Skip to content

ci: add weekly DRC end-to-end canary - #286

Merged
labgadget015-dotcom merged 1 commit into
mainfrom
ci/drc-e2e-canary
Sep 4, 2026
Merged

ci: add weekly DRC end-to-end canary#286
labgadget015-dotcom merged 1 commit into
mainfrom
ci/drc-e2e-canary

Conversation

@labgadget015-dotcom

Copy link
Copy Markdown
Owner

Replaces the accidental daily end-to-end signal that was removed today, at a seventh of the cost.

Why

The Event Router drops any sender whose login ends in [bot], so the nightly Daily Repository Summary issues never reach the council. That left the PR Triage Pipeline's daily rewrite of issue #164 as the only recurring event traversing the full path. That rewrite fired a three-minute council run every morning on an unchanged premise, so it was filtered out by dropping edited from the router's actionable-action list.

The Intake Canary that already runs every 30 minutes reads workflow metadata over the n8n API. It proves reachability, not that the path delivers. That is the same shape as the eight-day intake outage, where every probe stayed green.

What it asserts

It opens an issue, waits for a council execution, and then checks the Store to TIM Postgres node output rather than the execution status.

That distinction is the point. The node masks its own errors, so a failed audit write still reports a green execution. Issue #284 is exactly that failure.

Both branches were validated against real executions before this was committed.

Case Execution Result
Audit row written 7848 assertion passes
Masked write failure 7832 assertion fails

Notes

  • Uses GH_PAT, not GITHUB_TOKEN, so the canary issue passes the bot-sender filter. With GITHUB_TOKEN it would be silently dropped and always fail.
  • Costs one council run per week.
  • Closes the canary issue on completion, including on failure.

🤖 Generated with Claude Code

https://claude.ai/code/session_017bKHKCuokjG8ZKcizbgRs1

Restores a routine end-to-end signal for the intake path.

The Event Router drops any sender ending in "[bot]", so the nightly Daily
Repository Summary issues never reach the council. Until today the only
recurring event that traversed the full path was the PR Triage Pipeline's
daily rewrite of issue #164, which re-ran the council on an unchanged
premise every morning and has been filtered out. Without a replacement
there is no routine proof the path works, and the existing Intake Canary
only proves the n8n API is reachable.

The assertion inspects the "Store to TIM Postgres" node output rather than
the execution status, because that node masks its own errors and reports a
green execution while dropping the audit row. Both branches were validated
against real executions: the passing case against 7848, and the failing
case against 7832, the run that exposed the bug in #284.

Uses GH_PAT rather than GITHUB_TOKEN so the canary issue passes the router's
bot-sender filter. Costs one council run per week.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017bKHKCuokjG8ZKcizbgRs1
Copilot AI lite review requested due to automatic review settings September 4, 2026 08:38
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

📊 Code Complexity Analysis

Summary:

  • Total Functions Analyzed: 844
  • Average Complexity: 3.59
  • High Complexity Functions: 29
  • Low Maintainability Files: 60

⚠️ High Complexity Functions

These functions exceed the complexity threshold and should be refactored:

File Function Complexity Line
core/risk_scorer.py score_pull_request 35 141
autopilot/autopilot.py generate_summary 24 195
autopilot/staleness_engine.py process_stale_prs 16 281
autopilot/ai_optimization/performance_monitor.py get_benchmark_stats 15 184
.github/scripts/weekly_digest.py build_blocks 15 38
.github/scripts/batch_scan_dependabot.py main 15 64
autopilot/recommendation_contract.py validate 14 54
.github/scripts/prometheus_exporter.py collect_metrics 14 99
.github/scripts/self_healing_system.py analyze_failure_patterns 14 256
.github/scripts/setup_branch_protection.py main 14 240

... and 19 more

Recommendations:

  • Break down large functions into smaller, focused units
  • Extract complex conditional logic into separate functions
  • Use early returns to reduce nesting

🔧 Low Maintainability Files

These files have low maintainability scores and may need refactoring:

