fix(agent-team): dispatch via GitHub App so P3 reaches CI (run_id resolves) #63
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#63
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fix/agent-team-dispatch-run-id"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The agent-team P3 pipeline parked every task at
verify—dispatch_nodeproduced norun_id("dispatch unresolved"). Root cause: the dispatcher's default seams shell out togh(not installed on the R720 box) with a read-only PAT lacking Actions scope. A second, upstream gap:dispatch_noderequiredplan["scope"], which the planner never emits (onlysummary+phases), so auto-dispatch parked on "empty declared_scope" before ever dispatching.Fix
agent_team/github_app.py, new): the box mints short-lived (~1h) installation tokens from the App private key (RS256 App JWT →/access_tokens), cached + re-minted near expiry. Secret-safe: the JWT/token are never logged, never in an exception message, never persisted.dispatcher.py, additive — gh_default_*untouched):app_branch_pusher/app_workflow_dispatcher/app_run_locator. Push auth rides a host-scopedhttp.extraHeaderviaGIT_CONFIG_*env (token never in argv), using Basic auth (x-access-token) — git smart-HTTP rejects Bearer. REST locator mapsid→databaseId/created_at→createdAtinto the pureselect_run_id.coordinator.py):default_dispatch_node_factorybinds the App seams whenAGENT_TEAM_GH_APP_ID/_INSTALLATION_ID/_PRIVATE_KEYare all set; partial/unreadable → one warning + gh-default fallback, never crashes serve.nodes/dispatch_invoker.py): when no plan/operator scope is set, derivedeclared_scopefrom the candidate diff's touched paths (ci_gate.diff_touched_paths). CI's denylist +..-escape + hash-binding + theagent-applyrequired reviewer remain the independent gates.DEPLOY-R720.md(App config, key at~/.ssh, permission/scope, env-precedence, rotation/incident-response) + README.Validation
/sh-plan-review(GPT-4.1),/sh-security-review(high-recall fan-out + proof-or-kill verifier — no confirmed crit/high; 2 hardening fixes applied),/code-review(findings applied), focused security review of the scope delta (no regression).agent-team-apply-verifyrun went green (materialize, guard incl. diff-derived scope, build-test, pure-code gate, App-token mint, draft PR opened) — then cleaned up.Deploy-then-merge: already deployed + box-verified.
Conscious, mitigated deviation from the dispatcher's old "operator host only" note: the box now holds a write-capable App key (scoped to one repo, Contents+Actions only, short-lived tokens, key mode 600). Follow-up: dedicated least-privilege App.