Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 2 additions & 17 deletions .github/aw/memory-stateful-patterns.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,20 +138,5 @@ shards directly. When concurrent runs can report the same event, deduplicate
and resolve conflicts using deterministic application rules; the ledger
converges after branch merges but does not provide transactions.

The ledger is experimental and bounded to 1024 shard files by default (set
`ledger.max-shards` to choose a lower limit), 32 KiB per record and 100 KiB per
shard by default, and 500 records per query. A new writer shard is created by each workflow
invocation. When configured, `ledger.compaction` defaults to compacting 32 stable closed shards
once that threshold is reached; the trusted runtime selects, validates,
deduplicates, writes, verifies, and retires segments. Custom JavaScript
compactor scripts are disabled because Node's in-process VM is not a security
boundary. Ledger workflows require AWF Cloud Hypervisor, and the compiler keeps
ledger paths out of agent write permissions; append through MCP only.
The default per-run append limit is 10 KiB. Configure `max-segment-kb`,
`max-record-kb`, and `max-patch-kb` when daily volume needs tighter bounds;
compilation warns if those limits exceed the repo-memory file or patch limits.
Compaction, normalization, and save details appear in the persistence step
summary. Record SHA-256 values are unkeyed checksums rather than authentication;
the ledger is eventually convergent but neither transactional nor exactly-once.
Use application idempotency keys, deduplicate, and resolve concurrent conflicts
deterministically. Avoid it for replaceable snapshots or expiring baselines.
For shard/record/query limits, compaction behavior, and the Cloud Hypervisor
isolation model, see [memory.md](memory.md#structured-event-history-repo-memory-ledger-experimental).
1 change: 1 addition & 0 deletions .github/aw/safe-outputs-automation.md
Original file line number Diff line number Diff line change
Expand Up @@ -172,6 +172,7 @@ description: Safe-output reference for workflow dispatch, code scanning, checks,
custom-agent: "agent-id" # Optional: custom agent ID
custom-instructions: "..." # Optional: additional instructions for the agent
allowed: [copilot] # Optional: restrict to specific agent names
required-labels: [copilot-ready] # Optional: ALL of these labels must be present on the issue/PR for assignment to run
max: 1 # Optional: max assignments (default: 1)
target: "*" # Optional: "triggering" (default), "*", or number
target-repo: "owner/repo" # Optional: where the issue lives (cross-repository)
Expand Down
1 change: 1 addition & 0 deletions .github/aw/safe-outputs-management.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,6 +91,7 @@ description: Safe-output reference for update, label, milestone, project, releas
max: 5 # Optional: maximum number of labels (default: 5)
target: "*" # Optional: "triggering" (default), "*" (any issue/PR), or number
target-repo: "owner/repo" # Optional: cross-repository
item-schema: { ... } # Optional: narrows the label item schema shown to/enforced on the agent (can only restrict, not widen, the built-in string-or-object shape)
```

- `remove-labels:` - Safe label removal from issues or PRs
Expand Down
1 change: 1 addition & 0 deletions .github/aw/syntax-engine.md
Original file line number Diff line number Diff line change
Expand Up @@ -89,4 +89,5 @@ See [syntax-agentic.md](syntax-agentic.md) for the full frontmatter field index.

Constraints: exactly one runtime key per `driver` object; source must be non-empty; only supported on the `copilot` engine. Use `runtimes.<id>.version` to pin the runtime version used for the generated module files (e.g. `runtimes.go.version: "1.22"`).
- **`engine.auth:`** — keyless Workload Identity Federation via the AWF API proxy instead of a static API key; requires `id-token: write`. Set `type: github-oidc` (only supported type) plus `provider: azure` (`azure-tenant-id`, `azure-client-id`, optional `azure-scope`/`azure-cloud`) for Azure OpenAI, `provider: anthropic` (`federation-rule-id`, `organization-id`, `service-account-id`, `workspace-id`) for Claude, or `provider: gcp` (`workload-identity-provider`, `service-account`, optional `project`/`location`, default region `us-central1`) for Vertex AI / Gemini Enterprise. Optional `audience:`. Maps to `AWF_AUTH_*` env vars.
- **`engine.model-routing:`** (Copilot engine only) — lets AWF pick a Copilot model per task from the rendered prompt instead of a fixed `model`. Requires the AWF firewall and a minimum AWF version. Required sub-fields: `goal` (`cost` | `cost-speed`), `mode` (`economy` | `balanced` | `robust` | `auto`), `allowed-models` (non-empty list of Copilot model names; must intersect any top-level `models.allowed`/`models.blocked` policy).
- **Advanced engine sub-fields** (see the `engine_config` definition in `pkg/parser/schemas/main_workflow_schema.json`): `model-provider` (`github` | `anthropic` | `openai`), `harness` (`max-retries`/`initial-delay-ms`/`backoff-multiplier`/`max-delay-ms` retry policy, plus `watchdog-timeout` — a post-result idle-process watchdog, in seconds, for the built-in Copilot/Codex harnesses), engine-level `mcp` (`session-timeout`/`tool-timeout`), `extensions`, and `cwd`. See [Harness Settings and Runtime Tuning Variables](https://github.com/github/gh-aw/blob/main/docs/src/content/docs/reference/environment-variables.md#harness-settings-and-runtime-tuning-variables) for defaults, units, and `GH_AW_HARNESS_*` env var equivalents.