Repository navigation
[agent-job-health] Agent Job Health: 2026-10-07 daily report (12.77 percent fleet rate, redact-secrets regression) #66705
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Agent Job Health Monitor. A newer discussion is available at Discussion #67304. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
Warning
One novel, fleet-wide infrastructure regression was found: a post-execution "Redact secrets in logs" step is failing across 3 different agentic engines (codex, copilot, claude) and 4 different workflows, always after the agent itself completed successfully. This is new today (not present in the 2026-10-06 report) and is the largest single cluster (33% of all agent-job failures). An issue has been filed.
Failure Rate by Step
Tracked Failures
invalid_request_error, codex engine routed through the Copilot compatibility adapter). #65950 was auto-filed for this exact failure on 2026-10-05 and auto-closed/expired on 2026-10-06 without a fix landing, so it has recurred twice more today. Treated as tracked (known signature), not novel — but the underlying bug is still unresolved and the auto-expiry is hiding that.No other failing workflow or error signature today matched an open issue found by search (search results were partially filtered by the GitHub integrity policy — some matches may not be visible to this report; treat "no open issue found" as best-effort, not a guarantee).
Novel Failure Clusters
1.
Redact secrets in logsstep failure —ERR_VALIDATION: Failed to remove artifact source after secret redaction failed##[warning]Replaced non-writable file for secret redaction: /tmp/gh-aw/mcp-logs/safeoutputs/server.log→##[error]ERR_VALIDATION: Secret redaction failed: ERR_VALIDATION: Failed to remove artifact source after secret redaction failed.redact_secrets.cjsreplaces non-writable sandbox/firewall-audit files in place (logged as warnings), then a later step tries to remove the original artifact source and fails — likely because the replacement left a file with different ownership/permissions, or a race between the firewall sandbox teardown and the redaction step's cleanup. The agent's own execution always completed fine in all 4 cases; only this post-processing step fails, but it still fails the whole job.redact_secrets.cjsor the firewall-audit artifact handling, making artifact-source removal tolerant of files it just rewrote in place.2.
Execute GitHub Copilot CLI— engine timeout (agentic_engine_timeout)pull_request-triggered, both copilot engine)agent.execution categories=["agentic_engine_timeout"] errorCodes=[] errorTypes=[] exitCode=03.
Execute GitHub Copilot CLI— HTTP 429 rate limitagent.execution categories=[] errorCodes=[429] errorTypes=["rate_limit"] exitCode=14. Unconfirmed-root-cause singletons
agentic_engine_timeout/ai_credits_rate_limit_erroroutput keys are declared in every job output list regardless of value, so their presence in logs is not itself evidence — do not over-read it elsewhere in this fleet). No issue filed for these; flagging for awareness only.Schedule Heartbeat
245 workflows declare a
schedule:trigger in frontmatter. All were checked against the most recent Actions run of any kind..github/workflows/daily-geo-optimizer.lock.ymldisabled_manually.github/workflows/daily-hippo-learn.lock.ymldisabled_manually.github/workflows/slide-deck-maintainer.lock.ymldisabled_manually.github/workflows/smoke-ci.lock.ymldisabled_manuallyAll four are explained by
disabled_manually— not an undiagnosed cron misfire. Recommend re-enabling (gh workflow enable <name>.lock.yml) if these are still wanted, or removing theirschedule:trigger if intentionally retired, so they stop showing up as blind spots in future reports.Also observed:
smoke-pi-auto,smoke-claude-auto,smoke-claude-copilot-auto, andsmoke-codex-bare-autohave never run (zero runs ever) — all four were created 2026-10-07T17:07:58Z, i.e. a few hours before this report, and areactive. These are new workflows that haven't reached their first scheduled fire yet, not blind spots — no action needed, but worth a follow-up check tomorrow if they still haven't fired.View per-workflow breakdown
Recommendations
daily-geo-optimizer,daily-hippo-learn,slide-deck-maintainer, andsmoke-ci— all four aredisabled_manually, not misfiring; a deliberate decision is needed either way so they stop appearing as blind spots.unsupported_custom_toolerror) — the auto-generated issue expired before a fix landed, and the same failure has now recurred twice more. The expiry mechanism silently dropped a real, repeating bug.All reactions