convoy: forbidden-pattern gate + AGENTS.md docs (briefs 3+4) #133

Merged
varutasu merged 2 commits from convoy/migrate-ci-followups-briefs-3-4 into main 2026-06-06 01:18:21 -04:00
varutasu commented 2026-06-06 00:49:28 -04:00 (Migrated from github.com)

Summary

Closes out the migrate-ci-to-self-hosted convoy by landing the two defensive follow-ups that Brief 1+2 (#132) intentionally deferred.

Brief 3 — Drift gate (Check 8 in forbidden-patterns)

runs-on: ubuntu-latest outside an explicit allowlist now fails CI. The allowlist starts with .github/workflows/agent-context-drift.yml only (per Decision D4 of the convoy — the weekly cron stays GitHub-hosted so it runs even when axiom is offline). Self-tested locally against the current tree: 0 violations.

Also renames the job header from "Forbidden patterns (7 checks)" → "(8 checks)" and normalizes the older "Check N/6" labels to "N/8" so the in-log group headers stop lying about how many checks are running (the mixed /6 vs /7 was a known cosmetic carried over from the unify-glass-panel-surfaces convoy).

Brief 4 — AGENTS.md updates (§ 6 + § 7)

  • § 6 "CI behavior" — Playwright smoke runtime line updated to cover post-migration cold-cache vs warm-cache ranges (the stale 59s figure was from pre-migration ubuntu-latest).
  • § 6 new top-level bullet "Self-hosted runner pool (migrate-ci-to-self-hosted convoy, 2026-06-05)" — covers which 4 workflows moved, where the runners live (axiom CT 111, org-scoped to stwl-labs), where shared tooling caches are bind-mounted on the CT 111 host, the migrate-job's CT 102 Postgres dependency + per-run DB pattern, and the agent-context-drift.yml allowlist with a pointer to Check 8 as the enforcement.
  • § 7 new bullet "CI runs on the axiom homelab (CT 111)" with:
    1. PAT rotation cadence/opt/appdata/gha-runner/.env, 90-day rotation, sync.sh restart 111 to re-register, where to look in logs if a silent lapse breaks runner registration.
    2. The D5 one-line sed revert path for when axiom is offline mid-PR-storm. macOS sed -i '' form spelled out explicitly so the operator isn't fighting BSD-vs-GNU sed differences at 2am.

Convoy doc

status: queuedshipped, shipped_in enumerates both PRs (#132 + this one), and follow_ups makes the two remaining items (cleanup-stale-ci-runs-cron, seed-visual-baselines-on-linux) machine-greppable for whatever next picks them up.

Test plan

  • All 7 axiom CI jobs green (lint, schema-map-fresh, forbidden-patterns now showing "8/8", migrate, test, gate, rollup)
  • In the forbidden-patterns log: "Check 8/8: No drift back to runs-on: ubuntu-latest" reports OK: no drift to ubuntu-latest outside the allowlist.
  • Playwright smoke + Vercel preview pass (cache should be warm now, expecting ~1-2m vs the 6m10s cold-cache run on #132)

After this lands, the convoy is done. Remaining items move to their own convoys:

  • cleanup-stale-ci-runs-cron (weekly GC for ci_run_* DBs on CT 102 — defensive; the if: always() drop step in ci.yml should already handle happy + failure paths)
  • seed-visual-baselines-on-linux (already queued in .convoys/ship-readiness.md)

Made with Cursor

## Summary Closes out the [`migrate-ci-to-self-hosted`](.convoys/migrate-ci-to-self-hosted.md) convoy by landing the two defensive follow-ups that Brief 1+2 (#132) intentionally deferred. ## Brief 3 — Drift gate (Check 8 in `forbidden-patterns`) `runs-on: ubuntu-latest` outside an explicit allowlist now fails CI. The allowlist starts with `.github/workflows/agent-context-drift.yml` only (per Decision D4 of the convoy — the weekly cron stays GitHub-hosted so it runs even when axiom is offline). Self-tested locally against the current tree: 0 violations. Also renames the job header from "Forbidden patterns (7 checks)" → "(8 checks)" and normalizes the older "Check N/6" labels to "N/8" so the in-log group headers stop lying about how many checks are running (the mixed `/6` vs `/7` was a known cosmetic carried over from the unify-glass-panel-surfaces convoy). ## Brief 4 — `AGENTS.md` updates (§ 6 + § 7) - **§ 6 "CI behavior"** — Playwright smoke runtime line updated to cover post-migration cold-cache vs warm-cache ranges (the stale 59s figure was from pre-migration `ubuntu-latest`). - **§ 6 new top-level bullet** "Self-hosted runner pool (migrate-ci-to-self-hosted convoy, 2026-06-05)" — covers which 4 workflows moved, where the runners live (axiom CT 111, org-scoped to `stwl-labs`), where shared tooling caches are bind-mounted on the CT 111 host, the migrate-job's CT 102 Postgres dependency + per-run DB pattern, and the `agent-context-drift.yml` allowlist with a pointer to Check 8 as the enforcement. - **§ 7 new bullet** "CI runs on the axiom homelab (CT 111)" with: 1. **PAT rotation cadence** — `/opt/appdata/gha-runner/.env`, 90-day rotation, `sync.sh restart 111` to re-register, where to look in logs if a silent lapse breaks runner registration. 2. **The D5 one-line `sed` revert path** for when axiom is offline mid-PR-storm. macOS `sed -i ''` form spelled out explicitly so the operator isn't fighting BSD-vs-GNU sed differences at 2am. ## Convoy doc `status: queued` → `shipped`, `shipped_in` enumerates both PRs (#132 + this one), and `follow_ups` makes the two remaining items (`cleanup-stale-ci-runs-cron`, `seed-visual-baselines-on-linux`) machine-greppable for whatever next picks them up. ## Test plan - [ ] All 7 axiom CI jobs green (lint, schema-map-fresh, **forbidden-patterns now showing "8/8"**, migrate, test, gate, rollup) - [ ] In the forbidden-patterns log: "Check 8/8: No drift back to runs-on: ubuntu-latest" reports `OK: no drift to ubuntu-latest outside the allowlist.` - [ ] Playwright smoke + Vercel preview pass (cache should be warm now, expecting ~1-2m vs the 6m10s cold-cache run on #132) After this lands, the convoy is done. Remaining items move to their own convoys: - `cleanup-stale-ci-runs-cron` (weekly GC for `ci_run_*` DBs on CT 102 — defensive; the `if: always()` drop step in ci.yml should already handle happy + failure paths) - `seed-visual-baselines-on-linux` (already queued in `.convoys/ship-readiness.md`) Made with [Cursor](https://cursor.com)
vercel[bot] commented 2026-06-06 00:49:32 -04:00 (Migrated from github.com)

