-
Notifications
You must be signed in to change notification settings - Fork 0
feat(automation): run mightyETL hourly NVIDIA NIM review repair #1088
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
ae21a13
04dfa16
ac7f1ce
71241dd
d955cb9
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,35 @@ | ||
| name: mightyETL Hourly Review Repair | ||
|
|
||
| on: | ||
| schedule: | ||
| # Minute 8 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4), | ||
| # codec-carver (5), life-os (6), Wardnet (7), naruon (11), | ||
| # pg-erd-cloud (13), orchestrator (17), noema (19), Clearfolio (23), | ||
| # Keyverse (29), Scopeweave (31), DiskSage (37), Appguardrail (41), | ||
| # newsdom-api (43), Inkspan (47), fast-mlsirm (49), BandScope (53), | ||
| # and semantic-data-portal (59). | ||
|
Comment on lines
+5
to
+10
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Minute-8 avoidance comment omits neighbors already documented elsewhere The cron comment in mightyetl-hourly-review-repair.yml lists minutes it avoids but omits Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| - cron: "8 * * * *" | ||
|
Comment on lines
+1
to
+11
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: New caller not added to docs/automation/hourly-review-repair.md This PR registers the new caller in the quality workflow path filters and CLAUDE.md, but does not add it to Was this helpful? React with 👍 or 👎 to provide feedback.
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Cron minute 8 does not collide with existing hourly callers Verified all sibling hourly-review-repair workflows use distinct cron minutes (27, 53, 23, 37, 49, 21, 43, 16, 10, 14) and none use minute 8, so the new Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| concurrency: | ||
| group: mightyetl-hourly-review-repair | ||
| # A later heartbeat must not cancel an in-flight CDC or ETL RCA. | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| dispatch-review-repair: | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| uses: ./.github/workflows/pr-review-fix-scheduler.yml | ||
| with: | ||
| target_repository: ContextualWisdomLab/mightyETL | ||
| base_branch: develop | ||
| max_prs: "50" | ||
| max_dispatches: "1" | ||
| retry_hours: "2" | ||
| secrets: | ||
| PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }} | ||
| OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }} | ||
|
Comment on lines
+26
to
+35
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Caller inputs match the reusable scheduler contract All Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,140 @@ | ||
| # mightyETL hourly review-repair caller | ||
|
|
||
| 검토 기준일: **2026-08-17** | ||
|
|
||
| ## Decision | ||
|
|
||
| ContextualWisdomLab operates one protected hourly caller for | ||
| `ContextualWisdomLab/mightyETL` (microservices CDC and bounded ETL | ||
| platform). The caller runs at minute 8, delegates to the product-neutral | ||
| central review-fix scheduler, inspects at most 50 open pull requests | ||
| targeting protected `develop`, and dispatches at most one bounded repair | ||
| per heartbeat. | ||
|
|
||
| A paying buyer of change-data-capture pipelines would feel live mightyETL | ||
| pull requests stalling while hourly NVIDIA NIM repair scanned only | ||
| Clearfolio, DiskSage, and fast-mlsirm. Live heads such as | ||
| ContextualWisdomLab/mightyETL#327 (blank Config Server authority), | ||
| ContextualWisdomLab/mightyETL#326 (hourly maintenance on develop), | ||
| ContextualWisdomLab/mightyETL#322 (explicit Config Server authority), | ||
| and ContextualWisdomLab/mightyETL#321 (confidential CDC probe | ||
| diagnostics) target `develop` and never enter those other callers. | ||
|
|
||
| The caller does not implement review or mutation logic itself. mightyETL | ||
| remains standalone; naruon and other CWL services consume transformed | ||
| records without owning the CDC runtime. Privileged automation stays in | ||
| `ContextualWisdomLab/.github`. | ||
|
|
||
| ## Root-cause analysis and remediation feasibility | ||
|
|
||
| The reusable worker performs exact-head root-cause analysis and tests | ||
| remediation feasibility before it edits. The reusable worker must: | ||
|
|
||
| 1. Refetch the exact live head, base, reviews, checks, changed paths, and | ||
| writer state. | ||
| 2. Establish the causal chain rather than repeat the terminal symptom. | ||
| 3. Enumerate materially distinct minimal remedies. | ||
| 4. Reject remedies that lack writer authority, cross sealed paths, require | ||
| unavailable credentials or protected-setting changes, violate stack | ||
| order, cannot be verified, or do not alter the diagnosed cause. | ||
| 5. Dispatch at most one feasible repair. Otherwise leave the tree | ||
| unchanged. | ||
|
|
||
| A queued or pending check remains a merge blocker but is not itself a | ||
| code finding. The independent non-author approval remains an external | ||
| authorization gate and is never synthesized by the repair worker. The | ||
| worker cannot approve, merge, release, resolve review findings by | ||
| inference, change protection, or manufacture passing checks. | ||
|
|
||
| ## Cadence and concurrency | ||
|
|
||
| The caller uses a single concurrency group and `cancel-in-progress: false`. | ||
| This preserves an in-flight bounded RCA instead of discarding CDC | ||
| evidence when the next hourly heartbeat arrives. The reusable scheduler | ||
| cancels only its own superseded short queue scan. | ||
|
|
||
| The caller sets a **two-hour same-head retry floor**. Central OpenCode and | ||
| NVIDIA NIM work, plus Config Server or replication-probe analysis, can | ||
