From 3a23451802b7d5fb1cbd3ca8f2b442e3ec87279c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B8rgen=20Stensrud?= Date: Fri, 26 Jun 2026 11:38:30 +0000 Subject: [PATCH 1/5] feat(forte-drop): issuer dnsZones for *.drop.forteapps.net (subdomain-per-drop) (#22) --- cluster-resources/letsencrypt-issuer.yaml | 22 ++++++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/cluster-resources/letsencrypt-issuer.yaml b/cluster-resources/letsencrypt-issuer.yaml index 8881362..480b193 100644 --- a/cluster-resources/letsencrypt-issuer.yaml +++ b/cluster-resources/letsencrypt-issuer.yaml @@ -24,8 +24,15 @@ spec: name: azuredns-config key: client-secret selector: - dnsNames: - - '*.forteapps.net' + # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames + # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally + # named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones + # instead suffix-matches the zone apex AND every subdomain at any depth, so this single + # entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net, + # drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this + # Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail + # to match fall through to the http01 solver below. + dnsZones: - 'forteapps.net' # HTTP-01 fallback for non-wildcard certificates - http01: @@ -58,8 +65,15 @@ spec: name: azuredns-config key: client-secret selector: - dnsNames: - - '*.forteapps.net' + # NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames + # matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally + # named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones + # instead suffix-matches the zone apex AND every subdomain at any depth, so this single + # entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net, + # drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this + # Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail + # to match fall through to the http01 solver below. + dnsZones: - 'forteapps.net' # HTTP-01 fallback for non-wildcard certificates - http01: From 330c25f241d6b1015d6c0cccf16d12dcdb29cb26 Mon Sep 17 00:00:00 2001 From: Danijel Simeunovic Date: Mon, 29 Jun 2026 16:47:51 +0200 Subject: [PATCH 2/5] model --- .gitea/workflows/ai-review.yaml | 2 +- docs/REFERENCE.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.gitea/workflows/ai-review.yaml b/.gitea/workflows/ai-review.yaml index 178a0ad..1bdae68 100644 --- a/.gitea/workflows/ai-review.yaml +++ b/.gitea/workflows/ai-review.yaml @@ -23,7 +23,7 @@ jobs: REVIEW__INLINE_COMMENT_FALLBACK: "false" # LLM configuration LLM__PROVIDER: CLAUDE - LLM__META__MODEL: claude-sonnet-4-20250514 + LLM__META__MODEL: claude-3-opus LLM__META__MAX_TOKENS: "4096" LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }} diff --git a/docs/REFERENCE.md b/docs/REFERENCE.md index 97c7c76..a6f05b2 100644 --- a/docs/REFERENCE.md +++ b/docs/REFERENCE.md @@ -1326,7 +1326,7 @@ storage: - Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`) - Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient) - Agent mode: disabled (one-shot review, no multi-turn reasoning) -- LLM: Claude Sonnet (`claude-sonnet-4-20250514`) +- LLM: Claude Sonnet (`claude-3-opus`) **Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`): ``` @@ -1344,7 +1344,7 @@ shared-prompts/ ```yaml llm: provider: CLAUDE - model: claude-sonnet-4-20250514 + model: claude-3-opus vcs: provider: GITEA review: From 04b3a210fec8b675710e954e5bda94fd4df2cc07 Mon Sep 17 00:00:00 2001 From: Danijel Simeunovic Date: Mon, 29 Jun 2026 17:02:50 +0200 Subject: [PATCH 3/5] shared-prompts --- .gitmodules | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.gitmodules b/.gitmodules index 2e05419..b45d0db 100644 --- a/.gitmodules +++ b/.gitmodules @@ -1,3 +1,5 @@ [submodule "shared-prompts"] path = shared-prompts url = https://git.forteapps.net/Forte/ai-review-prompts.git + branch = main + From df35cd0630062094f9a702e41fa745b038196cbd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B8rgen=20Stensrud?= Date: Tue, 30 Jun 2026 06:59:37 +0000 Subject: [PATCH 4/5] feat(auth-sidecar): inject AUTH_OIDC_COOKIE_DOMAIN (#24) Adds AUTH_OIDC_COOKIE_DOMAIN to the injected OIDC sidecar, from the `policies.forteapps.io/auth-oidc-cookie-domain` annotation. Empty when unset = host-only = unchanged for every app. Pairs with forte-helm + auth-sidecar#23. Safe to merge anytime (opt-in). --------- Co-authored-by: Danijel Simeunovic Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/24 Reviewed-by: Danijel Simeunovic --- cluster-resources/policies/auth-sidecar-injector.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/cluster-resources/policies/auth-sidecar-injector.yaml b/cluster-resources/policies/auth-sidecar-injector.yaml index a358bdd..611a365 100644 --- a/cluster-resources/policies/auth-sidecar-injector.yaml +++ b/cluster-resources/policies/auth-sidecar-injector.yaml @@ -233,6 +233,8 @@ spec: value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}" - name: AUTH_OIDC_SCOPES value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}" + - name: AUTH_OIDC_COOKIE_DOMAIN + value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}" - name: AUTH_PUBLIC_PATHS value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}" - name: AUTH_OIDC_COOKIE_SECRET From af1e94d85d43e418d8556571bb03fe51f9d36c46 Mon Sep 17 00:00:00 2001 From: Danijel Simeunovic Date: Thu, 2 Jul 2026 12:25:11 +0200 Subject: [PATCH 5/5] review --- .gitea/workflows/ai-review.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.gitea/workflows/ai-review.yaml b/.gitea/workflows/ai-review.yaml index 1bdae68..379641e 100644 --- a/.gitea/workflows/ai-review.yaml +++ b/.gitea/workflows/ai-review.yaml @@ -36,6 +36,9 @@ jobs: fetch-depth: 0 token: ${{ secrets.AI_REVIEW_TOKEN }} + - name: Update submodules to remote + run: git submodule update --remote --merge + - name: Run inline review uses: docker://nikitafilonov/ai-review:v0.64.0 with: