Raise nightly agentic budget $20 -> $120 for full per-night coverage
First-run data (2026-06-17) showed the $20 ceiling covered only the canary + 5 of ~22 scannable repos before pausing the rotation, leaving 16 repos un-deep-scanned that night. Raise TOTAL_BUDGET_USD default to $120 so every repo gets a deep agentic pass each night (~22 x ~$5 + canary, with headroom). Spend draws on the Max subscription pool; the per-target cap ($12) and round-robin rotation are unchanged, so this is a ceiling raise, not a per-repo cost change. Updates README, DEPLOY, and the systemd Environment example to match.
This commit is contained in:
parent
15a16f8b88
commit
dbe2f8c186
4 changed files with 7 additions and 5 deletions
|
|
@ -101,7 +101,7 @@ ALARM-only (a clean night posts nothing). Secret-shaped values are redacted from
|
|||
under `~/sweep-reports/<UTC-date>/` are mode 600.
|
||||
|
||||
### Config (env / systemd `Environment=`)
|
||||
`GH_ORG` (Sea-Haven-Industries) · `MIRROR_DIR` (~/repo-mirrors) · `TOTAL_BUDGET_USD` (20) ·
|
||||
`GH_ORG` (Sea-Haven-Industries) · `MIRROR_DIR` (~/repo-mirrors) · `TOTAL_BUDGET_USD` (120) ·
|
||||
`PER_TARGET_BUDGET_USD` (12) · `CANARY_FLOOR` (10) · `MAX_CYCLE_NIGHTS` (4) · `MAX_AGENTIC_PER_NIGHT`
|
||||
(0 = unlimited) · `CENTRAL_SKIP_FILE` (~/.secrev-skip.txt) · `ENABLE_XMODEL_HOOK` (0) ·
|
||||
`TARGETS` (manual override — scan explicit paths, no discovery).
|
||||
|
|
|
|||
|
|
@ -93,7 +93,7 @@ It is **ALARM-only**: a clean night posts nothing. See memory `feedback_cloudwat
|
|||
- **Canary check:** the testbed MUST block AND surface ≥ `CANARY_FLOOR` (default 10) confirmed crit/high.
|
||||
Otherwise → COMPLACENCY ALARM. The corpus now includes Node + .NET fixtures (see the testbed key);
|
||||
re-tune the floor after the first VM canary run reports the expanded recall number.
|
||||
- **Budget ceiling:** `TOTAL_BUDGET_USD` (default 20) caps aggregate agentic spend; `PER_TARGET_BUDGET_USD`
|
||||
- **Budget ceiling:** `TOTAL_BUDGET_USD` (default 120 — full deep-pass coverage of every repo per night) caps aggregate agentic spend; `PER_TARGET_BUDGET_USD`
|
||||
(default 12) caps each repo; `MAX_AGENTIC_PER_NIGHT` (default 0 = unlimited) optionally caps wall-clock.
|
||||
With the SDK-billing split deferred (memory `reference-claude-subscription-billing`), spend draws from
|
||||
the Max subscription limits, so the two-tier design keeps full coverage cheap and bounds the agentic draw.
|
||||
|
|
|
|||
|
|
@ -39,7 +39,9 @@
|
|||
# TARGETS space-separated paths to scan INSTEAD of discovery (manual override)
|
||||
# TESTBED canary corpus dir (default: ~/security-review-testbed)
|
||||
# CANARY_FLOOR min confirmed crit+high the canary MUST surface (default: 10)
|
||||
# TOTAL_BUDGET_USD hard agentic spend ceiling across the night (default: 20)
|
||||
# TOTAL_BUDGET_USD hard agentic spend ceiling across the night (default: 120 —
|
||||
# full deep-pass coverage of every repo per night; first-run
|
||||
# data 2026-06-17 showed $20 covered only canary + 5 repos)
|
||||
# PER_TARGET_BUDGET_USD passed to run_headless --total-budget-usd (default: 12)
|
||||
# MAX_CYCLE_NIGHTS alarm if the agentic rotation hasn't covered every repo in this many nights (default: 4)
|
||||
# MAX_AGENTIC_PER_NIGHT cap on repos given the deep agentic pass per night, for wall-clock bounding
|
||||
|
|
@ -68,7 +70,7 @@ MIRROR_DIR="${MIRROR_DIR:-$HOME/repo-mirrors}"
|
|||
CENTRAL_SKIP_FILE="${CENTRAL_SKIP_FILE:-$HOME/.secrev-skip.txt}"
|
||||
TESTBED="${TESTBED:-$HOME/security-review-testbed}"
|
||||
CANARY_FLOOR="${CANARY_FLOOR:-14}"
|
||||
TOTAL_BUDGET_USD="${TOTAL_BUDGET_USD:-20}"
|
||||
TOTAL_BUDGET_USD="${TOTAL_BUDGET_USD:-120}"
|
||||
PER_TARGET_BUDGET_USD="${PER_TARGET_BUDGET_USD:-12}"
|
||||
MAX_CYCLE_NIGHTS="${MAX_CYCLE_NIGHTS:-6}"
|
||||
MAX_AGENTIC_PER_NIGHT="${MAX_AGENTIC_PER_NIGHT:-0}"
|
||||
|
|
|
|||
|
|
@ -31,7 +31,7 @@ WorkingDirectory=/home/adam/orchestrator
|
|||
EnvironmentFile=-/home/adam/secrev.env
|
||||
EnvironmentFile=-/home/adam/orchestrator/.env
|
||||
# Tune ceilings/targets here without editing the script (uncomment to override defaults):
|
||||
# Environment=TOTAL_BUDGET_USD=20
|
||||
# Environment=TOTAL_BUDGET_USD=120
|
||||
# Environment=PER_TARGET_BUDGET_USD=12
|
||||
# Environment=CANARY_FLOOR=10
|
||||
# Environment=MAX_CYCLE_NIGHTS=4
|
||||
|
|
|
|||
Reference in a new issue