| legitimately approach two hours. An hourly redispatch of the same | ||
| unchanged head would create duplicate writer pressure rather than faster | ||
| remediation. | ||
|
|
||
| GitHub scheduled workflows can be delayed under load and execute only | ||
| from the default branch. The cron expression is a heartbeat, not a | ||
| real-time SLA. | ||
|
|
||
| ## Credential and model boundary | ||
|
|
||
| The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants | ||
| the reusable job `id-token: write` so the central scheduler can request | ||
| a GitHub OIDC JWT. The scheduler governs any subsequent credential exchange | ||
| (GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and | ||
| `OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives | ||
| `NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. The caller | ||
| applies least privilege to prevent CWE-250 by excluding write and model | ||
| privileges it does not need (MITRE, 2026). | ||
|
|
||
| Model execution remains inside the central worker. The model credential | ||
| is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or | ||
| forward it. | ||
|
|
||
| Before protected-develop activation, the repository variable | ||
| `OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact | ||
| `ContextualWisdomLab/mightyETL` target. Missing or mismatched | ||
| configuration fails before mutation credential materialization. | ||
|
|
||
| ## Security, standalone operation, and modularity | ||
|
|
||
| The caller adds no mightyETL runtime dependency, database object, network | ||
| endpoint, tenant authority, or product credential. mightyETL continues to | ||
| run as a standalone CDC/ETL platform. Naruon and other CWL services may | ||
| consume its output, but they cannot weaken its exact-head, approval, or | ||
| security gates. | ||
|
|
||
| ## Verification and rollback | ||
|
|
||
| Machine-checkable contracts require the exact target/base, minute 8 | ||
| cadence, non-cancelling single-flight group, one dispatch, two-hour | ||
| retry floor, explicit secret mapping, read-only contents plus job-scoped | ||
| `id-token: write`, focused path-filter coverage, and absence of model or | ||
| Copilot credentials. Independent `pull_request`, `push`, and `compileall` | ||
| path blocks must each name the caller, doctoring, or contract they own. | ||
|
|
||
| After source integration, closure requires a scheduled protected-develop | ||
| consumer run proving the exact mightyETL repository and | ||
| `develop` base. Source checks alone are not protected-develop operational acceptance. | ||
| Merge still requires zero unresolved valid findings and a | ||
| qualifying independent non-author approval. | ||
|
|
||
| Rollback removes the mightyETL caller, its focused test, doctoring, and | ||
| central path-filter/documentation entries. It must not remove scheduler | ||
| dispatch validation or affect independent product callers. | ||
|
|
||
| ## APA 7th references | ||
|
|
||
| GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule | ||
|
|
||
| GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August | ||
| 17, 2026, from | ||
| https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows | ||
|
|
||
| GitHub, Inc. (n.d.-c). *OpenID Connect reference*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/security/oidc | ||
|
|
||
| MITRE. (2026). *CWE-250: Execution with unnecessary privileges*. | ||
| https://cwe.mitre.org/data/definitions/250.html | ||
|
|
||
| National Institute of Standards and Technology. (2022). *Secure software | ||
| development framework (SSDF) version 1.1: Recommendations for mitigating | ||
| the risk of software vulnerabilities* (NIST Special Publication 800-218). | ||
| https://doi.org/10.6028/NIST.SP.800-218 | ||
|
|
||
| NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.nvidia.com/nim/large-language-models/latest/ | ||
|
|
||
| OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, | ||
| from https://opencode.ai/docs/ |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -213,9 +213,9 @@ packaging==26.2 \ | |
| # via | ||
| # pip-audit | ||
| # pip-requirements-parser | ||
| pip==26.1.2 \ | ||
| --hash=sha256:382ff9f685ee3bc25864f820aa50505825f10f5458ffff07e30a6d96e5715cab \ | ||
| --hash=sha256:f49cd134c61cf2fd75e0ce2676db03e4054504a5a4986d00f8299ae632dc4605 | ||
| pip==26.2.1 \ | ||
| --hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c42108c0384ed3e \ | ||
| --hash=sha256:f6ad667e89a1fe78046c8f13232b247200f5258d7828f3f7883d660878e0813f | ||
|
Comment on lines
+216
to
+218
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔍 Unrelated pip bump in pip-audit hashes file requirements-pip-audit-ci-hashes.txt bumps pip 26.1.2→26.2.1 with new hashes — the only dependency change in an otherwise config/docs PR. CLAUDE.md requires regenerating Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| # via pip-api | ||
| pip-api==0.0.34 \ | ||
| --hash=sha256:8b2d7d7c37f2447373aa2cf8b1f60a2f2b27a84e1e9e0294a3f6ef10eb3ba6bb \ | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Schedule-avoidance comment lists cross-repo minute allocations, not this repo's
The scheduling comment in mightyetl-hourly-review-repair.yml claims minute 8 avoids e.g.
Wardnet (7), but within this repo minute 7 is actually taken byorganization-commercial-readiness-loop.yml. This is an org-wide minute-allocation ledger comment, not a per-repo conflict list, so it does not affect correctness (minute 8 is genuinely unique among this repo's scheduled workflows). Noting for awareness only in case the org intends this comment to stay accurate.Was this helpful? React with 👍 or 👎 to provide feedback.