From dbe2f8c186d55e1289029fc154270c3c2e40d5cb Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 13:18:46 -0400 Subject: [PATCH] Raise nightly agentic budget $20 -> $120 for full per-night coverage First-run data (2026-06-17) showed the $20 ceiling covered only the canary + 5 of ~22 scannable repos before pausing the rotation, leaving 16 repos un-deep-scanned that night. Raise TOTAL_BUDGET_USD default to $120 so every repo gets a deep agentic pass each night (~22 x ~$5 + canary, with headroom). Spend draws on the Max subscription pool; the per-target cap ($12) and round-robin rotation are unchanged, so this is a ceiling raise, not a per-repo cost change. Updates README, DEPLOY, and the systemd Environment example to match. --- security-review/DEPLOY-R720.md | 2 +- security-review/README.md | 2 +- security-review/nightly_sweep.sh | 6 ++++-- security-review/systemd/sea-haven-secrev.service | 2 +- 4 files changed, 7 insertions(+), 5 deletions(-) diff --git a/security-review/DEPLOY-R720.md b/security-review/DEPLOY-R720.md index 4f1259b..0788685 100644 --- a/security-review/DEPLOY-R720.md +++ b/security-review/DEPLOY-R720.md @@ -101,7 +101,7 @@ ALARM-only (a clean night posts nothing). Secret-shaped values are redacted from under `~/sweep-reports//` are mode 600. ### Config (env / systemd `Environment=`) -`GH_ORG` (Sea-Haven-Industries) · `MIRROR_DIR` (~/repo-mirrors) · `TOTAL_BUDGET_USD` (20) · +`GH_ORG` (Sea-Haven-Industries) · `MIRROR_DIR` (~/repo-mirrors) · `TOTAL_BUDGET_USD` (120) · `PER_TARGET_BUDGET_USD` (12) · `CANARY_FLOOR` (10) · `MAX_CYCLE_NIGHTS` (4) · `MAX_AGENTIC_PER_NIGHT` (0 = unlimited) · `CENTRAL_SKIP_FILE` (~/.secrev-skip.txt) · `ENABLE_XMODEL_HOOK` (0) · `TARGETS` (manual override — scan explicit paths, no discovery). diff --git a/security-review/README.md b/security-review/README.md index c4cc214..f68f625 100644 --- a/security-review/README.md +++ b/security-review/README.md @@ -93,7 +93,7 @@ It is **ALARM-only**: a clean night posts nothing. See memory `feedback_cloudwat - **Canary check:** the testbed MUST block AND surface ≥ `CANARY_FLOOR` (default 10) confirmed crit/high. Otherwise → COMPLACENCY ALARM. The corpus now includes Node + .NET fixtures (see the testbed key); re-tune the floor after the first VM canary run reports the expanded recall number. -- **Budget ceiling:** `TOTAL_BUDGET_USD` (default 20) caps aggregate agentic spend; `PER_TARGET_BUDGET_USD` +- **Budget ceiling:** `TOTAL_BUDGET_USD` (default 120 — full deep-pass coverage of every repo per night) caps aggregate agentic spend; `PER_TARGET_BUDGET_USD` (default 12) caps each repo; `MAX_AGENTIC_PER_NIGHT` (default 0 = unlimited) optionally caps wall-clock. With the SDK-billing split deferred (memory `reference-claude-subscription-billing`), spend draws from the Max subscription limits, so the two-tier design keeps full coverage cheap and bounds the agentic draw. diff --git a/security-review/nightly_sweep.sh b/security-review/nightly_sweep.sh index cab297a..5a4634d 100755 --- a/security-review/nightly_sweep.sh +++ b/security-review/nightly_sweep.sh @@ -39,7 +39,9 @@ # TARGETS space-separated paths to scan INSTEAD of discovery (manual override) # TESTBED canary corpus dir (default: ~/security-review-testbed) # CANARY_FLOOR min confirmed crit+high the canary MUST surface (default: 10) -# TOTAL_BUDGET_USD hard agentic spend ceiling across the night (default: 20) +# TOTAL_BUDGET_USD hard agentic spend ceiling across the night (default: 120 — +# full deep-pass coverage of every repo per night; first-run +# data 2026-06-17 showed $20 covered only canary + 5 repos) # PER_TARGET_BUDGET_USD passed to run_headless --total-budget-usd (default: 12) # MAX_CYCLE_NIGHTS alarm if the agentic rotation hasn't covered every repo in this many nights (default: 4) # MAX_AGENTIC_PER_NIGHT cap on repos given the deep agentic pass per night, for wall-clock bounding @@ -68,7 +70,7 @@ MIRROR_DIR="${MIRROR_DIR:-$HOME/repo-mirrors}" CENTRAL_SKIP_FILE="${CENTRAL_SKIP_FILE:-$HOME/.secrev-skip.txt}" TESTBED="${TESTBED:-$HOME/security-review-testbed}" CANARY_FLOOR="${CANARY_FLOOR:-14}" -TOTAL_BUDGET_USD="${TOTAL_BUDGET_USD:-20}" +TOTAL_BUDGET_USD="${TOTAL_BUDGET_USD:-120}" PER_TARGET_BUDGET_USD="${PER_TARGET_BUDGET_USD:-12}" MAX_CYCLE_NIGHTS="${MAX_CYCLE_NIGHTS:-6}" MAX_AGENTIC_PER_NIGHT="${MAX_AGENTIC_PER_NIGHT:-0}" diff --git a/security-review/systemd/sea-haven-secrev.service b/security-review/systemd/sea-haven-secrev.service index 3e40fb0..cb53527 100644 --- a/security-review/systemd/sea-haven-secrev.service +++ b/security-review/systemd/sea-haven-secrev.service @@ -31,7 +31,7 @@ WorkingDirectory=/home/adam/orchestrator EnvironmentFile=-/home/adam/secrev.env EnvironmentFile=-/home/adam/orchestrator/.env # Tune ceilings/targets here without editing the script (uncomment to override defaults): -# Environment=TOTAL_BUDGET_USD=20 +# Environment=TOTAL_BUDGET_USD=120 # Environment=PER_TARGET_BUDGET_USD=12 # Environment=CANARY_FLOOR=10 # Environment=MAX_CYCLE_NIGHTS=4