Skip to content

workflows: Pre-install just and gh-aw for drafter and fix - #117

Merged
cgwalters merged 2 commits into
bootc-dev:mainfrom
cgwalters-forge:bot/aw-preinstall-tools
Sep 30, 2026
Merged

cgwalters merged 2 commits into
bootc-dev:mainfrom
cgwalters-forge:bot/aw-preinstall-tools

Conversation

@cgwalters-bot

Copy link
Copy Markdown
Contributor

The drafter and fix agents are told to run just setup && just compile after editing a workflow, but can't install either tool from inside the AWF sandbox (#109): gh isn't logged in there and api.github.com isn't on the allowlist.

This adds a shared import that sets up both on the runner before the agent starts, which gh-aw supports directly, so no custom runner or container image is needed: custom steps: and runtimes: run outside the firewall (steps and jobs), and AWF exposes the host's binaries and $HOME (where gh keeps extensions) inside the sandbox (host binaries). just comes from apt; the compiler's gh-aw runtime installs the CLI through github/gh-aw-actions/setup-cli at the compiler's own version, which ci.yml already holds to .github/aw/gh-aw-version. A prep commit makes just setup detect the installed CLI with gh aw version, since gh extension list fails when gh isn't logged in.

Side effect of the gh-aw runtime: the compiler adds github.github.com to the agent's allowlist, and GitHub's download hosts to the threat-detection job's.

The ANTHROPIC_API_KEY 401/403 warning on #109 is a false positive, not a secret problem: all 31 model calls through the API proxy returned 200. The two 403s were Squid denying direct connections from the agent container to api.anthropic.com, which the firewall blocks by design (only the API proxy may connect).

Tested on a devspace: lock files recompiled with gh-aw v0.88.2, and recompiling again gives no drift. Inside unshare -rn with no GitHub token, just setup && just compile succeeds, both with the CLI installed as a gh extension and with it installed by setup-cli's manual fallback. The ci.yml node tests pass. actionlint reports the same 28 findings on the workflows as on main, none new. Not run: a live drafter run, since that needs the repository's secrets and App.

Fixes #109

The Signed-off-by: Colin Walters <walters@verbum.org> on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#2 (review)

Generated-by: https://github.com/cgwalters/#llms

`gh extension list` fails when gh isn't logged in, as in the agent
sandbox. setup then fell through to `gh extension install`, which needs
the network and fails outright when gh-aw was installed without an
extension manifest (setup-cli's fallback path). Asking `gh aw version`
works in both cases.

Prep for pre-installing gh-aw for the drafter and fix agents.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
The drafter and fix agents are told to recompile lock files after
editing a workflow, but they can't install the tools to do it (bootc-dev#109):
gh isn't logged in inside the sandbox, api.github.com isn't on the
allowlist, and building just from crates.io isn't worth the agent's
time even where it's allowed.

gh-aw's custom steps and runtimes are set up on the runner before the
agent starts, outside the firewall, and AWF exposes the host's binaries
and $HOME (where gh keeps extensions) inside the sandbox, so a shared
import is enough; no custom runner or container image. The gh-aw
runtime installs the CLI at the compiler's own version, which ci.yml
already holds to .github/aw/gh-aw-version, so there's no second pin
to keep in sync. As a side effect the compiler adds github.github.com
(gh-aw's docs) to the agent's allowlist and GitHub's download hosts to
the detection job's.

Fixes: bootc-dev#109

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
# Custom steps run outside the sandbox, after checkout; see
# https://github.github.com/gh-aw/reference/steps-jobs/
steps:
- name: Install just

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks right but followup cut over to ubuntu-26.04 plus https://github.com/bootc-dev/actions/tree/main/bootc-ubuntu-setup

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[aw] Drafter is missing required tool

2 participants