feat(agent-team): P3-live CI apply/verify hardening + ci_fetcher (gate-passed, provisioning-gated) #17
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#17
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/agent-team-p3-live"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
P3-live — hardened CI apply/verify trust boundary (Decision 1: GitHub App token, ZERO AWS, no OIDC)
Brings the §3.3.2 CI apply/verify surface to gate-passed, ready-to-flip. Everything privileged stays inert until provisioning — the actual go-live flip is a provisioning action (the GitHub App +
agent-applyenvironment + branch protection don't exist yet; flipping against a non-existent environment would be an unprotected hole).What's in here
ci_fetcher.py— read-only, fail-closed CI-result fetcher (GitHub Actions run conclusion via a read-only PAT). Validatesrun_id/owner/repo/fetched_id, conclusion-allowlists, fails closed on any error. Data-fetcher only —ci_gateowns the verdict.agent-team-apply-verify.yml): GitHub App token model (OIDC/id-token/AWS removed);task_idenv-indirection (CWE-94);download-artifactrun-id pinning; NUL-delimited post-build denied-path check; empty-hash fail-closed (fixed a real''==''pass bug); three trust-control denylists unified + drift-guard test.gated_build_verify_wiring()(NOT in the defaultrun-team.pypath).build(security-review)— prune.claudeworktrees from the deterministic scanners + gitignore (unblocks main-tree pushes during parallel agent work).Gates (both passed)
/sh-security-review(high-recall fan-out + proof-or-kill verifier) → PASS. The candidate high "SSRF via run_id" was refuted (run_id never populated from untrusted input; seam inert) but hardened anyway; 2 confirmed lows fixed.⚠️ Provisioning prerequisites (flip happens THEN, not in this PR)
The app-token mint + draft-PR steps remain
if: ${{ false }};pull-requests: write+environment: agent-applyare commented. To go live (provisioning runbook):pull-requests: writeonly), install on target repo(s); storeAGENT_APPLY_APP_ID/AGENT_APPLY_APP_PRIVATE_KEYsecrets.agent-applyGitHub Environment with a required reviewer; add branch protection on target repos.pull-requests: write+environment:; flip bothif: ${{ false }}→always() && needs.guard.result=='success' && needs.build-test.result=='success'.Rollback: revert the uncomment/flip (single commit) → workflow returns fully inert; remove the GitHub App install + environment. Nothing is live to roll back until step 4.
Unblocks
Step 5 (Plane-1 fixer) reuses this exact GitHub App surface.