Skip to content

[q] fix(observability): add firewall and mcp artifacts, remove invalid parse param #43654

Description

@github-actions

Q Workflow Optimization Report

Triggered by @pelikhan in discussion #43645: "make sure to download the agent artifact"

Issues Found (from live data)

daily-observability-report

  • Discussion analyzed: [observability] Observability Coverage Report - 2026-07-06 #43645 (Observability Coverage Report - 2026-07-06)
  • Reported symptoms: 0% coverage for both AWF Firewall and MCP Gateway across all 18 sampled runs
  • Issues Identified:
    1. parse: true is not a valid parameter for the logs MCP tool — causes the tool call to fail with Unknown parameter 'parse'
    2. The artifacts array was ["usage", "agent", "detection"] — missing firewall (needed for access.log) and mcp (needed for gateway.jsonl / rpc-messages.jsonl)

Because the artifact sets for firewall and MCP were never requested, those log files were never downloaded, so the analysis correctly reported 0% coverage — but the root cause was the missing artifact types, not an actual infrastructure problem.

Changes Made

daily-observability-report (.github/workflows/daily-observability-report.md)

Both logs call examples (broad fetch + targeted follow-up) updated:

  • Removed invalid parse: true parameter
  • Added "firewall" artifact set → downloads access.log for firewall-enabled runs
  • Added "mcp" artifact set → downloads gateway.jsonl and rpc-messages.jsonl for MCP-enabled runs

Expected Improvements

  • access.log will now be downloaded for firewall-enabled runs → firewall coverage > 0%
  • gateway.jsonl / rpc-messages.jsonl will now be downloaded for MCP-enabled runs → MCP gateway coverage > 0%
  • Invalid parse parameter removed → logs calls will no longer fail on parameter validation

Validation

All modified workflows compiled successfully:

  • ✅ daily-observability-report

Note: .lock.yml file will be regenerated automatically after merge.

References


Warning

Protected Files — Push Permission Denied

This was originally intended as a pull request, but the patch modifies protected files. A human must create the pull request manually.

Protected files

The push was rejected because GitHub Actions does not have workflows permission to push these changes, and is never allowed to make such changes, or other authorization being used does not have this permission.

Create the pull request manually
# Download the patch from the workflow run
gh run download 28761720561 -n agent -D /tmp/agent-28761720561

# Create a new branch
git checkout -b q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad main

# Apply the patch (--3way handles cross-repo patches)
git am --3way /tmp/agent-28761720561/aw-q-fix-observability-artifact-downloads.patch

# Push the branch and create the pull request
git push origin q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad
gh pr create --title '[q] fix(observability): add firewall and mcp artifacts, remove invalid parse param' --base main --head q/fix-observability-artifact-downloads-fc3e2df5b18ae4ad --repo github/gh-aw

🎩 Equipped by Q · 51.3 AIC · ⌖ 8.64 AIC · ⊞ 8K · ◷
Comment /q to run again

  • expires on Jul 7, 2026, 5:27 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions