Compare commits
10 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ff2b8fc0f5 | |||
| af1e94d85d | |||
| df35cd0630 | |||
| 04b3a210fe | |||
| 330c25f241 | |||
| 3a23451802 | |||
| df30877b5e | |||
| 9297398d56 | |||
| b0804e1e6a | |||
| 8216399155 |
@@ -23,7 +23,7 @@ jobs:
|
||||
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
||||
# LLM configuration
|
||||
LLM__PROVIDER: CLAUDE
|
||||
LLM__META__MODEL: claude-sonnet-4-20250514
|
||||
LLM__META__MODEL: claude-3-opus
|
||||
LLM__META__MAX_TOKENS: "4096"
|
||||
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
||||
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||
@@ -36,6 +36,9 @@ jobs:
|
||||
fetch-depth: 0
|
||||
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
||||
|
||||
- name: Update submodules to remote
|
||||
run: git submodule update --remote --merge
|
||||
|
||||
- name: Run inline review
|
||||
uses: docker://nikitafilonov/ai-review:v0.64.0
|
||||
with:
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: Install TruffleHog
|
||||
run: |
|
||||
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \
|
||||
| sh -s -- -b /usr/local/bin
|
||||
- name: Secret Scanning
|
||||
run: trufflehog git file://. --fail --no-update --results=verified,unknown
|
||||
@@ -1,3 +1,5 @@
|
||||
[submodule "shared-prompts"]
|
||||
path = shared-prompts
|
||||
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
||||
branch = main
|
||||
|
||||
|
||||
@@ -77,6 +77,12 @@ spec:
|
||||
mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true
|
||||
echo "backup retention pass complete"
|
||||
env:
|
||||
# mc writes its config under $MC_CONFIG_DIR; point it at the shared
|
||||
# emptyDir (writable by uid 65532 via fsGroup). Without this it tries
|
||||
# to mkdir /.mc on the read-only-to-nonroot root fs -> "mkdir /.mc:
|
||||
# permission denied" and every run fails before uploading.
|
||||
- name: MC_CONFIG_DIR
|
||||
value: "/work/.mc"
|
||||
- name: S3_ENDPOINT
|
||||
valueFrom:
|
||||
secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }
|
||||
|
||||
@@ -1,8 +1,3 @@
|
||||
# Labeled config Secret read by the Keycloak Client Registrar. Kyverno clones it
|
||||
# to the keycloak namespace; a CronJob registers the OIDC client in the forte
|
||||
# realm and writes the credentials back as forte-drop-oidc-credentials in THIS
|
||||
# namespace (~2 min). The forte-helm auth sidecar (auth.type: oidc) consumes that
|
||||
# registrar-created Secret automatically — no manual SealedSecret step needed.
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
|
||||
@@ -24,8 +24,15 @@ spec:
|
||||
name: azuredns-config
|
||||
key: client-secret
|
||||
selector:
|
||||
dnsNames:
|
||||
- '*.forteapps.net'
|
||||
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
|
||||
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
|
||||
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
|
||||
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
|
||||
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
|
||||
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
|
||||
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
|
||||
# to match fall through to the http01 solver below.
|
||||
dnsZones:
|
||||
- 'forteapps.net'
|
||||
# HTTP-01 fallback for non-wildcard certificates
|
||||
- http01:
|
||||
@@ -58,8 +65,15 @@ spec:
|
||||
name: azuredns-config
|
||||
key: client-secret
|
||||
selector:
|
||||
dnsNames:
|
||||
- '*.forteapps.net'
|
||||
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
|
||||
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
|
||||
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
|
||||
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
|
||||
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
|
||||
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
|
||||
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
|
||||
# to match fall through to the http01 solver below.
|
||||
dnsZones:
|
||||
- 'forteapps.net'
|
||||
# HTTP-01 fallback for non-wildcard certificates
|
||||
- http01:
|
||||
|
||||
@@ -233,6 +233,8 @@ spec:
|
||||
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
||||
- name: AUTH_OIDC_SCOPES
|
||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
||||
- name: AUTH_OIDC_COOKIE_DOMAIN
|
||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
|
||||
- name: AUTH_PUBLIC_PATHS
|
||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
||||
- name: AUTH_OIDC_COOKIE_SECRET
|
||||
|
||||
+2
-2
@@ -1326,7 +1326,7 @@ storage:
|
||||
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
||||
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
||||
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
||||
- LLM: Claude Sonnet (`claude-sonnet-4-20250514`)
|
||||
- LLM: Claude Sonnet (`claude-3-opus`)
|
||||
|
||||
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
||||
```
|
||||
@@ -1344,7 +1344,7 @@ shared-prompts/
|
||||
```yaml
|
||||
llm:
|
||||
provider: CLAUDE
|
||||
model: claude-sonnet-4-20250514
|
||||
model: claude-3-opus
|
||||
vcs:
|
||||
provider: GITEA
|
||||
review:
|
||||
|
||||
@@ -17,7 +17,7 @@ spec:
|
||||
sources:
|
||||
- repoURL: https://dl.gitea.com/charts
|
||||
chart: gitea
|
||||
targetRevision: "12.5.0"
|
||||
targetRevision: "12.6.0"
|
||||
helm:
|
||||
releaseName: gitea
|
||||
valueFiles:
|
||||
|
||||
Reference in New Issue
Block a user