diff --git a/.gitea/workflows/ai-review.yaml b/.gitea/workflows/ai-review.yaml index 178a0ad..379641e 100644 --- a/.gitea/workflows/ai-review.yaml +++ b/.gitea/workflows/ai-review.yaml @@ -23,7 +23,7 @@ jobs: REVIEW__INLINE_COMMENT_FALLBACK: "false" # LLM configuration LLM__PROVIDER: CLAUDE - LLM__META__MODEL: claude-sonnet-4-20250514 + LLM__META__MODEL: claude-3-opus LLM__META__MAX_TOKENS: "4096" LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }} @@ -36,6 +36,9 @@ jobs: fetch-depth: 0 token: ${{ secrets.AI_REVIEW_TOKEN }} + - name: Update submodules to remote + run: git submodule update --remote --merge + - name: Run inline review uses: docker://nikitafilonov/ai-review:v0.64.0 with: diff --git a/.gitmodules b/.gitmodules index 2e05419..b45d0db 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1,3 +1,5 @@ [submodule "shared-prompts"] path = shared-prompts url = https://git.forteapps.net/Forte/ai-review-prompts.git + branch = main + diff --git a/cluster-resources/letsencrypt-issuer.yaml b/cluster-resources/letsencrypt-issuer.yaml index 8881362..480b193 100644 --- a/cluster-resources/letsencrypt-issuer.yaml +++ b/cluster-resources/letsencrypt-issuer.yaml @@ -24,8 +24,15 @@ spec: name: azuredns-config key: client-secret selector: - dnsNames: - - '*.forteapps.net' + # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames + # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally + # named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones + # instead suffix-matches the zone apex AND every subdomain at any depth, so this single + # entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net, + # drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this + # Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail + # to match fall through to the http01 solver below. + dnsZones: - 'forteapps.net' # HTTP-01 fallback for non-wildcard certificates - http01: @@ -58,8 +65,15 @@ spec: name: azuredns-config key: client-secret selector: - dnsNames: - - '*.forteapps.net' + # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames + # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally + # named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones + # instead suffix-matches the zone apex AND every subdomain at any depth, so this single + # entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net, + # drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this + # Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail + # to match fall through to the http01 solver below. + dnsZones: - 'forteapps.net' # HTTP-01 fallback for non-wildcard certificates - http01: diff --git a/cluster-resources/policies/auth-sidecar-injector.yaml b/cluster-resources/policies/auth-sidecar-injector.yaml index a358bdd..611a365 100644 --- a/cluster-resources/policies/auth-sidecar-injector.yaml +++ b/cluster-resources/policies/auth-sidecar-injector.yaml @@ -233,6 +233,8 @@ spec: value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}" - name: AUTH_OIDC_SCOPES value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}" + - name: AUTH_OIDC_COOKIE_DOMAIN + value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}" - name: AUTH_PUBLIC_PATHS value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}" - name: AUTH_OIDC_COOKIE_SECRET diff --git a/docs/REFERENCE.md b/docs/REFERENCE.md index 97c7c76..a6f05b2 100644 --- a/docs/REFERENCE.md +++ b/docs/REFERENCE.md @@ -1326,7 +1326,7 @@ storage: - Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`) - Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient) - Agent mode: disabled (one-shot review, no multi-turn reasoning) -- LLM: Claude Sonnet (`claude-sonnet-4-20250514`) +- LLM: Claude Sonnet (`claude-3-opus`) **Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`): ``` @@ -1344,7 +1344,7 @@ shared-prompts/ ```yaml llm: provider: CLAUDE - model: claude-sonnet-4-20250514 + model: claude-3-opus vcs: provider: GITEA review: