Batch Mode: Failure Scenarios, Recovery, and Operational Gotchas #19
Closed
AlexDeMichieli
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Context
During E2E deployment testing of batch mode (
submit-repos.yml) on an EMU enterprise (volcano-coffee), we encountered multiple failure scenarios that required manual intervention. This discussion documents each failure mode, its root cause, recovery steps, and whether the proposed architecture in #14 would address it.Test environment: EMU enterprise, SAML SSO enforced, single org (
alexdemichieli-migrations), Copilot Enterprise license.Failure Scenarios
1. PAT-Based Agent Assignment Fails on SSO-Enforced Orgs
Symptom: Every batch-created issue gets: "The agent encountered an error and was unable to start working on this issue: Please try again later, or contact support if the problem persists."
Root cause: Platform bug in github/github#424974 (merged March 27, 2026). When
submit-repos.ymlassignscopilot-swe-agentvia GraphQL using a PAT, the monolith mints an OAuth token but computes the wrong SSO org IDs — the minted token has no access to the target repo.Who's affected: Any org/enterprise with SAML SSO enabled. Both classic and fine-grained PATs. Affects programmatic assignment only — manual assignment via Copilot Chat UI uses session credentials and works fine.
Fix: github/github#425401 (merged March 31). Rolling out behind feature flag
copilot_mint_token_from_pat_with_all_orgs.Recovery:
Would #14 fix this? Partially. The agentic workflows proposal eliminates per-repo issue creation via PAT, but the underlying token minting bug would still affect any PAT-based orchestration.
2. Ghost Sessions from Failed Assignments
Symptom:
github.com/copilot/agentsshows N "Active" sessions, but clicking the Active tab shows no sessions. New Copilot assignments fail with the same generic error.Root cause: Failed agent assignments (from Scenario 1 or transient errors) create phantom sessions that count against concurrency limits but aren't visible or stoppable in the UI.
Recovery:
github.com/copilot/agents— Active count should dropDetection: If the Active count > 0 but no sessions are listed, you have ghost sessions.
Would #14 fix this? Yes — agentic workflows wouldn't create per-repo issues, eliminating the ghost session scenario.
3. Tag Clear Fails — Repos Re-Processed on Next Batch Run
Symptom: Batch workflow logs show
Failed to update custom property for <repo>: Resource not accessible by integration. TheGH_MIGRATION_TYPEtag stays set, so the repo is picked up again on the next batch run, creating duplicate issues.Root cause: The GitHub App has
organization_custom_properties: write(for managing the org-level schema) but notcustom_propertiesat the repository level. The endpointPATCH /repos/{owner}/{repo}/properties/valuesrequires Repository: Custom properties (Read & Write).Recovery:
Prevention: Add this permission to the Phase 1 deployment checklist. The upstream
deployment.mddoesn't mention it.Would #14 fix this? Yes — the proposal uses a tracking file in
.github-privateinstead of custom properties.4. Enterprise Custom Agents Selector Conflict (Shared Enterprise)
Symptom: Custom agents disappear from
github.com/copilot/agents. The agent dropdown is empty when assigning Copilot to issues.Root cause: Enterprise AI Controls → Custom agents only allows one org to be selected. On a shared enterprise (e.g.,
volcano-coffeewith 133 orgs), another admin selected their org, removing yours.Recovery:
Prevention: Coordinate with enterprise admins. For production use, request a dedicated enterprise or document the shared-enterprise limitation.
Would #14 fix this? No — this is an enterprise configuration issue independent of architecture.
5. Duplicate Issues from Partial Batch Failures
Symptom: Multiple identical
[Actions Migration]issues on the same repo, each with the full agent prompt as the body.Root cause: The batch workflow has no idempotency check. If tag clear fails (Scenario 3) and the workflow is re-run, it finds the same tagged repos and creates new issues without checking for existing open migration issues.
Recovery:
Prevention: Add a pre-check to
submit-repositories.js: before creating an issue, search for open issues titled[Actions Migration]on the target repo. Skip if one exists.Would #14 fix this? Yes — eliminates the IssueOps pattern entirely.
6. Firewall Allowlist Required on EMU (Per-Repo)
Symptom: Copilot agent session starts but
git pushreturns 403. The agent can read files but can't create branches or push commits.Root cause: On EMU enterprises, the Copilot coding agent firewall blocks
api.github.comandgithub.comby default. Each target repo needs a custom allowlist.Recovery:
github.com,api.github.com,uploads.github.comPrevention: The
create-environment-secrets.jsscript insettings.ymlalready iterates every repo — it could also configure the firewall allowlist programmatically if an API exists.Would #14 fix this? No — per-repo firewall config is required regardless of architecture.
Summary: Architecture Impact
Related
#coding-agent-team— Platform bug tracking for SSO token mintingAll reactions