Repository navigation
fix(ci): public upstream image for sample-e2e + fast red-proof gate - #45
Merged
Merged
Conversation
sample-plugin-e2e pinned A0_IMAGE to the PRIVATE fork image and passed GHCR_PULL_TOKEN. Dependabot runs and fork PRs never receive secrets, so the pull 401d and the workflow was red for everyone outside the org -- which would be every external contributor once this repo is public. Switch to the DEC-019 default docker.io/agent0ai/agent-zero:latest (public, no creds). Consumers needing the ML-bundled fork still override A0_IMAGE per-plugin via .devkit.yml. Red-proof (Gate 3): the binding clock is Playwright test-level timeout, not action/expect timeouts -- a step passing an explicit per-call timeout cannot be overridden from config but IS capped by the test timeout. Measured 12 x ~113s = 22m40s. Cap the test timeout for the red-proof pass only; disable video/screenshot/trace capture there (expected failures, artifacts nobody reads). Semantics unchanged: every scenario still runs, still exactly 0 passes. Two guards make weakening impossible to miss -- Guard A asserts red-proof and real run cover the same scenario count; Guard B fails if the slowest genuinely-passing scenario exceeds 80%% of the cap (a cap that could clip an honest pass could mask a fake-green). Also restores the exec bit on run-bdd.sh (text_editor clears it).
DEVKIT_IMAGE defaulted to ghcr.io/agent-zero-plugins/plugin-devkit:latest but nothing ever published it, so the package did not exist: every consumer make e2e died with manifest unknown, and CI only worked because each workflow rebuilt the image inline (~85s per run). Build devcontainer/Containerfile and push :latest + :sha-<12>, plus the version tag on v* tags. Least privilege: contents:read + packages:write, GITHUB_TOKEN only, no PAT. The final step logs OUT and pulls anonymously, failing with actionable instructions if the package is not public -- the no-auth consumer path is the reason to publish at all, so it is proven rather than assumed.
LoginPage.login() asserted the top-nav "Plugins" button with Playwright's bare 5000ms expect default -- the only post-login landmark in the suite left on the default (PluginsPage uses explicit 8s/20s/10s). On a cold nested A0 the WebUI hydrates ~5s AFTER the post-login redirect, so that deadline straddles the render and flakes ~50%. Proven from run 30721063715's trace: page reached / at t=2.4s, top-nav rendered at t=7.755s, default deadline ~7.4s -- missed by ~350ms. The passing run on the very next commit touched no test/timeout/image config, confirming a coin-flip race rather than an image behavioural difference. The wait exists to surface a silent auth failure, not to measure hydration speed, so bound it generously at 30s.
omar-nahhas
added a commit
that referenced
this pull request
Aug 3, 2026
PR #45 accidentally committed e2e/node_modules as a mode-120000 symlink pointing at /a0/usr/workdir/.bdd-deps/node_modules -- a machine-local dep cache path that exists on exactly one machine. Every clone would carry a dangling symlink. .gitignore already had 'node_modules/', but the trailing slash matches only real DIRECTORIES, so a symlink of the same name slips past. Added a bare 'node_modules' pattern alongside it so this cannot recur.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepares the repo to go public.
1. sample-e2e must pass with NO secrets
sample-plugin-e2e.ymlpinnedA0_IMAGEto the private fork image and passedGHCR_PULL_TOKEN. Dependabot runs and fork PRs never receive secrets, so the pull 401d:That is why PRs #42/#43/#44 are red — and it would be every external contributor once this repo is public.
Fix: use the
DEC-019defaultdocker.io/agent0ai/agent-zero:latest(public, no creds). Consumers needing the ML-bundled fork still overrideA0_IMAGEper-plugin via.devkit.yml.2. Fast red-proof (Gate 3) — semantics unchanged
The binding clock is Playwright's test-level timeout, not action/expect timeouts: a step passing an explicit per-call
{ timeout: N }cannot be overridden from config but is capped by the test timeout. Measured 12 x ~113s = 22m40s of a ~35min run.Cap the test timeout for the red-proof pass only, and disable video/screenshot/trace there (expected failures, artifacts nobody reads).
Every scenario still runs; the assertion is still exactly 0 passes. Two guards make weakening impossible to miss:
Also restores the exec bit on
run-bdd.sh(text_editorclears it).