diff --git a/.github/aw/memory-stateful-patterns.md b/.github/aw/memory-stateful-patterns.md index 0517baeadac..804b5a027b3 100644 --- a/.github/aw/memory-stateful-patterns.md +++ b/.github/aw/memory-stateful-patterns.md @@ -138,20 +138,5 @@ shards directly. When concurrent runs can report the same event, deduplicate and resolve conflicts using deterministic application rules; the ledger converges after branch merges but does not provide transactions. -The ledger is experimental and bounded to 1024 shard files by default (set -`ledger.max-shards` to choose a lower limit), 32 KiB per record and 100 KiB per -shard by default, and 500 records per query. A new writer shard is created by each workflow -invocation. When configured, `ledger.compaction` defaults to compacting 32 stable closed shards -once that threshold is reached; the trusted runtime selects, validates, -deduplicates, writes, verifies, and retires segments. Custom JavaScript -compactor scripts are disabled because Node's in-process VM is not a security -boundary. Ledger workflows require AWF Cloud Hypervisor, and the compiler keeps -ledger paths out of agent write permissions; append through MCP only. -The default per-run append limit is 10 KiB. Configure `max-segment-kb`, -`max-record-kb`, and `max-patch-kb` when daily volume needs tighter bounds; -compilation warns if those limits exceed the repo-memory file or patch limits. -Compaction, normalization, and save details appear in the persistence step -summary. Record SHA-256 values are unkeyed checksums rather than authentication; -the ledger is eventually convergent but neither transactional nor exactly-once. -Use application idempotency keys, deduplicate, and resolve concurrent conflicts -deterministically. Avoid it for replaceable snapshots or expiring baselines. +For shard/record/query limits, compaction behavior, and the Cloud Hypervisor +isolation model, see [memory.md](memory.md#structured-event-history-repo-memory-ledger-experimental). diff --git a/.github/aw/safe-outputs-automation.md b/.github/aw/safe-outputs-automation.md index 9fa64cdb017..391cb98f069 100644 --- a/.github/aw/safe-outputs-automation.md +++ b/.github/aw/safe-outputs-automation.md @@ -172,6 +172,7 @@ description: Safe-output reference for workflow dispatch, code scanning, checks, custom-agent: "agent-id" # Optional: custom agent ID custom-instructions: "..." # Optional: additional instructions for the agent allowed: [copilot] # Optional: restrict to specific agent names + required-labels: [copilot-ready] # Optional: ALL of these labels must be present on the issue/PR for assignment to run max: 1 # Optional: max assignments (default: 1) target: "*" # Optional: "triggering" (default), "*", or number target-repo: "owner/repo" # Optional: where the issue lives (cross-repository) diff --git a/.github/aw/safe-outputs-management.md b/.github/aw/safe-outputs-management.md index 4ef77062f44..e7ef9f68fb3 100644 --- a/.github/aw/safe-outputs-management.md +++ b/.github/aw/safe-outputs-management.md @@ -91,6 +91,7 @@ description: Safe-output reference for update, label, milestone, project, releas max: 5 # Optional: maximum number of labels (default: 5) target: "*" # Optional: "triggering" (default), "*" (any issue/PR), or number target-repo: "owner/repo" # Optional: cross-repository + item-schema: { ... } # Optional: narrows the label item schema shown to/enforced on the agent (can only restrict, not widen, the built-in string-or-object shape) ``` - `remove-labels:` - Safe label removal from issues or PRs diff --git a/.github/aw/syntax-engine.md b/.github/aw/syntax-engine.md index 1a361198490..18a631522ae 100644 --- a/.github/aw/syntax-engine.md +++ b/.github/aw/syntax-engine.md @@ -89,4 +89,5 @@ See [syntax-agentic.md](syntax-agentic.md) for the full frontmatter field index. Constraints: exactly one runtime key per `driver` object; source must be non-empty; only supported on the `copilot` engine. Use `runtimes..version` to pin the runtime version used for the generated module files (e.g. `runtimes.go.version: "1.22"`). - **`engine.auth:`** — keyless Workload Identity Federation via the AWF API proxy instead of a static API key; requires `id-token: write`. Set `type: github-oidc` (only supported type) plus `provider: azure` (`azure-tenant-id`, `azure-client-id`, optional `azure-scope`/`azure-cloud`) for Azure OpenAI, `provider: anthropic` (`federation-rule-id`, `organization-id`, `service-account-id`, `workspace-id`) for Claude, or `provider: gcp` (`workload-identity-provider`, `service-account`, optional `project`/`location`, default region `us-central1`) for Vertex AI / Gemini Enterprise. Optional `audience:`. Maps to `AWF_AUTH_*` env vars. + - **`engine.model-routing:`** (Copilot engine only) — lets AWF pick a Copilot model per task from the rendered prompt instead of a fixed `model`. Requires the AWF firewall and a minimum AWF version. Required sub-fields: `goal` (`cost` | `cost-speed`), `mode` (`economy` | `balanced` | `robust` | `auto`), `allowed-models` (non-empty list of Copilot model names; must intersect any top-level `models.allowed`/`models.blocked` policy). - **Advanced engine sub-fields** (see the `engine_config` definition in `pkg/parser/schemas/main_workflow_schema.json`): `model-provider` (`github` | `anthropic` | `openai`), `harness` (`max-retries`/`initial-delay-ms`/`backoff-multiplier`/`max-delay-ms` retry policy, plus `watchdog-timeout` — a post-result idle-process watchdog, in seconds, for the built-in Copilot/Codex harnesses), engine-level `mcp` (`session-timeout`/`tool-timeout`), `extensions`, and `cwd`. See [Harness Settings and Runtime Tuning Variables](https://github.com/github/gh-aw/blob/main/docs/src/content/docs/reference/environment-variables.md#harness-settings-and-runtime-tuning-variables) for defaults, units, and `GH_AW_HARNESS_*` env var equivalents.