CI / validate (pull_request) Failing after 14s
ci.yml has been invalid YAML since introduction: the 'Config validation' and old inline checks dedented out of their run:| block scalar, so Gitea could never parse the workflow — CI never ran on any PR despite CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always passed (|| echo swallows the grep hit) and never scanned *.yml — where six embedded credentials were living. - validation logic moved to ci_check.py (testable locally: python3 ci_check.py all) - secrets check now FAILS on embedded http-basic URLs and long api_keys, across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist - added workflow-YAML parse gate so this class of breakage can't recur - py_compile steps no longer swallow errors with '|| echo skipped' - removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml copy would have deployed Mumuni on rc tags too, breaking canary policy, and never ran anyway. - CI_STATUS.md rewritten with the real state + caveats (history still contains the old creds — rotation is a server-side task)
1.3 KiB
1.3 KiB
CI Pipeline Status
Last verified: 2026-09-25 — see PR "main security + truncate + CI repair".
Reality check (before that PR)
ci.yml was invalid YAML — the inline run: | blocks for the config and
secrets checks dedented out of their block scalar, so Gitea Actions could never
parse the workflow. CI never ran on any PR, and this file's "Active" status was
fiction. The old "No secrets check" also swallowed hits with || echo (always
green) and never scanned .yml files — which is where six embedded
credentials were living.
Current pipeline
| Trigger | Job | Checks |
|---|---|---|
PR → main, push main, tag v* |
validate |
adapter + a2a py_compile; workflow YAML parse; config.yaml.example; secret scan; bash -n scripts/deploy.sh |
tag v* |
deploy |
Tanko canary + Mumuni via scripts/deploy.sh (native mode) |
All validation logic lives in ci_check.py — run python3 ci_check.py all
locally before pushing; it fails the check on real hits instead of echoing
warnings.
Known caveats
- The removed credentials still exist in git history (pre-July commits) —
rotating
abiba-bot's password is a server-side task, out of repo scope. - Runner availability (
zulip-runneron CT 116) is not verifiable from agents — the first green run after merge is the proof.