-
Notifications
You must be signed in to change notification settings - Fork 2
108 lines (103 loc) · 5.33 KB
/
Copy pathdeploy-agent.yml
File metadata and controls
108 lines (103 loc) · 5.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
name: Deploy agent
# Deploy one agent from this repo to YOUR Agent Workforce workspace.
# Full setup instructions: docs/SELF-DEPLOY.md
#
# Required config (Settings -> Environments -> New environment named "workforce"):
# WORKFORCE_WORKSPACE_ID your CLOUD workspace id — a UUID that identifies
# the workspace, not a credential (not the rw_…
# relaycast id). Set it as an
# Environment VARIABLE (preferred, stays readable
# in logs) or an Environment SECRET; either is
# read, so an existing secret keeps working.
# WORKFORCE_WORKSPACE_TOKEN your cloud access token (Environment SECRET —
# sensitive; grants write access to the workspace;
# expires — not the rk_… key from workspaces.json)
#
# --- Why `workflow_dispatch` ONLY -------------------------------------------
# This repo is PUBLIC, so anyone can open a pull request from a fork. Do NOT add
# `pull_request_target`, and do NOT add any trigger that runs a fork's code with
# access to these secrets: a fork PR could then edit the deploy script (or any
# file it runs) and read WORKFORCE_WORKSPACE_TOKEN straight out of the job. That
# is a workspace takeover, not a CI inconvenience. `workflow_dispatch` can only
# be started by someone with write access to the repo, from a ref in the repo.
# If you fork this and want deploy-on-merge, add `push:` on your OWN default
# branch — never a pull_request* trigger.
#
# --- Why a composite action and not a reusable workflow ---------------------
# The steps live in .github/actions/deploy-agent (a composite action) rather
# than in a `workflow_call` workflow. A job in a called workflow does not
# resolve environment secrets even when it declares `environment:` itself, and
# the caller cannot declare one alongside `uses:` — so the secrets arrive empty.
# A composite action runs inside THIS job, so `environment: workforce` below
# applies and the secrets resolve. Do not convert this into a reusable workflow.
on:
workflow_dispatch:
inputs:
agent:
description: >-
Agent to deploy (must be listed in scripts/deploy/agents.json).
Connect the agent's providers FIRST in Workspace Integrations —
e.g. askable-gtm needs Revternal, where you paste your Revternal API
key. Providers hold their own credentials; never type a key below.
required: true
type: string
agent-inputs:
description: >-
Optional persona inputs, one KEY=VALUE per line (e.g. SLACK_CHANNEL=C0123ABCD).
Values typed here appear in the run log — for anything sensitive use the
AGENT_INPUTS secret instead.
required: false
type: string
harness-source:
description: >-
Which stored credential to use for the agent's harness: managed, byok,
oauth, or plan. Leave empty to use the WORKFORCE_DEPLOY_HARNESS_SOURCE
Environment variable, or to let the CLI resolve it. Use "oauth" when
the harness was connected with a setup token.
required: false
type: string
dry-run:
description: Print what would be deployed without deploying it
required: false
type: boolean
default: false
concurrency:
group: deploy-agent-${{ inputs.agent }}
cancel-in-progress: false
permissions:
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
# `environment:` MUST be on this job — it is what resolves the secrets below.
environment: workforce
steps:
- uses: actions/checkout@v4
with:
# This job only reads the tree; it never pushes. Don't leave the
# checkout token in .git/config where any later step could read it.
persist-credentials: false
- uses: ./.github/actions/deploy-agent
with:
agent: ${{ inputs.agent }}
dry-run: ${{ inputs.dry-run }}
# Accept the id as EITHER an Environment variable or an Environment
# secret. It is a UUID, not a credential, so a variable is the right
# home and keeps it readable in run logs — but it lived in secrets
# before, every existing setup and every fork put it there, and a
# workflow that silently reads empty from the other place costs an
# operator a failed deploy and a confused hour. `||` takes the first
# non-empty, so both work and neither needs migrating.
# Dispatch box wins, then the Environment variable, then empty (the
# CLI resolves it). Same precedence as the other stacked inputs.
harness-source: ${{ inputs.harness-source || vars.WORKFORCE_DEPLOY_HARNESS_SOURCE }}
workspace-id: ${{ vars.WORKFORCE_WORKSPACE_ID || secrets.WORKFORCE_WORKSPACE_ID }}
workspace-token: ${{ secrets.WORKFORCE_WORKSPACE_TOKEN }}
# Stacked lowest-precedence first; the deploy script lets later lines
# win. So: AGENT_INPUTS variable = your standing defaults, AGENT_INPUTS
# secret = the ones that must stay masked in logs, dispatch box = a
# per-run override. All three are optional.
agent-inputs: |
${{ vars.AGENT_INPUTS }}
${{ secrets.AGENT_INPUTS }}
${{ inputs.agent-inputs }}