Compare commits
11 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 52c752caba | |||
| af1e94d85d | |||
| df35cd0630 | |||
| 04b3a210fe | |||
| 330c25f241 | |||
| 3a23451802 | |||
| 9297398d56 | |||
| b0804e1e6a | |||
| 8216399155 | |||
| a70f078bbb | |||
| a24e61d538 |
@@ -23,7 +23,7 @@ jobs:
|
|||||||
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
||||||
# LLM configuration
|
# LLM configuration
|
||||||
LLM__PROVIDER: CLAUDE
|
LLM__PROVIDER: CLAUDE
|
||||||
LLM__META__MODEL: claude-sonnet-4-20250514
|
LLM__META__MODEL: claude-3-opus
|
||||||
LLM__META__MAX_TOKENS: "4096"
|
LLM__META__MAX_TOKENS: "4096"
|
||||||
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
||||||
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
@@ -36,6 +36,9 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
||||||
|
|
||||||
|
- name: Update submodules to remote
|
||||||
|
run: git submodule update --remote --merge
|
||||||
|
|
||||||
- name: Run inline review
|
- name: Run inline review
|
||||||
uses: docker://nikitafilonov/ai-review:v0.64.0
|
uses: docker://nikitafilonov/ai-review:v0.64.0
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
- name: Install TruffleHog
|
||||||
|
run: |
|
||||||
|
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh \
|
||||||
|
| sh -s -- -b /usr/local/bin
|
||||||
|
- name: Secret Scanning
|
||||||
|
run: trufflehog git file://. --fail --no-update --results=verified,unknown
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
[submodule "shared-prompts"]
|
[submodule "shared-prompts"]
|
||||||
path = shared-prompts
|
path = shared-prompts
|
||||||
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
||||||
|
branch = main
|
||||||
|
|
||||||
|
|||||||
@@ -5,9 +5,9 @@ metadata:
|
|||||||
namespace: argocd
|
namespace: argocd
|
||||||
annotations:
|
annotations:
|
||||||
argocd.argoproj.io/sync-wave: "1"
|
argocd.argoproj.io/sync-wave: "1"
|
||||||
notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
|
# notifications.argoproj.io/subscribe.on-sync-succeeded.slack: ""
|
||||||
notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
|
# notifications.argoproj.io/subscribe.on-sync-failed.slack: ""
|
||||||
notifications.argoproj.io/subscribe.on-degraded.slack: ""
|
# notifications.argoproj.io/subscribe.on-degraded.slack: ""
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: forte-drop
|
app.kubernetes.io/name: forte-drop
|
||||||
app.kubernetes.io/part-of: apps
|
app.kubernetes.io/part-of: apps
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: keycloak-client-forte-drop
|
||||||
|
namespace: forte-drop
|
||||||
|
labels:
|
||||||
|
keycloak.forteapps.net/client-config: "true"
|
||||||
|
annotations:
|
||||||
|
keycloak.forteapps.net/source-namespace: "forte-drop"
|
||||||
|
stringData:
|
||||||
|
client.json: |
|
||||||
|
{
|
||||||
|
"clientId": "forte-drop",
|
||||||
|
"name": "Forte Drop (web)",
|
||||||
|
"enabled": true,
|
||||||
|
"protocol": "openid-connect",
|
||||||
|
"clientAuthenticatorType": "client-secret",
|
||||||
|
"standardFlowEnabled": true,
|
||||||
|
"directAccessGrantsEnabled": false,
|
||||||
|
"serviceAccountsEnabled": false,
|
||||||
|
"publicClient": false,
|
||||||
|
"redirectUris": ["https://drop.forteapps.net/auth/callback"],
|
||||||
|
"webOrigins": ["https://drop.forteapps.net"],
|
||||||
|
"defaultClientScopes": ["openid","email","profile"],
|
||||||
|
"secret": {
|
||||||
|
"namespace": "forte-drop",
|
||||||
|
"name": "forte-drop-oidc-credentials",
|
||||||
|
"keys": {
|
||||||
|
"clientId": "client-id",
|
||||||
|
"clientSecret": "client-secret"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,5 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- forte-drop.yaml
|
- forte-drop.yaml
|
||||||
|
- keycloak-client-forte-drop.yaml
|
||||||
- forte-drop-pdb.yaml
|
- forte-drop-pdb.yaml
|
||||||
- forte-drop-secrets-sealed.yaml
|
- forte-drop-secrets-sealed.yaml
|
||||||
|
|||||||
@@ -24,8 +24,15 @@ spec:
|
|||||||
name: azuredns-config
|
name: azuredns-config
|
||||||
key: client-secret
|
key: client-secret
|
||||||
selector:
|
selector:
|
||||||
dnsNames:
|
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
|
||||||
- '*.forteapps.net'
|
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
|
||||||
|
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
|
||||||
|
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
|
||||||
|
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
|
||||||
|
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
|
||||||
|
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
|
||||||
|
# to match fall through to the http01 solver below.
|
||||||
|
dnsZones:
|
||||||
- 'forteapps.net'
|
- 'forteapps.net'
|
||||||
# HTTP-01 fallback for non-wildcard certificates
|
# HTTP-01 fallback for non-wildcard certificates
|
||||||
- http01:
|
- http01:
|
||||||
@@ -58,8 +65,15 @@ spec:
|
|||||||
name: azuredns-config
|
name: azuredns-config
|
||||||
key: client-secret
|
key: client-secret
|
||||||
selector:
|
selector:
|
||||||
dnsNames:
|
# NOTE: cert-manager solver selectors are NOT TLS-style wildcards. selector.dnsNames
|
||||||
- '*.forteapps.net'
|
# matches by exact FQDN, so '*.forteapps.net' here would match only a cert literally
|
||||||
|
# named '*.forteapps.net' — it would NOT cover 'drop.forteapps.net'. selector.dnsZones
|
||||||
|
# instead suffix-matches the zone apex AND every subdomain at any depth, so this single
|
||||||
|
# entry routes all forteapps.net ACME challenges (forteapps.net, *.forteapps.net,
|
||||||
|
# drop.forteapps.net, *.drop.forteapps.net, mcp.drop.forteapps.net, ...) through this
|
||||||
|
# Azure dns01 solver. Wildcard names require dns01; non-wildcard names that ever fail
|
||||||
|
# to match fall through to the http01 solver below.
|
||||||
|
dnsZones:
|
||||||
- 'forteapps.net'
|
- 'forteapps.net'
|
||||||
# HTTP-01 fallback for non-wildcard certificates
|
# HTTP-01 fallback for non-wildcard certificates
|
||||||
- http01:
|
- http01:
|
||||||
|
|||||||
@@ -233,6 +233,10 @@ spec:
|
|||||||
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
||||||
- name: AUTH_OIDC_SCOPES
|
- name: AUTH_OIDC_SCOPES
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
||||||
|
- name: AUTH_OIDC_COOKIE_DOMAIN
|
||||||
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
|
||||||
|
- name: AUTH_OIDC_ALLOWED_RETURN_HOSTS
|
||||||
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-allowed-return-hosts\" || '' }}"
|
||||||
- name: AUTH_PUBLIC_PATHS
|
- name: AUTH_PUBLIC_PATHS
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
||||||
- name: AUTH_OIDC_COOKIE_SECRET
|
- name: AUTH_OIDC_COOKIE_SECRET
|
||||||
|
|||||||
+2
-2
@@ -1326,7 +1326,7 @@ storage:
|
|||||||
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
||||||
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
||||||
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
||||||
- LLM: Claude Sonnet (`claude-sonnet-4-20250514`)
|
- LLM: Claude Sonnet (`claude-3-opus`)
|
||||||
|
|
||||||
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
||||||
```
|
```
|
||||||
@@ -1344,7 +1344,7 @@ shared-prompts/
|
|||||||
```yaml
|
```yaml
|
||||||
llm:
|
llm:
|
||||||
provider: CLAUDE
|
provider: CLAUDE
|
||||||
model: claude-sonnet-4-20250514
|
model: claude-3-opus
|
||||||
vcs:
|
vcs:
|
||||||
provider: GITEA
|
provider: GITEA
|
||||||
review:
|
review:
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ spec:
|
|||||||
sources:
|
sources:
|
||||||
- repoURL: https://dl.gitea.com/charts
|
- repoURL: https://dl.gitea.com/charts
|
||||||
chart: gitea
|
chart: gitea
|
||||||
targetRevision: "12.5.0"
|
targetRevision: "12.6.0"
|
||||||
helm:
|
helm:
|
||||||
releaseName: gitea
|
releaseName: gitea
|
||||||
valueFiles:
|
valueFiles:
|
||||||
|
|||||||
@@ -59,10 +59,6 @@ config:
|
|||||||
href: https://benken.hackathon.forteapps.net
|
href: https://benken.hackathon.forteapps.net
|
||||||
description: Teknisk kompetanse fra offentlige anbud
|
description: Teknisk kompetanse fra offentlige anbud
|
||||||
icon: forte
|
icon: forte
|
||||||
- Forte Drop:
|
|
||||||
href: https://drop.forteapps.net
|
|
||||||
description: Self-hosted HTML-drops + MCP for Claude
|
|
||||||
icon: forte
|
|
||||||
- Forte Feedback:
|
- Forte Feedback:
|
||||||
href: https://feedback.forteapps.net
|
href: https://feedback.forteapps.net
|
||||||
description: Fortes internal feedback app
|
description: Fortes internal feedback app
|
||||||
|
|||||||
Reference in New Issue
Block a user