Skip to content

Add inline WIF setup summaries to the quick-start - #65570

Merged
pelikhan merged 4 commits into
mainfrom
copilot/deep-report-add-inline-wif-setup-summary
Oct 4, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/deep-report-add-inline-wif-setup-summary

Conversation

Copilot AI commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

The quick-start presented API-key setup steps inline but described Workload Identity Federation only with bare links. Add brief setup summaries so both keyless paths are equally discoverable.

  • Claude: Summarize the Anthropic federation rule and id-token: write requirement.
  • Gemini: Summarize the Google Cloud WIF provider and Vertex AI service-account setup.
  • Both summaries explain that GitHub OIDC exchanges a short-lived token, avoiding a repository secret.

Copilot AI and others added 2 commits October 4, 2026 13:31
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Add inline WIF setup summary to quick-start.mdx Add inline WIF setup summaries to the quick-start Oct 4, 2026
Copilot AI requested a review from pelikhan October 4, 2026 13:32
@pelikhan
pelikhan marked this pull request as ready for review October 4, 2026 13:38
Copilot AI balanced review requested due to automatic review settings October 4, 2026 13:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The queue schema breaks expression-based workflows, the router loses valid commands, and Gemini’s summary omits required setup.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)
What changed in this PR

Adds inline WIF setup guidance to the quick-start, but also includes unrelated workflow/schema changes.

Changes:

  • Summarizes Claude and Gemini keyless authentication.
  • Changes concurrency queue schema validation.
  • Regenerates the centralized command router with many routes removed.
File Description
docs/​src/​content/​docs/​setup/​quick-start.mdx Adds WIF summaries.
pkg/​workflow/​schemas/​github-workflow.json Restricts concurrency queue values.
go.mod Promotes YAML v3 to a direct dependency.
.github/​workflows/​agentic_commands.yml Removes numerous command routes.

@@ -1,4 +1,4 @@
# gh-aw-commands: {"payload_version":"v1","schema_version":"v1","compiler_version":"dev","commands":["*","ace","approach-validator","archie","cloclo","craft","dependabot-burner","grumpy","matt","mergefest","nit","plan","poem-bot","ponytail","review","ruflo","scout","security-review","smoke-agent-all-merged","smoke-agent-all-none","smoke-agent-public-approved","smoke-agent-public-none","smoke-agent-scoped-approved","smoke-aider","smoke-call-workflow","smoke-checkout-pr-dispatch","smoke-claude","smoke-claude-on-copilot","smoke-codex","smoke-copilot","smoke-copilot-aoai-apikey","smoke-copilot-aoai-entra","smoke-copilot-arm","smoke-copilot-mai","smoke-copilot-sdk","smoke-copilot-small","smoke-create-cross-repo-pr","smoke-crush","smoke-cursor","smoke-deepseek-harness","smoke-drive","smoke-gemini","smoke-github-claude","smoke-goose","smoke-kiro","smoke-multi-pr","smoke-opencode","smoke-otel-backends","smoke-pi","smoke-project","smoke-pydantic","smoke-service-ports","smoke-temporary-id","smoke-test-tools","smoke-update-cross-repo-pr","souschef","squad-plan","summarize","tidy","unbloat","windows"],"workflows":["ace-editor","approach-validator","archie","cloclo","craft","dependabot-burner","design-decision-gate","dev","grumpy-reviewer","mattpocock-skills-reviewer","mergefest","necromancer","pdf-summary","plan","poem-bot","ponytail-reviewer","pr-code-quality-reviewer","pr-nitpick-reviewer","pr-sous-chef","ruflo-backed-task","scout","security-review","skillet","smoke-agent-all-merged","smoke-agent-all-none","smoke-agent-public-approved","smoke-agent-public-none","smoke-agent-scoped-approved","smoke-aider","smoke-call-workflow","smoke-checkout-pr-dispatch","smoke-claude","smoke-claude-on-copilot","smoke-codex","smoke-copilot","smoke-copilot-aoai-apikey","smoke-copilot-aoai-entra","smoke-copilot-arm","smoke-copilot-mai","smoke-copilot-sdk","smoke-copilot-small","smoke-create-cross-repo-pr","smoke-crush","smoke-cursor","smoke-deepseek-harness","smoke-drive","smoke-gemini","smoke-github-claude","smoke-goose","smoke-kiro","smoke-multi-pr","smoke-opencode","smoke-otel-backends","smoke-pi","smoke-project","smoke-pydantic","smoke-service-ports","smoke-temporary-id","smoke-test-tools","smoke-update-cross-repo-pr","squad-plan","test-quality-sentinel","tidy","unbloat-docs","windows"]}
# gh-aw-commands: {"payload_version":"v1","schema_version":"v1","compiler_version":"dev","commands":["*","ace","approach-validator","archie","cloclo","craft","dependabot-burner","grumpy","mergefest","nit","plan","poem-bot","ruflo","scout","security-review","smoke-claude-on-copilot","smoke-copilot","smoke-copilot-aoai-apikey","smoke-copilot-aoai-entra","smoke-copilot-mai","smoke-copilot-sdk","smoke-copilot-small","smoke-github-claude","smoke-otel-backends","smoke-service-ports","souschef","squad-plan","summarize","tidy","unbloat","windows"],"workflows":["ace-editor","approach-validator","archie","cloclo","craft","dependabot-burner","dev","grumpy-reviewer","mergefest","necromancer","pdf-summary","plan","poem-bot","pr-nitpick-reviewer","pr-sous-chef","ruflo-backed-task","scout","security-review","skillet","smoke-claude-on-copilot","smoke-copilot","smoke-copilot-aoai-apikey","smoke-copilot-aoai-entra","smoke-copilot-mai","smoke-copilot-sdk","smoke-copilot-small","smoke-github-claude","smoke-otel-backends","smoke-service-ports","squad-plan","tidy","unbloat-docs","windows"]}
Comment on lines +45 to +46
"type": "string",
"enum": ["single", "max"],
2. Add it as a repository secret from your repository root with `gh secret set GEMINI_API_KEY < /path/to/key.txt`, or use the GitHub UI. See [Authentication](/gh-aw/reference/auth/#gemini_api_key) for more detail.

To avoid a long-lived key, configure [Google Workload Identity Federation](/gh-aw/reference/auth/#google-workload-identity-federation-wif).
For keyless authentication, configure [Google Workload Identity Federation](/gh-aw/reference/auth/#google-workload-identity-federation-wif) with a Google Cloud Workload Identity Pool and Provider for GitHub Actions, and grant the service account Vertex AI User permissions. GitHub Actions exchanges a short-lived OIDC token for Google Cloud credentials, so you don't need a repository secret.
@pelikhan
pelikhan merged commit 24940d6 into main Oct 4, 2026
2 of 3 checks passed
@pelikhan
pelikhan deleted the copilot/deep-report-add-inline-wif-setup-summary branch October 4, 2026 14:44
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deep-report] Add inline WIF setup summary to quick-start.mdx (currently bare links, unlike API-key paths)

3 participants