Compare commits
13 Commits
fcf187e903
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
| 4712eb4804 | |||
| 2696044a02 | |||
| b0c0074f7f | |||
| 7f4a0bccf1 | |||
| 52c752caba | |||
| af1e94d85d | |||
| df35cd0630 | |||
| 04b3a210fe | |||
| 330c25f241 | |||
| 3a23451802 | |||
| 9297398d56 | |||
| b0804e1e6a | |||
| 8216399155 |
@@ -23,7 +23,7 @@ jobs:
|
|||||||
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
||||||
# LLM configuration
|
# LLM configuration
|
||||||
LLM__PROVIDER: CLAUDE
|
LLM__PROVIDER: CLAUDE
|
||||||
LLM__META__MODEL: claude-sonnet-4-20250514
|
LLM__META__MODEL: claude-3-opus
|
||||||
LLM__META__MAX_TOKENS: "4096"
|
LLM__META__MAX_TOKENS: "4096"
|
||||||
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
||||||
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
@@ -36,6 +36,9 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
||||||
|
|
||||||
|
- name: Update submodules to remote
|
||||||
|
run: git submodule update --remote --merge
|
||||||
|
|
||||||
- name: Run inline review
|
- name: Run inline review
|
||||||
uses: docker://nikitafilonov/ai-review:v0.64.0
|
uses: docker://nikitafilonov/ai-review:v0.64.0
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
- name: Install TruffleHog
|
||||||
|
run: |
|
||||||
|
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \
|
||||||
|
| sh -s -- -b /usr/local/bin
|
||||||
|
- name: Secret Scanning
|
||||||
|
run: trufflehog git file://. --fail --no-update --results=verified,unknown
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
[submodule "shared-prompts"]
|
[submodule "shared-prompts"]
|
||||||
path = shared-prompts
|
path = shared-prompts
|
||||||
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
||||||
|
branch = main
|
||||||
|
|
||||||
|
|||||||
@@ -1,39 +0,0 @@
|
|||||||
# Wildcard routing for per-slug forte drops: <slug>.drop.forteapps.net -> the forte-drop
|
|
||||||
# web pod. The forteapp chart only emits a single exact Host(`drop.forteapps.net`) route
|
|
||||||
# (the apex: admin + /api + public /shared drops), so this ADDITIVE IngressRoute adds the
|
|
||||||
# wildcard. Kept in launchpad (forte-drop-specific) rather than the shared forteapp chart.
|
|
||||||
#
|
|
||||||
# It targets the SAME service the chart's route does — forte-drop-app:3000 — whose
|
|
||||||
# targetPort is the auth sidecar (service.yaml: targetPort = auth.sidecarPort when auth is
|
|
||||||
# on). So wildcard subdomains flow service:3000 -> sidecar -> app, i.e. they are Forte-login
|
|
||||||
# gated exactly like the admin root. A forteOnly drop is therefore never served un-gated.
|
|
||||||
#
|
|
||||||
# priority: 1 (intentionally LOW). Traefik orders routers by rule-length by default, and the
|
|
||||||
# regex string is longer than Host(`mcp.drop.forteapps.net`); without an explicit low
|
|
||||||
# priority this regex would OUTRANK and STEAL mcp.drop.forteapps.net (and the apex) into the
|
|
||||||
# web pod. priority:1 guarantees the exact Host() routers (mcp release, chart apex) always win;
|
|
||||||
# only real per-slug subdomains fall through to here. The app's reserved-slug check
|
|
||||||
# (mcp/www/api/admin/app) is a second line of defence.
|
|
||||||
apiVersion: traefik.io/v1alpha1
|
|
||||||
kind: IngressRoute
|
|
||||||
metadata:
|
|
||||||
name: forte-drop-subdomains
|
|
||||||
namespace: forte-drop
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: forte-drop
|
|
||||||
app.kubernetes.io/part-of: apps
|
|
||||||
app.kubernetes.io/managed-by: argocd
|
|
||||||
spec:
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
routes:
|
|
||||||
# Traefik v3 (chart 28.x) HostRegexp takes a Go RE2 pattern. Verify the rendered
|
|
||||||
# router against mcp./www./app./apex/<real-slug> before relying on it in prod.
|
|
||||||
- match: HostRegexp(`^[a-z0-9-]+\.drop\.forteapps\.net$`)
|
|
||||||
kind: Rule
|
|
||||||
priority: 1
|
|
||||||
services:
|
|
||||||
- name: forte-drop-app
|
|
||||||
port: 3000
|
|
||||||
tls:
|
|
||||||
secretName: wildcard-drop-forteapps-net-tls
|
|
||||||
@@ -1,8 +1,3 @@
|
|||||||
# Labeled config Secret read by the Keycloak Client Registrar. Kyverno clones it
|
|
||||||
# to the keycloak namespace; a CronJob registers the OIDC client in the forte
|
|
||||||
# realm and writes the credentials back as forte-drop-oidc-credentials in THIS
|
|
||||||
# namespace (~2 min). The forte-helm auth sidecar (auth.type: oidc) consumes that
|
|
||||||
# registrar-created Secret automatically — no manual SealedSecret step needed.
|
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Secret
|
kind: Secret
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
@@ -5,5 +5,3 @@ resources:
|
|||||||
- keycloak-client-forte-drop.yaml
|
- keycloak-client-forte-drop.yaml
|
||||||
- forte-drop-pdb.yaml
|
- forte-drop-pdb.yaml
|
||||||
- forte-drop-secrets-sealed.yaml
|
- forte-drop-secrets-sealed.yaml
|
||||||
- wildcard-drop-tls-certificate.yaml
|
|
||||||
- forte-drop-subdomains-ingressroute.yaml
|
|
||||||
|
|||||||
@@ -1,35 +0,0 @@
|
|||||||
---
|
|
||||||
# Wildcard TLS cert for the per-slug drop subdomains: <slug>.drop.forteapps.net.
|
|
||||||
# forte_drop serves forte-login drops on their own subdomain (gated by the auth
|
|
||||||
# sidecar), so each drop needs a valid cert for *.drop.forteapps.net — a name the
|
|
||||||
# existing *.forteapps.net wildcard CANNOT cover (TLS wildcards match one label only).
|
|
||||||
#
|
|
||||||
# Scope: this cert covers ONLY *.drop.forteapps.net. The apex drop.forteapps.net is
|
|
||||||
# NOT included here — it is served by the forteapp chart's own Certificate (secret
|
|
||||||
# forte-drop-tls, dnsNames: [drop.forteapps.net]) and/or the existing *.forteapps.net
|
|
||||||
# wildcard, so adding it here would be redundant.
|
|
||||||
#
|
|
||||||
# Issued DIRECTLY into the forte-drop namespace (not via the chart) so the app's
|
|
||||||
# Traefik IngressRoute — which must reference a TLS secret in its OWN namespace — can
|
|
||||||
# use it without cross-namespace cloning. This is the single issuer of secret
|
|
||||||
# wildcard-drop-forteapps-net-tls; the forte-drop-subdomains IngressRoute references
|
|
||||||
# that secret. The letsencrypt-prod dns01 solver is authorized for this name via its
|
|
||||||
# selector.dnsZones (forteapps.net).
|
|
||||||
apiVersion: cert-manager.io/v1
|
|
||||||
kind: Certificate
|
|
||||||
metadata:
|
|
||||||
name: wildcard-drop-forteapps-net
|
|
||||||
namespace: forte-drop
|
|
||||||
spec:
|
|
||||||
secretName: wildcard-drop-forteapps-net-tls
|
|
||||||
issuerRef:
|
|
||||||
name: letsencrypt-prod
|
|
||||||
kind: ClusterIssuer
|
|
||||||
dnsNames:
|
|
||||||
- '*.drop.forteapps.net' # per-slug forte drop subdomains
|
|
||||||
duration: 2160h0m0s # 90 days
|
|
||||||
renewBefore: 720h0m0s # renew 30 days before expiry
|
|
||||||
privateKey:
|
|
||||||
algorithm: RSA
|
|
||||||
encoding: PKCS1
|
|
||||||
size: 4096
|
|
||||||
@@ -233,6 +233,10 @@ spec:
|
|||||||
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
||||||
- name: AUTH_OIDC_SCOPES
|
- name: AUTH_OIDC_SCOPES
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
||||||
|
- name: AUTH_OIDC_COOKIE_DOMAIN
|
||||||
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
|
||||||
|
- name: AUTH_OIDC_ALLOWED_RETURN_HOSTS
|
||||||
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-allowed-return-hosts\" || '' }}"
|
||||||
- name: AUTH_PUBLIC_PATHS
|
- name: AUTH_PUBLIC_PATHS
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
||||||
- name: AUTH_OIDC_COOKIE_SECRET
|
- name: AUTH_OIDC_COOKIE_SECRET
|
||||||
|
|||||||
+2
-2
@@ -1326,7 +1326,7 @@ storage:
|
|||||||
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
||||||
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
||||||
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
||||||
- LLM: Claude Sonnet (`claude-sonnet-4-20250514`)
|
- LLM: Claude Sonnet (`claude-3-opus`)
|
||||||
|
|
||||||
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
||||||
```
|
```
|
||||||
@@ -1344,7 +1344,7 @@ shared-prompts/
|
|||||||
```yaml
|
```yaml
|
||||||
llm:
|
llm:
|
||||||
provider: CLAUDE
|
provider: CLAUDE
|
||||||
model: claude-sonnet-4-20250514
|
model: claude-3-opus
|
||||||
vcs:
|
vcs:
|
||||||
provider: GITEA
|
provider: GITEA
|
||||||
review:
|
review:
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
# Domain Docs
|
||||||
|
|
||||||
|
How the engineering skills should consume this repo's domain documentation when exploring the codebase.
|
||||||
|
|
||||||
|
## Before exploring, read these
|
||||||
|
|
||||||
|
- **`CONTEXT.md`** at the repo root, or
|
||||||
|
- **`CONTEXT-MAP.md`** at the repo root if it exists — it points at one `CONTEXT.md` per context. Read each one relevant to the topic.
|
||||||
|
- **`docs/adr/`** — read ADRs that touch the area you're about to work in. In multi-context repos, also check `src/<context>/docs/adr/` for context-scoped decisions.
|
||||||
|
|
||||||
|
If any of these files don't exist, **proceed silently**. Don't flag their absence; don't suggest creating them upfront. The `/domain-modeling` skill (reached via `/grill-with-docs` and `/improve-codebase-architecture`) creates them lazily when terms or decisions actually get resolved.
|
||||||
|
|
||||||
|
## File structure
|
||||||
|
|
||||||
|
Single-context repo (most repos):
|
||||||
|
|
||||||
|
```
|
||||||
|
/
|
||||||
|
├── CONTEXT.md
|
||||||
|
├── docs/adr/
|
||||||
|
│ ├── 0001-event-sourced-orders.md
|
||||||
|
│ └── 0002-postgres-for-write-model.md
|
||||||
|
└── src/
|
||||||
|
```
|
||||||
|
|
||||||
|
## Use the glossary's vocabulary
|
||||||
|
|
||||||
|
When your output names a domain concept (in an issue title, a refactor proposal, a hypothesis, a test name), use the term as defined in `CONTEXT.md`. Don't drift to synonyms the glossary explicitly avoids.
|
||||||
|
|
||||||
|
If the concept you need isn't in the glossary yet, that's a signal — either you're inventing language the project doesn't use (reconsider) or there's a real gap (note it for `/domain-modeling`).
|
||||||
|
|
||||||
|
## Flag ADR conflicts
|
||||||
|
|
||||||
|
If your output contradicts an existing ADR, surface it explicitly rather than silently overriding:
|
||||||
|
|
||||||
|
> _Contradicts ADR-0007 (event-sourced orders) — but worth reopening because…_
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Issue tracker: Gitea
|
||||||
|
|
||||||
|
Issues for this repo live in Gitea at `git.forteapps.net/Forte/launchpad`. Use the Gitea API or `tea` CLI.
|
||||||
|
|
||||||
|
## Conventions
|
||||||
|
|
||||||
|
- **Create an issue**: `tea issue create --title "..." --description "..."`
|
||||||
|
or via API: `curl -X POST "https://git.forteapps.net/api/v1/repos/Forte/launchpad/issues" -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" -d '{"title":"...","body":"..."}'`
|
||||||
|
- **Read an issue**: `tea issue view <number>` or API `GET /api/v1/repos/Forte/launchpad/issues/<number>`
|
||||||
|
- **List issues**: `tea issue list` or API `GET /api/v1/repos/Forte/launchpad/issues?state=open`
|
||||||
|
- **Comment on an issue**: `tea issue comment <number> "..."` or API `POST /api/v1/repos/Forte/launchpad/issues/<number>/comments`
|
||||||
|
- **Apply labels**: API `POST /api/v1/repos/Forte/launchpad/issues/<number>/labels` with `{"labels": [<label_id>]}`
|
||||||
|
- **Close**: API `PATCH /api/v1/repos/Forte/launchpad/issues/<number>` with `{"state": "closed"}`
|
||||||
|
|
||||||
|
Infer the repo from `git remote -v`.
