Repository navigation
Migrate Daily Reliability Review off the hanging opencode engine - #62490
Conversation
…copilot Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot fix OpenCode wiring to copilot models inference endpoints |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot resolve the merge conflicts on this branch. |
|
Thanks for this fix! 🎉 Migrating the Daily Reliability Review workflow off the hanging opencode engine is a solid piece of infrastructure maintenance — the diff is focused, well-explained, and comes with the necessary lock file updates. This looks ready for review. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The intended workflow remains on the failing engine while unrelated OpenCode consumers are modified.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Intended to migrate Daily Reliability Review to Copilot, but the diff instead changes the shared OpenCode endpoint while leaving the target workflow on OpenCode.
Changes:
- Changes the shared OpenCode proxy endpoint.
- Regenerates three OpenCode workflow lock files.
- Does not implement the described Copilot migration.
| File | Description |
|---|---|
.github/workflows/shared/opencode.md |
Changes the provider endpoint globally. |
.github/workflows/daily-reliability-review.lock.yml |
Regenerated but remains on OpenCode. |
.github/workflows/daily-security-red-team.lock.yml |
Incorporates the shared endpoint change. |
.github/workflows/smoke-opencode.lock.yml |
Incorporates the shared endpoint change. |
| @@ -1,4 +1,4 @@ | |||
| # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"592b158a7c5aa74097c286d321c76ab76d737824c38ac89729c3ac522e667d51","body_hash":"3257e2a36b70696ecce65eeea934f2bd4a04cff46fb940def529496db0ffcbb8","strict":true,"agent_id":"opencode","agent_model":"copilot/claude-sonnet-4.5","engine_versions":{"opencode":"1.2.14"}} | |||
| # gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"df0f28cd09d531fe2e6b853914288f52c75ec9594cf14afe0892512a5ca73f7f","body_hash":"3257e2a36b70696ecce65eeea934f2bd4a04cff46fb940def529496db0ffcbb8","strict":true,"agent_id":"opencode","agent_model":"copilot/claude-sonnet-4.5","engine_versions":{"opencode":"1.2.14"}} | |||
There was a problem hiding this comment.
Addressed in f0f070b: .github/workflows/daily-reliability-review.md now selects engine.id: copilot, uses model: claude-sonnet-4.5, removes shared/opencode.md, and the lock file is recompiled with agent_id: "copilot" and no OpenCode CLI step.
| "provider": { | ||
| "awf-proxy": { | ||
| "api": "http://172.30.0.30:10002", | ||
| "api": "http://host.docker.internal:10002", |
There was a problem hiding this comment.
Addressed in f0f070b: the shared OpenCode definition and the unrelated OpenCode lock-file churn are reverted out of the PR diff. The current PR file list only changes daily-reliability-review.md and its generated lock file.
…reliability-review # Conflicts: # .github/workflows/daily-reliability-review.lock.yml # .github/workflows/daily-security-red-team.lock.yml # .github/workflows/smoke-opencode.lock.yml Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot resolve the merge conflicts in this pull request |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
Please resolve the merge conflicts on this branch with Run: https://github.com/github/gh-aw/actions/runs/35676042651
|
…reliability-review Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Resolved with
Completed |
|
Please address the open Copilot review findings below, refresh the branch if needed, and then run the Open review follow-ups (newest first):
Run: https://github.com/github/gh-aw/actions/runs/35681273619
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed in f0f070b: the branch is refreshed, the Daily Reliability Review workflow is migrated to Copilot, shared OpenCode churn is reverted out of scope, and |
|
🎉 This pull request is included in a new release. Release: |


Daily Reliability Reviewhas been timing out every run. The reported "engine terminated unexpectedly" is actually a hang: opencode emits its startup lines and then goes silent until the step timeout kills it.From run 35664876261:
0 turns, 0 tokens, and a single outbound request (
models.dev) — the remaining firewall entries came from the AWF api-proxy sidecar, not the agent.Root cause
This is engine-wide, not workflow-specific.
Smoke OpenCode— the canary for this engine — has failed identically on every scheduled run sinceshared/opencode.mdwas reintroduced on Sep 5 pinned toopencode-ai@1.2.14, always stopping at the sameDatabase migration complete.line. It matches known upstream reports of headlessopencode runhanging in CI. There is no fix on our side that can be verified without live CI iteration, so the workflow is moved to a working engine instead — the same remedy applied to this workflow once before.Changes
.github/workflows/daily-reliability-review.md—engine: opencode→engine: copilot,model: copilot/claude-sonnet-4.5→model: claude-sonnet-4.5, and dropped the now-unusedshared/opencode.mdimport..github/workflows/daily-reliability-review.lock.yml— recompiled.shared/opencode.mdandsmoke-opencodeare untouched, so the canary keeps tracking the upstream hang.Side effect worth reviewing
Under
opencodethe Sentry MCP server was never wired into the lock file — the workflow's core dependency never reached the agent. Recompiling undercopilotadds it, which brings two secrets into the lock manifest:SENTRY_ACCESS_TOKENSENTRY_OPENAI_API_KEYBoth come from the already-imported
shared/mcp/sentry.mdand are passed only to the read-only@sentry/mcp-serverstdio server. Both are already used bymcp-inspector,portfolio-analyst, andsmoke-otel-backends. No new actions, containers, or redirects; the agent job stays read-only with writes routed throughsafe-outputs.Not addressed
daily-security-red-team.mdstill usesengine: opencodeand will keep failing for the same reason. Separate workflow, separate failure issue — worth a follow-up.pr-sous-chefRun: https://github.com/github/gh-aw/actions/runs/35681273619