Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 5d866b6348 | |||
| fcf187e903 | |||
| fcd8f99a52 | |||
| 44ae8e0da6 |
@@ -23,7 +23,7 @@ jobs:
|
|||||||
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
REVIEW__INLINE_COMMENT_FALLBACK: "false"
|
||||||
# LLM configuration
|
# LLM configuration
|
||||||
LLM__PROVIDER: CLAUDE
|
LLM__PROVIDER: CLAUDE
|
||||||
LLM__META__MODEL: claude-3-opus
|
LLM__META__MODEL: claude-sonnet-4-20250514
|
||||||
LLM__META__MAX_TOKENS: "4096"
|
LLM__META__MAX_TOKENS: "4096"
|
||||||
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
|
||||||
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
@@ -36,9 +36,6 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
token: ${{ secrets.AI_REVIEW_TOKEN }}
|
||||||
|
|
||||||
- name: Update submodules to remote
|
|
||||||
run: git submodule update --remote --merge
|
|
||||||
|
|
||||||
- name: Run inline review
|
- name: Run inline review
|
||||||
uses: docker://nikitafilonov/ai-review:v0.64.0
|
uses: docker://nikitafilonov/ai-review:v0.64.0
|
||||||
with:
|
with:
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
[submodule "shared-prompts"]
|
[submodule "shared-prompts"]
|
||||||
path = shared-prompts
|
path = shared-prompts
|
||||||
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
url = https://git.forteapps.net/Forte/ai-review-prompts.git
|
||||||
branch = main
|
|
||||||
|
|
||||||
|
|||||||
@@ -77,12 +77,6 @@ spec:
|
|||||||
mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true
|
mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true
|
||||||
echo "backup retention pass complete"
|
echo "backup retention pass complete"
|
||||||
env:
|
env:
|
||||||
# mc writes its config under $MC_CONFIG_DIR; point it at the shared
|
|
||||||
# emptyDir (writable by uid 65532 via fsGroup). Without this it tries
|
|
||||||
# to mkdir /.mc on the read-only-to-nonroot root fs -> "mkdir /.mc:
|
|
||||||
# permission denied" and every run fails before uploading.
|
|
||||||
- name: MC_CONFIG_DIR
|
|
||||||
value: "/work/.mc"
|
|
||||||
- name: S3_ENDPOINT
|
- name: S3_ENDPOINT
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }
|
secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Wildcard routing for per-slug forte drops: <slug>.drop.forteapps.net -> the forte-drop
|
||||||
|
# web pod. The forteapp chart only emits a single exact Host(`drop.forteapps.net`) route
|
||||||
|
# (the apex: admin + /api + public /shared drops), so this ADDITIVE IngressRoute adds the
|
||||||
|
# wildcard. Kept in launchpad (forte-drop-specific) rather than the shared forteapp chart.
|
||||||
|
#
|
||||||
|
# It targets the SAME service the chart's route does — forte-drop-app:3000 — whose
|
||||||
|
# targetPort is the auth sidecar (service.yaml: targetPort = auth.sidecarPort when auth is
|
||||||
|
# on). So wildcard subdomains flow service:3000 -> sidecar -> app, i.e. they are Forte-login
|
||||||
|
# gated exactly like the admin root. A forteOnly drop is therefore never served un-gated.
|
||||||
|
#
|
||||||
|
# priority: 1 (intentionally LOW). Traefik orders routers by rule-length by default, and the
|
||||||
|
# regex string is longer than Host(`mcp.drop.forteapps.net`); without an explicit low
|
||||||
|
# priority this regex would OUTRANK and STEAL mcp.drop.forteapps.net (and the apex) into the
|
||||||
|
# web pod. priority:1 guarantees the exact Host() routers (mcp release, chart apex) always win;
|
||||||
|
# only real per-slug subdomains fall through to here. The app's reserved-slug check
|
||||||
|
# (mcp/www/api/admin/app) is a second line of defence.
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: forte-drop-subdomains
|
||||||
|
namespace: forte-drop
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/name: forte-drop
|
||||||
|
app.kubernetes.io/part-of: apps
|
||||||
|
app.kubernetes.io/managed-by: argocd
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
# Traefik v3 (chart 28.x) HostRegexp takes a Go RE2 pattern. Verify the rendered
|
||||||
|
# router against mcp./www./app./apex/<real-slug> before relying on it in prod.
|
||||||
|
- match: HostRegexp(`^[a-z0-9-]+\.drop\.forteapps\.net$`)
|
||||||
|
kind: Rule
|
||||||
|
priority: 1
|
||||||
|
services:
|
||||||
|
- name: forte-drop-app
|
||||||
|
port: 3000
|
||||||
|
tls:
|
||||||
|
secretName: wildcard-drop-forteapps-net-tls
|
||||||
@@ -5,3 +5,5 @@ resources:
|
|||||||
- keycloak-client-forte-drop.yaml
|
- keycloak-client-forte-drop.yaml
|
||||||
- forte-drop-pdb.yaml
|
- forte-drop-pdb.yaml
|
||||||
- forte-drop-secrets-sealed.yaml
|
- forte-drop-secrets-sealed.yaml
|
||||||
|
- wildcard-drop-tls-certificate.yaml
|
||||||
|
- forte-drop-subdomains-ingressroute.yaml
|
||||||
|
|||||||
@@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
# Wildcard TLS cert for the per-slug drop subdomains: <slug>.drop.forteapps.net.
|
||||||
|
# forte_drop serves forte-login drops on their own subdomain (gated by the auth
|
||||||
|
# sidecar), so each drop needs a valid cert for *.drop.forteapps.net — a name the
|
||||||
|
# existing *.forteapps.net wildcard CANNOT cover (TLS wildcards match one label only).
|
||||||
|
#
|
||||||
|
# Scope: this cert covers ONLY *.drop.forteapps.net. The apex drop.forteapps.net is
|
||||||
|
# NOT included here — it is served by the forteapp chart's own Certificate (secret
|
||||||
|
# forte-drop-tls, dnsNames: [drop.forteapps.net]) and/or the existing *.forteapps.net
|
||||||
|
# wildcard, so adding it here would be redundant.
|
||||||
|
#
|
||||||
|
# Issued DIRECTLY into the forte-drop namespace (not via the chart) so the app's
|
||||||
|
# Traefik IngressRoute — which must reference a TLS secret in its OWN namespace — can
|
||||||
|
# use it without cross-namespace cloning. This is the single issuer of secret
|
||||||
|
# wildcard-drop-forteapps-net-tls; the forte-drop-subdomains IngressRoute references
|
||||||
|
# that secret. The letsencrypt-prod dns01 solver is authorized for this name via its
|
||||||
|
# selector.dnsZones (forteapps.net).
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: wildcard-drop-forteapps-net
|
||||||
|
namespace: forte-drop
|
||||||
|
spec:
|
||||||
|
secretName: wildcard-drop-forteapps-net-tls
|
||||||
|
issuerRef:
|
||||||
|
name: letsencrypt-prod
|
||||||
|
kind: ClusterIssuer
|
||||||
|
dnsNames:
|
||||||
|
- '*.drop.forteapps.net' # per-slug forte drop subdomains
|
||||||
|
duration: 2160h0m0s # 90 days
|
||||||
|
renewBefore: 720h0m0s # renew 30 days before expiry
|
||||||
|
privateKey:
|
||||||
|
algorithm: RSA
|
||||||
|
encoding: PKCS1
|
||||||
|
size: 4096
|
||||||
@@ -233,8 +233,6 @@ spec:
|
|||||||
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
value: "{{ regex_replace_all('https?://[^/]*', request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-callback-path\", '') }}"
|
||||||
- name: AUTH_OIDC_SCOPES
|
- name: AUTH_OIDC_SCOPES
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-scopes\" || 'openid,profile,email' }}"
|
||||||
- name: AUTH_OIDC_COOKIE_DOMAIN
|
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-oidc-cookie-domain\" || '' }}"
|
|
||||||
- name: AUTH_PUBLIC_PATHS
|
- name: AUTH_PUBLIC_PATHS
|
||||||
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
value: "{{ request.object.metadata.annotations.\"policies.forteapps.io/auth-public-paths\" || '/healthz' }}"
|
||||||
- name: AUTH_OIDC_COOKIE_SECRET
|
- name: AUTH_OIDC_COOKIE_SECRET
|
||||||
|
|||||||
+2
-2
@@ -1326,7 +1326,7 @@ storage:
|
|||||||
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
- Shared configuration and prompts live in the `shared-prompts` Git submodule (→ `Forte/ai-review-prompts`)
|
||||||
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
- Review mode: `ONLY_ADDED_WITH_CONTEXT` — reviews only new/changed lines plus surrounding context (token-efficient)
|
||||||
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
- Agent mode: disabled (one-shot review, no multi-turn reasoning)
|
||||||
- LLM: Claude Sonnet (`claude-3-opus`)
|
- LLM: Claude Sonnet (`claude-sonnet-4-20250514`)
|
||||||
|
|
||||||
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
**Shared Prompts Structure** (submodule: `Forte/ai-review-prompts`):
|
||||||
```
|
```
|
||||||
@@ -1344,7 +1344,7 @@ shared-prompts/
|
|||||||
```yaml
|
```yaml
|
||||||
llm:
|
llm:
|
||||||
provider: CLAUDE
|
provider: CLAUDE
|
||||||
model: claude-3-opus
|
model: claude-sonnet-4-20250514
|
||||||
vcs:
|
vcs:
|
||||||
provider: GITEA
|
provider: GITEA
|
||||||
review:
|
review:
|
||||||
|
|||||||
Reference in New Issue
Block a user