Deploy agent #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy agent | |
| # Deploy one agent from this repo to YOUR Agent Workforce workspace. | |
| # Full setup instructions: docs/SELF-DEPLOY.md | |
| # | |
| # Required config (Settings -> Environments -> New environment named "workforce" | |
| # -> Environment secrets): | |
| # WORKFORCE_WORKSPACE_ID your workspace id | |
| # WORKFORCE_WORKSPACE_TOKEN that workspace's token | |
| # | |
| # --- Why `workflow_dispatch` ONLY ------------------------------------------- | |
| # This repo is PUBLIC, so anyone can open a pull request from a fork. Do NOT add | |
| # `pull_request_target`, and do NOT add any trigger that runs a fork's code with | |
| # access to these secrets: a fork PR could then edit the deploy script (or any | |
| # file it runs) and read WORKFORCE_WORKSPACE_TOKEN straight out of the job. That | |
| # is a workspace takeover, not a CI inconvenience. `workflow_dispatch` can only | |
| # be started by someone with write access to the repo, from a ref in the repo. | |
| # If you fork this and want deploy-on-merge, add `push:` on your OWN default | |
| # branch — never a pull_request* trigger. | |
| # | |
| # --- Why a composite action and not a reusable workflow --------------------- | |
| # The steps live in .github/actions/deploy-agent (a composite action) rather | |
| # than in a `workflow_call` workflow. A job in a called workflow does not | |
| # resolve environment secrets even when it declares `environment:` itself, and | |
| # the caller cannot declare one alongside `uses:` — so the secrets arrive empty. | |
| # A composite action runs inside THIS job, so `environment: workforce` below | |
| # applies and the secrets resolve. Do not convert this into a reusable workflow. | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| agent: | |
| description: >- | |
| Agent to deploy (must be listed in scripts/deploy/agents.json). | |
| Connect the agent's providers FIRST in Workspace Integrations — | |
| e.g. askable-gtm needs Revternal, where you paste your Revternal API | |
| key. Providers hold their own credentials; never type a key below. | |
| required: true | |
| type: string | |
| agent-inputs: | |
| description: >- | |
| Optional persona inputs, one KEY=VALUE per line (e.g. SLACK_CHANNEL=C0123ABCD). | |
| Values typed here appear in the run log — for anything sensitive use the | |
| AGENT_INPUTS secret instead. | |
| required: false | |
| type: string | |
| dry-run: | |
| description: Print what would be deployed without deploying it | |
| required: false | |
| type: boolean | |
| default: false | |
| concurrency: | |
| group: deploy-agent-${{ inputs.agent }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| jobs: | |
| deploy: | |
| runs-on: ubuntu-latest | |
| # `environment:` MUST be on this job — it is what resolves the secrets below. | |
| environment: workforce | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| # This job only reads the tree; it never pushes. Don't leave the | |
| # checkout token in .git/config where any later step could read it. | |
| persist-credentials: false | |
| - uses: ./.github/actions/deploy-agent | |
| with: | |
| agent: ${{ inputs.agent }} | |
| dry-run: ${{ inputs.dry-run }} | |
| workspace-id: ${{ secrets.WORKFORCE_WORKSPACE_ID }} | |
| workspace-token: ${{ secrets.WORKFORCE_WORKSPACE_TOKEN }} | |
| # Stacked lowest-precedence first; the deploy script lets later lines | |
| # win. So: AGENT_INPUTS variable = your standing defaults, AGENT_INPUTS | |
| # secret = the ones that must stay masked in logs, dispatch box = a | |
| # per-run override. All three are optional. | |
| agent-inputs: | | |
| ${{ vars.AGENT_INPUTS }} | |
| ${{ secrets.AGENT_INPUTS }} | |
| ${{ inputs.agent-inputs }} |