|
||||||
|
|
||||||
|
## Pull requests as a triage surface
|
||||||
|
|
||||||
|
**PRs as a request surface: no.**
|
||||||
|
|
||||||
|
## When a skill says "publish to the issue tracker"
|
||||||
|
|
||||||
|
Create a Gitea issue.
|
||||||
|
|
||||||
|
## When a skill says "fetch the relevant ticket"
|
||||||
|
|
||||||
|
Fetch the issue via API or `tea issue view <number>`.
|
||||||
|
|
||||||
|
## Wayfinding operations
|
||||||
|
|
||||||
|
Used by `/wayfinder`. The **map** is a single issue with **child** issues as tickets.
|
||||||
|
|
||||||
|
- **Map**: a single issue labelled `wayfinder:map`, holding the Destination / Notes / Decisions-so-far / Fog body.
|
||||||
|
- Create: `POST /api/v1/repos/Forte/launchpad/issues` with `{"title":"...","body":"...","labels":[<wayfinder:map label id>]}`
|
||||||
|
- **Child ticket**: an issue carrying `Part of #<map>` at the top of its body and a `wayfinder:<type>` label (`research`/`prototype`/`grilling`/`task`). Once claimed, the ticket is assigned to the driving dev.
|
||||||
|
- **Blocking**: Gitea does not have native issue dependencies. Fall back to a `Blocked by: #<n>, #<n>` line at the top of the child body. A ticket is unblocked when every issue it lists is closed.
|
||||||
|
- **Frontier query**: list the map's open children — `GET /api/v1/repos/Forte/launchpad/issues?state=open&labels=wayfinder:research,wayfinder:prototype,wayfinder:grilling,wayfinder:task` — then filter to those whose body starts with `Part of #<map>`. Drop any with an open issue in their `Blocked by` line, or with an assignee. First in map order wins.
|
||||||
|
- **Claim**: `PATCH /api/v1/repos/Forte/launchpad/issues/<n>` with `{"assignees":["<username>"]}` — the session's first write.
|
||||||
|
- **Resolve**: post the answer as a comment (`POST .../comments`), close the issue (`PATCH` with `{"state":"closed"}`), then append a context pointer (gist + link) to the map's Decisions-so-far by editing the map issue body.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
# Triage Labels
|
||||||
|
|
||||||
|
The skills speak in terms of five canonical triage roles. This file maps those roles to the actual label strings used in this repo's issue tracker.
|
||||||
|
|
||||||
|
| Label in mattpocock/skills | Label in our tracker | Meaning |
|
||||||
|
| -------------------------- | -------------------- | ---------------------------------------- |
|
||||||
|
| `needs-triage` | `needs-triage` | Maintainer needs to evaluate this issue |
|
||||||
|
| `needs-info` | `needs-info` | Waiting on reporter for more information |
|
||||||
|
| `ready-for-agent` | `ready-for-agent` | Fully specified, ready for an AFK agent |
|
||||||
|
| `ready-for-human` | `ready-for-human` | Requires human implementation |
|
||||||
|
| `wontfix` | `wontfix` | Will not be actioned |
|
||||||
|
|
||||||
|
When a skill mentions a role (e.g. "apply the AFK-ready triage label"), use the corresponding label string from this table.
|
||||||
|
|
||||||
|
Edit the right-hand column to match whatever vocabulary you actually use.
|
||||||
@@ -17,7 +17,7 @@ spec:
|
|||||||
sources:
|
sources:
|
||||||
- repoURL: https://dl.gitea.com/charts
|
- repoURL: https://dl.gitea.com/charts
|
||||||
chart: gitea
|
chart: gitea
|
||||||
targetRevision: "12.5.0"
|
targetRevision: "12.6.0"
|
||||||
helm:
|
helm:
|
||||||
releaseName: gitea
|
releaseName: gitea
|
||||||
valueFiles:
|
valueFiles:
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ gitea:
|
|||||||
ENABLE_PASSWORD_SIGNIN_FORM: false
|
ENABLE_PASSWORD_SIGNIN_FORM: false
|
||||||
AUTO_WATCH_ON_CHANGES: false
|
AUTO_WATCH_ON_CHANGES: false
|
||||||
AUTO_WATCH_NEW_REPOS: false
|
AUTO_WATCH_NEW_REPOS: false
|
||||||
ENABLE_NOTIFY_MAIL: false
|
ENABLE_NOTIFY_MAIL: true
|
||||||
ENABLE_TIMETRACKING: false
|
ENABLE_TIMETRACKING: false
|
||||||
|
|
||||||
openid:
|
openid:
|
||||||
|
|||||||
Reference in New Issue
Block a user