File Score Status
.github/scripts/health_dashboard_generator.py 28.14 🔴
.github/scripts/workflow_monitor.py 33.73 🔴
.github/scripts/ai_code_suggestor.py 33.76 🔴
.github/scripts/ai_workflow_optimizer.py 35.51 🔴
.github/scripts/performance_benchmark.py 39.46 🔴
.github/scripts/self_healing_system.py 40.27 🔴
.github/scripts/threshold_monitor.py 41.13 🔴
.github/scripts/parallel_code_analyzer_optimized.py 41.16 🔴
autopilot/tests/test_recommendation_contract.py 42.05 🔴
autopilot/autopilot.py 42.45 🔴
autopilot/ai_optimization/anomaly_detector.py 42.56 🔴
.github/scripts/refactoring_assistant.py 43.03 🔴
autopilot/ai_optimization/intelligent_cache.py 43.28 🔴
autopilot/ai_optimization/commit_summarizer.py 44.05 🔴
.github/scripts/async_parallel_analyzer.py 44.47 🔴
autopilot/ai_optimization/performance_monitor.py 44.69 🔴
.github/scripts/badge_generator.py 45.28 🔴
.github/scripts/copilot_integration.py 45.37 🔴
.github/scripts/distributed_monitoring.py 45.53 🔴
autopilot/dependency_graph.py 45.65 🔴
.github/scripts/elite_copilot.py 45.69 🔴
.github/scripts/issue_auto_creator.py 46.39 🔴
.github/scripts/cost_calculator.py 46.4 🔴
.github/scripts/inline_pr_commenter.py 46.63 🔴
.github/scripts/complexity_reporter.py 46.78 🔴
.github/scripts/pr_triage.py 47.13 🔴
core/risk_scorer.py 48.15 🔴
autopilot/ai_optimization/nlp_relevance_filter.py 48.43 🔴
.github/scripts/pr_inline_commenter.py 48.47 🔴
.github/scripts/dependency_audit.py 48.7 🔴
autopilot/staleness_engine.py 48.73 🔴
.github/scripts/dependency_updater.py 48.91 🔴
.github/scripts/metrics_collector.py 48.91 🔴
autopilot/ai_optimization/ml_priority_scorer.py 49.53 🔴
.github/scripts/parallel_code_analyzer.py 49.96 🔴
autopilot/ai_optimization/api_optimizer.py 50.46 🟡
.github/scripts/workflow_optimizer.py 51.67 🟡
.github/scripts/cot_selector.py 51.73 🟡
.github/scripts/release_manager.py 51.92 🟡
.github/scripts/check_quality.py 52.33 🟡
.github/scripts/auto_pr.py 52.72 🟡
.github/scripts/changelog_generator.py 53.13 🟡
.github/scripts/notification_manager.py 53.58 🟡
.github/scripts/prometheus_exporter.py 54.96 🟡
.github/scripts/weekly_digest.py 55.02 🟡
.github/scripts/llm_router.py 55.19 🟡
core/audit_logger.py 55.6 🟡
.github/scripts/gather_context.py 56.0 🟡
.github/scripts/batch_scan_dependabot.py 56.3 🟡
core/llm_provider.py 56.32 🟡
.github/scripts/streaming_results.py 56.64 🟡
.github/scripts/setup_branch_protection.py 57.0 🟡
.github/scripts/optimized_github_client.py 58.27 🟡
agents/orchestrator_agent.py 59.02 🟡
core/incident_freeze.py 59.67 🟡
core/github_client.py 61.96 🟡
core/message_queue.py 63.22 🟡
core/agent_config.py 63.82 🟡
autopilot/decisions/ledger.py 63.92 🟡
core/idempotency.py 64.45 🟡

Maintainability Index Guide:

  • 🟢 85-100: Excellent maintainability
  • 🟡 65-84: Good maintainability
  • 🟠 50-64: Moderate maintainability (consider refactoring)
  • 🔴 0-49: Poor maintainability (needs refactoring)

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🟢 Risk Assessment: LOW (2.5/10)

Analysed 3 files, 128+ / 24− lines. Security-sensitive paths detected. Test coverage unchanged or improved.

Scoring breakdown

Factor Score
Change volume — 152 lines changed +0.5
Sensitive paths — 1 security-relevant files +1.5
Risky extensions — 1 config/script files +0.5

⚠️ Security-sensitive paths modified

  • .github/workflows/drc-e2e-canary.yml

✅ Eligible for auto-merge (subject to CI passing).

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Code Quality Analysis ❌ FAILED

Duration: 0.01s
Total Issues: 10

Tool Results

  • pylint: ❌
  • flake8: ❌
  • bandit: ❌
  • radon_cc: ❌
  • radon_mi: ❌
View detailed results
{
  "timestamp": "2026-09-04 08:39:01",
  "elapsed_seconds": 0.01,
  "summary": {
    "total_issues": 10,
    "critical": 0,
    "high": 0,
    "medium": 0,
    "low": 0
  },
  "tools": {
    "pylint": {
      "status": "failed",
      "output": "",
      "errors": "Pylint error: [Errno 2] No such file or directory: 'pylint'"
    },
    "flake8": {
      "status": "failed",
      "output": "",
      "errors": "Flake8 error: [Errno 2] No such file or directory: 'flake8'"
    },
    "bandit": {
      "status": "failed",
      "output": "",
      "errors": "Bandit error: [Errno 2] No such file or directory: 'bandit'"
    },
    "radon_cc": {
      "status": "failed",
      "output": "",
      "errors": "Radon error: [Errno 2] No such file or directory: 'radon'"
    },
    "radon_mi": {
      "status": "failed",
      "output": "",
      "errors": "Radon MI error: [Errno 2] No such file or directory: 'radon'"
    }
  },
  "passed": false
}

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🔒 Security Scan Results

🛡️ Bandit Security Scan

  • 🔴 HIGH: 0
  • 🟡 MEDIUM: 5
  • 🟢 LOW: 107

📦 Dependency Vulnerabilities

  • Total vulnerable dependencies: 62

Vulnerable Dependencies:

  • pygithub 2.10.0
  • aiohttp 3.14.3
  • multidict 6.7.1
  • yarl 1.24.5
  • pyyaml 6.0.3
  • ... and 57 more

Security scans run automatically on every PR. View detailed reports in the Actions tab.

