event.pull_request.draft }} COMMENT_BODY: ${{ github.event.comment.body }} COMMENT_ID: ${{ github.event.comment.id }} ACTOR: ${{ github.actor }} # --- provider auth (via secrets: inherit; empty if consumer unset) - OLLAMA_CLOUD_API_KEY: ${{ secrets.OLLAMA_CLOUD_API_KEY }} OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }} GOOGLE_API_KEY: ${{ secrets.GOOGLE_API_KEY }} GADFLY_API_KEY: ${{ secrets.GADFLY_API_KEY }} CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # Common named foreman/LAN endpoints (optional). Consumers with other # GADFLY_ENDPOINT_s need the full stub (examples/), since a # reusable workflow can't enumerate arbitrary names. GADFLY_ENDPOINT_M1: ${{ secrets.GADFLY_ENDPOINT_M1 }} GADFLY_ENDPOINT_M5: ${{ secrets.GADFLY_ENDPOINT_M5 }} # --- findings telemetry (optional) -------------------------------- GADFLY_FINDINGS_URL: ${{ secrets.GADFLY_FINDINGS_URL }} GADFLY_FINDINGS_TOKEN: ${{ secrets.GADFLY_FINDINGS_TOKEN }} # --- config (from inputs; empty => image default) ----------------- GADFLY_MODELS: ${{ inputs.models }} GADFLY_SPECIALISTS: ${{ inputs.specialists }} GADFLY_PROVIDER: ${{ inputs.provider }} GADFLY_BASE_URL: ${{ inputs.base_url }} GADFLY_PROVIDER_CONCURRENCY: ${{ inputs.provider_concurrency }} GADFLY_PROVIDER_LENS_CONCURRENCY: ${{ inputs.provider_lens_concurrency }} GADFLY_TIMEOUT_SECS: ${{ inputs.timeout_secs }} GADFLY_MAX_STEPS: ${{ inputs.max_steps }} GADFLY_WORKER_MODEL: ${{ inputs.worker_model }} GADFLY_ALLOWED_USERS: ${{ inputs.allowed_users }} GADFLY_TRIGGER_PHRASE: ${{ inputs.trigger_phrase }}