fix(ci): make the validate job actually able to run — it never had
CI / validate (pull_request) Failing after 14s
CI / validate (pull_request) Failing after 14s
ci.yml has been invalid YAML since introduction: the 'Config validation' and old inline checks dedented out of their run:| block scalar, so Gitea could never parse the workflow — CI never ran on any PR despite CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always passed (|| echo swallows the grep hit) and never scanned *.yml — where six embedded credentials were living. - validation logic moved to ci_check.py (testable locally: python3 ci_check.py all) - secrets check now FAILS on embedded http-basic URLs and long api_keys, across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist - added workflow-YAML parse gate so this class of breakage can't recur - py_compile steps no longer swallow errors with '|| echo skipped' - removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml copy would have deployed Mumuni on rc tags too, breaking canary policy, and never ran anyway. - CI_STATUS.md rewritten with the real state + caveats (history still contains the old creds — rotation is a server-side task)
This commit is contained in:
+26
-1
@@ -1,2 +1,27 @@
|
||||
# CI Pipeline Status
|
||||
Status: Active
|
||||
|
||||
**Last verified: 2026-09-25** — see PR "main security + truncate + CI repair".
|
||||
|
||||
## Reality check (before that PR)
|
||||
`ci.yml` was **invalid YAML** — the inline `run: |` blocks for the config and
|
||||
secrets checks dedented out of their block scalar, so Gitea Actions could never
|
||||
parse the workflow. CI never ran on any PR, and this file's "Active" status was
|
||||
fiction. The old "No secrets check" also swallowed hits with `|| echo` (always
|
||||
green) and never scanned `.yml` files — which is where six embedded
|
||||
credentials were living.
|
||||
|
||||
## Current pipeline
|
||||
| Trigger | Job | Checks |
|
||||
|---|---|---|
|
||||
| PR → main, push main, tag `v*` | `validate` | adapter + a2a `py_compile`; workflow YAML parse; `config.yaml.example`; secret scan; `bash -n scripts/deploy.sh` |
|
||||
| tag `v*` | `deploy` | Tanko canary + Mumuni via `scripts/deploy.sh` (native mode) |
|
||||
|
||||
All validation logic lives in **`ci_check.py`** — run `python3 ci_check.py all`
|
||||
locally before pushing; it fails the check on real hits instead of echoing
|
||||
warnings.
|
||||
|
||||
## Known caveats
|
||||
- The removed credentials still exist in git history (pre-July commits) —
|
||||
rotating `abiba-bot`'s password is a **server-side** task, out of repo scope.
|
||||
- Runner availability (`zulip-runner` on CT 116) is not verifiable from agents
|
||||
— the first green run after merge is the proof.
|
||||
|
||||
Reference in New Issue
Block a user