retro: Add scheduled retrospective analysis across deployments - #123
bootc-bot[bot] wants to merge 1 commit into
Conversation
Every six hours, collect recent gh-aw runs from each public bootc-dev repository that has compiled gh-aw workflows, and let an agent file up to three deduplicated improvement issues here. The collection is a deterministic pre-fetch outside the sandbox, since the agent's own gh is unauthenticated; it records per-job conclusions so runs whose agent job was silently skipped stand out, and reports anything it couldn't fetch instead of presenting it as healthy. retro.md is not added to aw.yml, so gh aw add consumers don't get it. Adds an agent/retro label for the filed issues. Closes: #73 Generated-by: AI Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| # Deterministic pre-fetch, outside the sandbox (the agent's own `gh` is not | ||
| # authenticated). Like queue-triage.md, every value the run: script uses |
There was a problem hiding this comment.
Right actually we should cut over to the gh-proxy mode from https://github.github.com/gh-aw/reference/github-tools/#github-tools-access-modes
Let's do that across the board in our tools (can we have a common facotred out incliude for it?)
| HOST_REPO: ${{ github.repository }} | ||
| LOOKBACK_HOURS: ${{ github.event.inputs.lookback_hours || '8' }} | ||
| run: | | ||
| set -euo pipefail |
There was a problem hiding this comment.
No no no let's add to AGENTS.md I hate anything that's more than 10 lines of bash. Unacceptable.
We should absolutely not have giant inline bash in yaml in markdown.
Splitting scripts like this out-of-line would help.
node.js with zero deps for slightly longer things past that we will use Rust.
We may end up with a shared "github tools" wrapper for gh or so? But prereq is using proper authenticated gh here.
|
Warning The Pushed a fix commit for the two review threads:
Two things need a human decision:
The larger inline bash pre-fetches in
|
Adds
retro.md, a scheduled gh-aw workflow that runs in this repository only and looks back at how the pipeline behaved in each repository where it's deployed (#73). This is a redo of the closed #74, rebased on currentmain.What it does
Schedule: gh-aw's fuzzy
every 6h(compiled to17 */6 * * *), plusworkflow_dispatchwith alookback_hoursinput (1–168, default 8). The 8h window overlaps the 6h schedule on purpose, so a run still in progress at one fetch is seen as completed at the next.Which repos count as deployed: every public, non-archived, non-fork repo in the org with at least one
.github/workflows/*.lock.yml. Today that's bcvk and this repo; new adopters are picked up automatically, with no hardcoded list.Deterministic pre-fetch (a
steps:block outside the sandbox, followingqueue-triage.md): the agent's ownghis unauthenticated, which was the main problem with feat: Add retro workflow for retrospective analysis #74'sgh apiinstructions. The step writes:successwith a skippedagentjob (thepre_activationgotcha) stands out,summary.txt.Fetches are capped (150 job lookups, 20 failed-job logs). Any fetch failure or truncation goes into the summary, and the prompt tells the agent to report it via
missing-datainstead of treating it as healthy.Outputs: at most 3
create-issueper run, titled[retro] ...and labeledagent/retro, each proposing a concrete change to a named file in this repo, after checking all open issues for duplicates.noophasreport-as-issue: false, so quiet runs don't comment on gh-aw's tracking issue every 6 hours.Not added to
aw.yml, sogh aw addconsumers don't get it.Supporting changes
justfileandci.ymlcompile lists now includeretro.agent/retrolabel inscripts/install-labels.js,install-labels.yml,scripts/README.mdand the README setup checklist (eight → nine labels). Note thatinstall-labels.ymlships to consumers, so they'll get this label too, the same asagent/flake-trackertoday.Validation
just setup && just compile: all 6 workflows compile with 0 warnings. I followed the compiler's suggestions to use the fuzzy schedule and aconcurrency.job-discriminator. No other.lock.ymlchanged.ghcovering these cases, all of which behave as intended:total_count > 100truncation,jobs: null),agentjob,lookback_hours.node tests/workflow-rerun.test.jsandnode --test tests/org-history.test.jspass.head/pipefailhazard, README wording) are fixed.Not validated: I haven't run it live, since there's no authenticated API here. To check after merging:
ghcalls through it (min-integrity: approved, as inqueue-triage.md). Open issues from low-integrity authors may be dropped from the dedup list, matching what the agent's GitHub tools would see. The first real run should confirm that cross-repo run and job-log reads go through it.scripts/org-history.jshelpers in a follow-up.timeout-minutesis set, per CLAUDE.md, so the agent job gets gh-aw's default.Generated-by: AI
The workflow and docs were generated by an agent and still need careful human review, especially the prompt text, commit message and README wording. The commit has no
Signed-off-by; if the DCO check needs one, a human should review it and amend withgit commit --amend -s.Closes #73
🤖 Generated with [Claude Code]((claude.com/redacted)