chore(ci): fix sandbox agent smoke image handoff and retries - #106811
Conversation
|
😎 Merged successfully - details. |
🤖 CI report🚨 Trunk lane — universal laneThis PR is assigned to the universal lane. It cannot merge in parallel with other PRs, so it can take longer to merge. Ask dev-ex if you think this is wrong. ✅ Duplication (Python) — cleanNew Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying. ✅ Duplication (TypeScript) — cleanNew TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying. |
|
✅ Security review complete — 2 findings posted as a review, in 19 min. Add the |
|
[High risk] Changes CI workflows and build infrastructure for sandbox agent. The PR should not merge until digest resolution handles builds carried forward during partial reruns. Reviews (1) · Last reviewed commit: "chore(ci): fix sandbox agent smoke image..." |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: PostHog/posthog/.coderabbit.yaml Review profile: QUIET Plan: Enterprise Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review. 📝 WalkthroughWalkthroughThe wait-for-check action now outputs the details URL for the selected completed check. The base-image workflow records pull-request build metadata and checks platform-specific image digests. The agent-version workflow validates the related build artifact and passes its digest-pinned image to the gateway smoke check. New tests cover check outputs, artifact validation, platform digests, and workflow planning. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The image handoff is consistent in the covered rerun scenarios. No actionable merge-blocking issue is established beyond normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new digest handoff adds a release-control dependency, but the inspected path checks the build’s identity and stops before approval when validation or smoke testing fails. An existing PR still does not appear to resume candidate validation on manual dispatch, despite that being a stated goal; this change does not establish a new approval bypass. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ❌ 1❌ Failed checks (1 warning)
Full details: Description checkExplanation The description clearly explains the problem, user-visible changes, and CI flow before and after the change. It omits the required testing details, release-status selection, automatic-notification and docs-update entries, and agent context, including agent-authorship and validation information. Resolution Add the missing template sections. Document the automated tests that were run and their regression coverage, select exactly one release-status option, state the changelog and docs-update decisions, and complete the Agent context section or remove it if no agent contributed.
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Problem
Automated sandbox agent releases stop before gateway validation, as in #106779.
The failed run requests the PR head tag, but the image build publishes the merge-commit tag. Retrying an existing PR skips candidate validation.
Changes
Before
flowchart LR B[Build and smoke merge-SHA image] --> C[Successful PR-head check] C --> P[Pull head-SHA image] --> F[Missing image] R[Retry existing PR] --> S[Skip candidate smoke] classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff; classDef phRed fill:#f54e00,stroke:#f54e00,color:#fff; class B,C,P,R phBlue; class F,S phRed;After
flowchart LR R[New bump or manual retry] --> V[Validate pin-only PR] V --> B[Successful build attempt] --> D[Image digest] D --> G[Gateway smoke and version check] --> A[Approval guard] classDef phBlue fill:#1d4aff,stroke:#1d4aff,color:#fff; classDef phGray fill:#e5e7eb,stroke:#c7ccd1,color:#000; classDef phYellow fill:#f9bd2b,stroke:#f9bd2b,color:#000; class R,V,B,G phBlue; class D phGray; class A phYellow;