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🔍 Pre-commit Checks

✅ All pre-commit checks passed!

Your code follows the project style guidelines.


Pre-commit hooks help maintain code quality and consistency.

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🤖 Elite AI Copilot Analysis

Elite AI Copilot Analysis Report

Generated: 2026-09-04 08:39:27
Session ID: copilot_1788511167
Repository: .

🎯 Health Score: 100.0/100

🚀 Top Recommendations

  1. ✅ Repository is in excellent shape - continue current practices

📊 Detailed Insights

Code Quality Baseline Established

  • Category: code_quality
  • Severity: info
  • Description: Repository code quality metrics captured
  • Suggested Action: Continue monitoring for regressions
  • Confidence: 90%

Security Scan Initiated

  • Category: security
  • Severity: info
  • Description: No critical vulnerabilities detected in initial scan
  • Suggested Action: Enable continuous security monitoring
  • Confidence: 85%

Repository Structure Analyzed

  • Category: architecture
  • Severity: info
  • Description: Well-organized modular structure detected
  • Suggested Action: Maintain separation of concerns
  • Confidence: 80%

Performance Baseline Captured

  • Category: performance
  • Severity: info
  • Description: Repository performance metrics recorded
  • Suggested Action: Monitor for performance regressions
  • Confidence: 75%

Documentation Structure Good

  • Category: documentation
  • Severity: info
  • Description: Comprehensive documentation files present
  • Suggested Action: Keep documentation in sync with code changes
  • Confidence: 90%

Powered by Elite AI Copilot v1.0

@labgadget015-dotcom

Copy link
Copy Markdown
Owner Author

🤖 DRC Agent Analysis

Recommendation: 🟠 P1 IMPORTANT

Summary: Minimal Synthetic Issue Canary (Dreamer Solution 1, Realist-validated as feasible with known workarounds)

Next steps:

  1. Step 1: Run a manual workflow_dispatch connectivity test job against TIM Postgres (psql $TIM_POSTGRES_CONN_STR -c 'SELECT 1') to confirm network reachability before any other work — this is the go/no-go gate for the entire implementation
  2. Step 2: Create a dedicated canary GitHub App or PAT with repo+issues:write scope under a non-bot identity; store as GH_PAT_CANARY secret; verify this identity is not filtered by the Event Router bot-filter
  3. Step 3: Add all required secrets to the repository: GH_PAT_CANARY, N8N_API_KEY, N8N_BASE_URL, TIM_POSTGRES_CONN_STR — document each in the repo secrets inventory
  4. Step 4: Create the canary GitHub label (name: canary, color: #FFC300) and add an exclusion rule for this label in the Event Router filter to prevent canary issues from triggering real agent work
  5. Step 5: Implement .github/workflows/canary-drc-weekly.yml per Realist implementation path Steps 4-10, including concurrency guard, polling loop, psql assertion, always() cleanup, and job summary

Strategic fit: Consulting: high · Product: high · Tech debt: reduces


Analysed by GadgetLab DRC Agent (Dreamer → Realist → Critic) · Run run_1788511106780

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The canary’s execution selection relies on lexicographic timestamp comparison (startedAt > since), which can misorder/filter n8n timestamps (notably with fractional seconds) and produce false results.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds a new scheduled GitHub Actions workflow intended to provide a low-cost, weekly end-to-end canary for the DRC intake pipeline (GitHub issue → n8n DRC execution → tim.agent_runs audit write), specifically asserting the Store to TIM Postgres node output rather than trusting overall execution “green”.

Changes:

  • Introduces .github/workflows/drc-e2e-canary.yml to open a canary issue weekly using GH_PAT, poll n8n for the resulting DRC execution, and validate the audit-write node output.
  • Closes the created canary issue on completion (success or failure) and optionally alerts Slack on workflow failure.
File summaries
File Description
.github/workflows/drc-e2e-canary.yml New weekly workflow to exercise and assert the full DRC intake + audit-write path via a real GitHub issue and n8n execution inspection.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

N8N_API_KEY: ${{ secrets.N8N_API_KEY }}
SINCE: ${{ steps.t0.outputs.value }}
run: |
set -euo pipefail
Comment on lines +79 to +81
| jq -r --arg since "$SINCE" \
'[.data[] | select(.startedAt > $since) | select(.status != "running")]
| sort_by(.startedAt) | last | .id // ""')
Comment on lines +92 to +94
node=$(curl -sS -H "X-N8N-API-KEY: $N8N_API_KEY" \
"$N8N_BASE/api/v1/executions/$exec_id?includeData=true" \
| jq -c '.data.resultData.runData["Store to TIM Postgres"][0].data.main[0][0].json // {}')
@labgadget015-dotcom
labgadget015-dotcom merged commit 3d2aa0f into main Sep 4, 2026
39 checks passed
@labgadget015-dotcom
labgadget015-dotcom deleted the ci/drc-e2e-canary branch September 4, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants