Merge remote-tracking branch 'origin/main' into codex/playwright-mcp-supply-20260715
Some checks failed
CD Pipeline / workflow-shape (push) Successful in 0s
CD Pipeline / cancel-stale-cd (push) Has been skipped
CD Pipeline / tests (push) Successful in 4m17s
CD Pipeline / build-and-deploy (push) Successful in 15m48s
MCP External Artifact Mirror / mirror-and-verify (push) Failing after 49s
AWOOOI Harbor 110 Local Repair / workflow-shape (push) Successful in 0s
AWOOOI Harbor 110 Local Repair / harbor-110-local-repair (push) Successful in 20s
CD Pipeline / post-deploy-checks (push) Successful in 2m1s

# Conflicts:
#	apps/api/tests/test_gitea_capability_ci_cd_optimization_readback_api.py
#	docs/evaluations/gitea_workflow_runner_health_2026-06-05.json
This commit is contained in:
ogt
2026-07-15 10:04:31 +08:00
3 changed files with 100 additions and 28 deletions

View File

@@ -1,6 +1,6 @@
{
"schema_version": "gitea_workflow_runner_health_v1",
"generated_at": "2026-07-15T09:54:44+08:00",
"generated_at": "2026-07-15T09:57:22+08:00",
"program_status": {
"overall_completion_percent": 100,
"current_priority": "P1",
@@ -24,6 +24,7 @@
".gitea/workflows/mcp-external-artifact-mirror.yaml",
".gitea/workflows/run-migration.yml",
".gitea/workflows/type-sync-check.yaml",
"config/mcp/playwright-mcp-artifact-policy.json",
"docs/evaluations/ai_agent_version_lifecycle_update_proposal_2026-07-10.json",
"scripts/ci/check-gitea-step-env-secrets.js",
"scripts/ci/cleanup-host-runner-workspace.sh",
@@ -48,7 +49,7 @@
"workflow_ids_requiring_runner_attestation": [],
"total_runner_contracts": 5,
"runner_contracts_requiring_action": [],
"notification_contracts_total": 7,
"notification_contracts_total": 8,
"notification_contracts_quiet_success_count": 3,
"notification_contracts_quiet_success_ids": [
"agent_market_watch_actionable_only",
@@ -342,30 +343,31 @@
"workflow_id": "mcp_external_artifact_mirror",
"file_ref": ".gitea/workflows/mcp-external-artifact-mirror.yaml",
"display_name": "MCP External Artifact Mirror",
"scope": "以 exact npm registry artifact、digest、簽章、SLSA subject、SBOM 與 OSV 查核建立 Harbor scratch OCI bundle獨立 verifier 只讀回 layer data不啟動 MCP、browser 或 container。",
"scope": "以 exact npm registry URL、committed SHA-512 與 Harbor digest 執行受控外部 MCP artifact mirror只寫獨立 audit branch不啟動 MCP、不改 production route。",
"status": "manifest_mapped",
"risk_level": "high",
"triggers": [
"push:main",
"workflow_dispatch",
"schedule",
"push"
"schedule"
],
"schedule_cadence": "每週三 10:13 Asia/Taipei 重驗 pinned artifactcron=13 2 * * 3 UTC",
"schedule_cadence": "每週三 10:13 Asia/Taipeicron=13 2 * * 3 UTC",
"runner_labels": [
"awoooi-non110-host"
],
"runner_evidence_status": "non110_host_runner_mapped",
"job_count": 1,
"notification_policy": "durable_receipt_only_no_notify",
"notification_policy": "read_only_no_notify",
"notify_bridge_calls": 0,
"secrets_policy_status": "只引用既有 Harbor 與 Gitea push secret 名稱password-stdinephemeral askpass 且不輸出、不保存值。",
"secrets_policy_status": "只使用 workflow secret references 進行 Harbor 登入與獨立 audit branch normal push本 snapshot 與 readback 不讀取、保存或顯示任何值。",
"evidence_refs": [
".gitea/workflows/mcp-external-artifact-mirror.yaml",
"config/mcp/playwright-mcp-artifact-policy.json",
"scripts/security/external_mcp_artifact_controller.py",
"scripts/security/verify_external_mcp_artifact_receipt.py"
"scripts/security/verify_external_mcp_artifact_receipt.py",
"scripts/ci/wait-host-web-build-pressure.sh"
],
"next_action": "先完成 audit branch mirror/verifier receipt在 registered public-origin replay adapter 與 rollback receipt 完成前維持 deployment/shadow/canary=false。"
"next_action": "維持 bounded capacity wait、獨立 verifier 與 mcp-artifact-receipts audit branch不得啟動 artifact、寫 RAG、切 production route 或推回 deploy main。"
},
{
"workflow_id": "run_migration",
@@ -429,7 +431,8 @@
"used_by_workflows": [
"awoooi_onboarding_warning_step",
"cd_pipeline",
"harbor_110_local_repair"
"harbor_110_local_repair",
"mcp_external_artifact_mirror"
],
"health_contract": "host-level controlled workflows use the explicit awoooi-non110-host label; this snapshot does not restart or mutate the runner.",
"guardrail_refs": [
@@ -439,7 +442,8 @@
"evidence_refs": [
".gitea/workflows/cd.yaml",
".gitea/workflows/harbor-110-local-repair.yaml",
".gitea/workflows/awoooi-onboarding-warning-step.yaml"
".gitea/workflows/awoooi-onboarding-warning-step.yaml",
".gitea/workflows/mcp-external-artifact-mirror.yaml"
],
"next_action": "維持 explicit non110 host label任何 runner/service 變更另走維護窗口。"
},
@@ -643,6 +647,22 @@
],
"next_action": "後續補 alert/repair receipt本 snapshot 不發通知、不觸發 migration 或 repair。"
},
{
"contract_id": "mcp_artifact_mirror_no_notify",
"display_name": "MCP artifact mirror no-notify",
"status": "preserved",
"policy_kind": "read_only_no_notify",
"success_noise_policy": "artifact mirror 與 verifier 成功只寫獨立 audit branch不向 Telegram 或產品告警群組發送成功訊息。",
"failure_policy": "失敗留在 Gitea workflow 與脫敏 receipt不得因通知失敗而重送 artifact、切 production route 或啟動 MCP。",
"workflow_refs": [
"mcp_external_artifact_mirror"
],
"evidence_refs": [
".gitea/workflows/mcp-external-artifact-mirror.yaml",
"config/mcp/playwright-mcp-artifact-policy.json"
],
"next_action": "維持 no-notify 與獨立 audit branch只在受控營運 readback 顯示 terminal receipt。"
},
{
"contract_id": "lint_and_typecheck_no_notify",
"display_name": "Lint / typecheck no-notify",