Repository navigation
Isolate dry-run telemetry and make agents own security preflight - #66954
Conversation
Permit compile-only dry runs with scoped snapshot and restoration of generated changes, while preserving live authorization gates. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Suppress automatic OTLP export and authentication in dry-run job data, filter telemetry variables from emitted Actions env mappings, and preserve normal compilation and executable script contents. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.
|
|
✅ Ponytail Reviewer completed successfully! Lean already. Ship.
|
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
🧠 Matt Pocock Skills Reviewer is reviewing this pull request using Matt Pocock's engineering skills... |
🏗️ Design Decision Gate — ADR RequiredThis PR makes significant changes to core business logic (401 new lines in 📄 Draft ADR committed:
🔍 Decision inferred from the diff
The 📋 What to do next
Once an ADR is linked in the PR body, this gate will re-run and verify the implementation matches the decision. ❓ Why ADRs Matter
ADRs create a searchable, permanent record of why the codebase looks the way it does. Future contributors (and your future self) will thank you. 📋 Michael Nygard ADR Format ReferenceAn ADR must contain these four sections to be considered complete:
All ADRs are stored in
|
Remove workflow activation and secret availability/validity metadata as pre-dispatch gates while preserving credential-flow review, destination authorization, and live safety controls. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment MemoryPeek at saved memory (pr-code-quality-reviewer)Note This comment is managed by comment memory.Expand the saved memory block to view or edit the persistent context for this thread.
|
There was a problem hiding this comment.
Request changes
Dry-run still leaves OTLP-only helper behavior in the emitted lock because the new path strips rendered env mappings after job generation but keeps the already-injected telemetry env in WorkflowData.
Blocking theme
- dryRunConclusionData clears OTLP fields and removes observability, but it does not clear WorkflowData.Env.
- OTLP-gated helpers still key off data.Env, so dry-run locks can continue to emit telemetry-specific steps such as Generate observability summary, Mask OTLP telemetry headers, and Mask OTLP custom attribute values.
- The added regression only checks emitted env mappings plus a couple of auth/default-credential steps, so this hole is currently untested.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 104.4 AIC · ⌖ 5.57 AIC · ⊞ 19.8K
Comment /review to run again
There was a problem hiding this comment.
🟡 Changes recommended
Environment rewriting can alter retained values and remove quoting required for valid YAML.
2 open findings
What changed in this PR
Isolates telemetry from compiled dry-run workflows and assigns security preflight and diagnostic cleanup to agents.
Changes:
- Removes telemetry environment variables and automatic OTLP configuration from dry-run output.
- Adds regression coverage for environment scopes, reusable workflows, and compiler reuse.
- Updates guidance for agent-owned validation, evidence collection, and scoped cleanup.
| File | Description |
|---|---|
pkg/workflow/compiler_yaml.go |
Filters telemetry before secret collection and after regeneration. |
pkg/workflow/compiler_development.go |
Clears dry-run telemetry configuration. |
pkg/workflow/compiler_development_telemetry.go |
Implements environment filtering. |
pkg/workflow/compiler_development_telemetry_test.go |
Adds telemetry-isolation regressions. |
pkg/cli/compile_development_report.go |
Updates the dry-run scope message. |
docs/src/content/docs/setup/cli.md |
Documents telemetry suppression. |
docs/src/content/docs/reference/compilation-process.md |
Explains suppression scope and limitations. |
.github/skills/review-agentic-workflows/SKILL.md |
Assigns review and cleanup responsibilities. |
.github/aw/debug-security-review.md |
Defines compile-only evidence and restoration rules. |
.github/aw/debug-agentic-workflow.md |
Aligns debugging guidance with agent ownership. |
🧠 Review effort: Balanced
Prepare cloned telemetry-free workflow environment before building jobs and headers, omit stale env-source metadata, and disable telemetry mask detection for dry-run data even when retained values contain OTEL literals. Preserve the final all-scope filter and normal compile behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Always summarize the reviewed artifact, outcome, checks performed, and material findings or coverage gaps in short separate user-facing sentences, including blocked and unavailable attempts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: a0ea82d
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Preserve retained env scalars and quoting; keep dry-run diagnostics bounded, restrict manual dispatch to maintainers/admins, and report value-free mutation logs. Document explicit session grants and compiler-warning invalidation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…elikhan-debug-smoke-agy Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |

Summary
Make workflow security preflight and diagnostic cleanup agent-owned, and remove telemetry export configuration from compiled
--dry-runlocks.OTEL_*andGH_AW_OTLP_*variables from workflow, job, step, container, and service environments, including user-defined values and engine/pre/post-step environments.DEBUG=workflow:compiler_development,cli:compile_development, without configuration values or duplicate unchanged-state logs.Validation
observability_otlp.go, the existing oversized builder function inworkflow_builder.go, two unchanged indexing diagnostics inawf_env.go, and one unchanged indexing diagnostic incompile_development.go. New lint issues were fixed; no check was disabled or unrelated cleanup applied. This PR is not declared merge-ready.make check-workflow-driftseparately compiled all 333 workflows with normal generated locks unchanged../gh-aw compile smoke-agy --dry-run --jsonpassed strict/source/model validation and native shellcheck with zero errors/warnings. Verified 53 parsed environment mappings have noOTEL_*orGH_AW_OTLP_*keys, daily accounting is omitted, the admin/maintainer role gate is present, and the 50-credit per-run cap remains.Architecture decision
Draft ADR-66954: telemetry suppression in diagnostic locks. Maintainer acceptance is not implied. The record describes scoped YAML rewriting and its formatting/alias limitations, separately authorized diagnostic execution, and the associated bounded dry-run controls.
Custom scripts that configure their own exporters remain outside the compiler's env suppression.