Build & push image / build-and-push (pull_request) Successful in 3s
The pre-flight comment was the worst of them, and three models agreed. It said providers absent from the table "need no key or carry it in their endpoint/DSN" — false for google, which needs a key and is absent for an entirely different reason: it accepts GOOGLE_API_KEY *or* GEMINI_API_KEY, so a single-variable arm would silently skip a correctly-configured reviewer. That reasoning was in the PR description and not in the code, so the comment invited exactly the wrong edit. It now states both exclusion reasons and names google's. Forwarded KIMI_API_KEY alongside QWEN_API_KEY in the dogfooding stub. This PR argues that sibling call sites must move together, and I declared both secrets in the reusable workflow and forwarded one — a config that looks complete and 401s on the model you didn't wire. The two endpoint-provider error messages listed the same accepted set in different order and spelling. Both functions accept an identical set, so they now share one endpointProviderNames constant and cannot disagree. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
69 lines
3.1 KiB
YAML
69 lines
3.1 KiB
YAML
# Gadfly reviewing its OWN PRs — a thin CALLER of the reusable workflow
|
|
# (.gitea/workflows/review-reusable.yml), dogfooding the "subscribe" path. The
|
|
# reusable holds the image pin, env plumbing, AND the default swarm; this file
|
|
# holds only the triggers, the actor gate, secret forwarding, and allow-list.
|
|
#
|
|
# Advisory only — never blocks a merge. It inherits the default swarm: 3 cloud
|
|
# models + Claude Code (sonnet, opus, opus:max), 5-lens suite (claude models run
|
|
# one at a time, each with all 5 lenses at once).
|
|
|
|
name: Adversarial Review (Gadfly)
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, reopened, ready_for_review]
|
|
issue_comment:
|
|
types: [created]
|
|
workflow_dispatch:
|
|
inputs:
|
|
pr_number:
|
|
description: "PR number to review"
|
|
required: true
|
|
|
|
permissions:
|
|
contents: read
|
|
issues: write
|
|
pull-requests: write
|
|
|
|
concurrency:
|
|
group: gadfly-${{ github.event.issue.number || github.event.pull_request.number || github.event.inputs.pr_number }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
review:
|
|
# Security: only trusted users may trigger a secret-bearing run via a PR
|
|
# comment (pull_request + workflow_dispatch are already trusted). Mirrors
|
|
# the allowed_users input below, the in-container belt-and-suspenders check.
|
|
if: >-
|
|
github.event_name != 'issue_comment'
|
|
|| (github.event.issue.pull_request
|
|
&& (github.actor == 'steve'
|
|
|| github.actor == 'fizi'
|
|
|| github.actor == 'dazed'))
|
|
uses: ./.gitea/workflows/review-reusable.yml
|
|
# Least privilege: forward ONLY the secrets this swarm uses (cloud + Claude
|
|
# Code + findings telemetry), not `secrets: inherit`. GITEA_TOKEN is auto.
|
|
secrets:
|
|
OLLAMA_CLOUD_API_KEY: ${{ secrets.OLLAMA_CLOUD_API_KEY }}
|
|
CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
|
# Forwarded so a "qwen/<model>" or "kimi/<model>" entry can join the
|
|
# swarm by editing the GADFLY_DEFAULT_MODELS var alone — no workflow
|
|
# edit, no re-release. Both are forwarded together on purpose: the
|
|
# reusable workflow declares both, and forwarding only one is a config
|
|
# that looks complete and 401s on the model you didn't wire. Empty until
|
|
# the repo secret exists, which is a 401 on that one model, not a broken
|
|
# review. NB kimi/<model> is Moonshot's own API — a different route than
|
|
# the kimi-k2.6:cloud swarm entry, which rides OLLAMA_CLOUD_API_KEY.
|
|
QWEN_API_KEY: ${{ secrets.QWEN_API_KEY }}
|
|
KIMI_API_KEY: ${{ secrets.KIMI_API_KEY }}
|
|
GADFLY_FINDINGS_URL: ${{ secrets.GADFLY_FINDINGS_URL }}
|
|
GADFLY_FINDINGS_TOKEN: ${{ secrets.GADFLY_FINDINGS_TOKEN }}
|
|
with:
|
|
# Inherit the default swarm (3 cloud + Claude Code sonnet/opus/opus:max,
|
|
# 5-lens suite) from review-reusable.yml. Only the consumer-specific
|
|
# allow-list is set here.
|
|
allowed_users: "steve,fizi,dazed"
|
|
# Gitea >= 1.27 does not propagate dispatch inputs into a called workflow's
|
|
# github.event — thread the PR number explicitly (empty on non-dispatch events).
|
|
pr_number: ${{ github.event.inputs.pr_number }}
|