Skip to content

retro: Add scheduled retrospective analysis across deployments - #123

Draft
bootc-bot[bot] wants to merge 1 commit into
mainfrom
agent/retro-workflow-73-25ed6464c7a3fd68
Draft

bootc-bot[bot] wants to merge 1 commit into
mainfrom
agent/retro-workflow-73-25ed6464c7a3fd68

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Adds retro.md, a scheduled gh-aw workflow that runs in this repository only and looks back at how the pipeline behaved in each repository where it's deployed (#73). This is a redo of the closed #74, rebased on current main.

What it does

  • Schedule: gh-aw's fuzzy every 6h (compiled to 17 */6 * * *), plus workflow_dispatch with a lookback_hours input (1–168, default 8). The 8h window overlaps the 6h schedule on purpose, so a run still in progress at one fetch is seen as completed at the next.

  • Which repos count as deployed: every public, non-archived, non-fork repo in the org with at least one .github/workflows/*.lock.yml. Today that's bcvk and this repo; new adopters are picked up automatically, with no hardcoded list.

  • Deterministic pre-fetch (a steps: block outside the sandbox, following queue-triage.md): the agent's own gh is unauthenticated, which was the main problem with feat: Add retro workflow for retrospective analysis #74's gh api instructions. The step writes:

    • runs per gh-aw workflow, queried per workflow so ordinary CI can't crowd them out of a page,
    • per-job conclusions for those runs, so a run that concluded success with a skipped agent job (the pre_activation gotcha) stands out,
    • bounded grep/tail log hints for failed jobs,
    • this repo's open issue titles, for deduplication,
    • a summary.txt.

    Fetches are capped (150 job lookups, 20 failed-job logs). Any fetch failure or truncation goes into the summary, and the prompt tells the agent to report it via missing-data instead of treating it as healthy.

  • Outputs: at most 3 create-issue per run, titled [retro] ... and labeled agent/retro, each proposing a concrete change to a named file in this repo, after checking all open issues for duplicates. noop has report-as-issue: false, so quiet runs don't comment on gh-aw's tracking issue every 6 hours.

  • Not added to aw.yml, so gh aw add consumers don't get it.

Supporting changes

  • justfile and ci.yml compile lists now include retro.
  • New agent/retro label in scripts/install-labels.js, install-labels.yml, scripts/README.md and the README setup checklist (eight → nine labels). Note that install-labels.yml ships to consumers, so they'll get this label too, the same as agent/flake-tracker today.
  • New README section, "Retrospective analyzer".

Validation

  • just setup && just compile: all 6 workflows compile with 0 warnings. I followed the compiler's suggestions to use the fuzzy schedule and a concurrency.job-discriminator. No other .lock.yml changed.
  • I extracted the pre-fetch script and ran it against a mock gh covering these cases, all of which behave as intended:
    • 404 vs. non-404 errors when listing workflows,
    • a failed run listing,
    • total_count > 100 truncation,
    • a failed jobs fetch (gives jobs: null),
    • a skipped agent job,
    • failed-job log hints,
    • PRs filtered out of the issue list,
    • invalid lookback_hours.
  • node tests/workflow-rerun.test.js and node --test tests/org-history.test.js pass.
  • A review subagent went over the diff, and its main findings (the truncation, swallowed errors, a head/pipefail hazard, README wording) are fixed.

Not validated: I haven't run it live, since there's no authenticated API here. To check after merging:

  • DIFC proxy: gh-aw routes the pre-fetch's gh calls through it (min-integrity: approved, as in queue-triage.md). Open issues from low-integrity authors may be dropped from the dedup list, matching what the agent's GitHub tools would see. The first real run should confirm that cross-repo run and job-log reads go through it.
  • Shell length: the pre-fetch shell is longer than REVIEW.md's ~50-line guideline. If you'd rather, it could be ported to a tested node script reusing scripts/org-history.js helpers in a follow-up.
  • Timeout: no timeout-minutes is set, per CLAUDE.md, so the agent job gets gh-aw's default.

Generated-by: AI
The workflow and docs were generated by an agent and still need careful human review, especially the prompt text, commit message and README wording. The commit has no Signed-off-by; if the DCO check needs one, a human should review it and amend with git commit --amend -s.

Closes #73

🤖 Generated with [Claude Code]((claude.com/redacted)

Generated by Drafter for #73 · claude · opus55 · 390.3 AIC · ⌖ 44.7 AIC · ⊞ 4.3K · ◷

Every six hours, collect recent gh-aw runs from each public bootc-dev
repository that has compiled gh-aw workflows, and let an agent file
up to three deduplicated improvement issues here. The collection is a
deterministic pre-fetch outside the sandbox, since the agent's own gh
is unauthenticated; it records per-job conclusions so runs whose agent
job was silently skipped stand out, and reports anything it couldn't
fetch instead of presenting it as healthy.

retro.md is not added to aw.yml, so gh aw add consumers don't get it.
Adds an agent/retro label for the filed issues.

Closes: #73
Generated-by: AI
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@bootc-bot bootc-bot Bot added the agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate label Oct 1, 2026
@bootc-bot bootc-bot Bot mentioned this pull request Oct 1, 2026
@bootc-bot bootc-bot Bot added agent/review-working The review agent is actively working on this PR and removed agent/review-working The review agent is actively working on this PR labels Oct 1, 2026
Comment on lines +78 to +79
# Deterministic pre-fetch, outside the sandbox (the agent's own `gh` is not
# authenticated). Like queue-triage.md, every value the run: script uses

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right actually we should cut over to the gh-proxy mode from https://github.github.com/gh-aw/reference/github-tools/#github-tools-access-modes

Let's do that across the board in our tools (can we have a common facotred out incliude for it?)

HOST_REPO: ${{ github.repository }}
LOOKBACK_HOURS: ${{ github.event.inputs.lookback_hours || '8' }}
run: |
set -euo pipefail

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No no no let's add to AGENTS.md I hate anything that's more than 10 lines of bash. Unacceptable.

We should absolutely not have giant inline bash in yaml in markdown.

Splitting scripts like this out-of-line would help.

node.js with zero deps for slightly longer things past that we will use Rust.

We may end up with a shared "github tools" wrapper for gh or so? But prereq is using proper authenticated gh here.

@cgwalters cgwalters added agent/fixme Reviewer agent found issues that need fixing agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate and removed agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate labels Oct 1, 2026
@bootc-bot bootc-bot Bot added agent/fix-working The fix agent is actively working on this PR and removed agent/fixme Reviewer agent found issues that need fixing labels Oct 1, 2026
@bootc-bot

bootc-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Warning

The push_to_pull_request_branch operation failed: Branch push rejected: the branch includes changes to workflow files (.github/workflows/**) requiring the 'workflows' scope. The token used for the safe-outputs checkout does not have this scope. Fix: configure 'push-to-pull-request-branch.allow-workflows: true' with a GitHub App in 'safe-outputs.github-app', or exclude workflow files from the changeset.. The code changes were not applied.

Pushed a fix commit for the two review threads:

  • gh-proxy everywhere: the new .github/workflows/shared/github-tools.md sets tools.github.mode: gh-proxy. All six agentic workflows import it, and every lockfile has been recompiled. Prompts that said gh wasn't available, such as gh pr diff in shared/triage-classification.md, now tell the agent to use gh.
  • No giant inline bash: retro's ~150-line pre-fetch now lives in scripts/retro-collect.js, a zero-dependency Node script with the same outputs and bounds. It still runs as a deterministic step outside the sandbox. I tested it against a stubbed gh.

Two things need a human decision:

  1. trusted-users isn't enforced in gh-proxy mode. In the pinned gh-aw v0.90.1, the compiled CLI_PROXY_POLICY keeps min-integrity but drops trusted-users in every lockfile. As a result, issues filed by the bot are filtered again when an agent reads them with gh. That covers fallback issues and [retro] issues handed to the drafter. PRs are not affected, since non-fork PRs count as approved. I documented this in the README and the shared include. If that regression is unacceptable for now, an option is to keep review/ci-triage/queue-triage on the MCP server until upstream supports it.
  2. AGENTS.md: I did not add the "no more than ~10 lines of inline bash; zero-dep Node beyond that; Rust after that" rule. This repo's AGENTS.md is marked as canonically maintained in bootc-dev/infra common/, so the rule probably belongs there.

The larger inline bash pre-fetches in queue-triage.md and ci-triage.md are unchanged and out of scope here.

Generated by PR Fix Agent for #123 · claude · opus55 · 279.2 AIC · ⌖ 45.3 AIC · ⊞ 5.4K · ◷

@bootc-bot bootc-bot Bot removed the agent/fix-working The fix agent is actively working on this PR label Oct 1, 2026
@bootc-bot bootc-bot Bot mentioned this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent/workflow-edits-allowed Pre-authorizes agent runs to edit protected files without the request_review gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

New agent: retro

1 participant