Make automated deploy fixes fail closed - #34
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
always()-guarded evidence jobWhy
PR 376 in HLS was opened after a transient Railway 503, but its failure-evidence
job was skipped and the repair agent continued with an empty evidence directory.
It then proposed an unrelated application change. The repair workflow must stop
when it cannot prove what failed, while provider adapters should absorb bounded
transient read failures without replaying deployment mutations.
Impact
Generated Railway and Cloud Run deploy workflows will reliably upload failure
evidence. Automated repair workflows will only run with their declared evidence,
will include the configured agent's diagnosis in any draft PR, and will create
no source patch when the evidence does not establish an application defect.
Verification
npm run typechecknpm run buildgit diff --checkExisting test changes
always()onfailure-evidence collection, replacing the prior skipped-on-upstream-failure
behavior
lines, with replacement coverage proving generated source strings do not
trigger false diagnostics