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tcg-vault Ready Ready Preview, Comment Jun 6, 2026 4:49am

Request Review

[vc]: #8fme4yBLNgTZ7ME5d7mBfVj9+SFFx8Dc0VxznIRbgaI=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ0Y2ctdmF1bHQiLCJwcm9qZWN0SWQiOiJwcmpfRjZXOEVvRkd3Y0g3aWVGcnRvRlNlOXdVVkFhNSIsImluc3BlY3RvclVybCI6Imh0dHBzOi8vdmVyY2VsLmNvbS9yYW5kYWxsLXN0aWxsd2VsbHMtcHJvamVjdHMvdGNnLXZhdWx0L2gyc281UTRmelBwSkZyQktWYjhVUjlrUlBSUmUiLCJwcmV2aWV3VXJsIjoidGNnLXZhdWx0LWdpdC1jb252b3ktbWlncmF0ZS1kNTY1ZjAtcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzLnZlcmNlbC5hcHAiLCJuZXh0Q29tbWl0U3RhdHVzIjoiREVQTE9ZRUQiLCJsaXZlRmVlZGJhY2siOnsicmVzb2x2ZWQiOjAsInVucmVzb2x2ZWQiOjAsInRvdGFsIjowLCJsaW5rIjoidGNnLXZhdWx0LWdpdC1jb252b3ktbWlncmF0ZS1kNTY1ZjAtcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzLnZlcmNlbC5hcHAifSwicm9vdERpcmVjdG9yeSI6bnVsbH1dLCJyZXF1ZXN0UmV2aWV3VXJsIjoiaHR0cHM6Ly92ZXJjZWwuY29tL3ZlcmNlbC1hZ2VudC9yZXF1ZXN0LXJldmlldz9vd25lcj1zdHdsLWxhYnMmcmVwbz10Y2ctdmF1bHQmcHI9MTMzIn0= The latest updates on your projects. Learn more about [Vercel for GitHub](https://vercel.link/github-learn-more). | Project | Deployment | Actions | Updated (UTC) | | :--- | :----- | :------ | :------ | | [tcg-vault](https://vercel.com/randall-stillwells-projects/tcg-vault) | ![Ready](https://vercel.com/static/status/ready.svg) [Ready](https://vercel.com/randall-stillwells-projects/tcg-vault/h2so5Q4fzPpJFrBKVb8UR9kRPRRe) | [Preview](https://tcg-vault-git-convoy-migrate-d565f0-randall-stillwells-projects.vercel.app), [Comment](https://vercel.live/open-feedback/tcg-vault-git-convoy-migrate-d565f0-randall-stillwells-projects.vercel.app?via=pr-comment-feedback-link) | Jun 6, 2026 4:49am | <a href="https://vercel.com/vercel-agent/request-review?owner=stwl-labs&repo=tcg-vault&pr=133" rel="noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://agents-vade-review.vercel.sh/request-review-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://agents-vade-review.vercel.sh/request-review-light.svg"><img src="https://agents-vade-review.vercel.sh/request-review-light.svg" alt="Request Review"></picture></a>
github-actions[bot] commented 2026-06-06 00:49:37 -04:00 (Migrated from github.com)

Pipeline Health

Build + CI gates

Gate Status
Vercel build (Preview) pass
CI: Lint pass
CI: Schema map fresh skipped
Preview smoke pass
Visual diff ⏭ skipped or pending

Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build).

Role reports

Role Status
Reviewer report pending
A11y audit pending
Design system audit pending

See individual comments above for details. This rollup updates automatically.

<!-- pipeline-rollup --> ## Pipeline Health ### Build + CI gates | Gate | Status | | --- | --- | | Vercel build (Preview) | ✅ pass | | CI: Lint | ✅ pass | | CI: Schema map fresh | ❌ skipped | | Preview smoke | ✅ pass | | Visual diff | ⏭ skipped or pending | _Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build)._ ### Role reports | Role | Status | | --- | --- | | Reviewer report | ⏳ pending | | A11y audit | ⏳ pending | | Design system audit | ⏳ pending | See individual comments above for details. This rollup updates automatically.
Sign in to join this conversation.
No description provided.