4636 Commits

Author SHA1 Message Date
flux-bot
62b227bd2e chore(cassandra): automated image update 2026-08-07 17:59:54 +00:00
flux-bot
5ffebba63a chore(maintenance): automated image update 2026-08-07 17:16:38 +00:00
flux-bot
c9b40309bd chore(cassandra): automated image update 2026-08-07 17:04:39 +00:00
flux-bot
4ccd3d85c6 chore(cassandra): automated image update 2026-08-07 17:00:38 +00:00
flux-bot
fe54653c18 chore(cassandra): automated image update 2026-08-07 16:56:47 +00:00
flux-bot
6a514a9885 chore(cassandra): automated image update 2026-08-07 16:56:38 +00:00
flux-bot
1919326513 chore(maintenance): automated image update 2026-08-07 13:41:09 +00:00
flux-bot
0767822701 chore(maintenance): automated image update 2026-08-07 13:41:01 +00:00
flux-bot
361baa37ea chore(maintenance): automated image update 2026-08-07 13:39:01 +00:00
flux-bot
4fe4e8d075 chore(cassandra): automated image update 2026-08-07 13:37:16 +00:00
flux-bot
59173a3abf chore(maintenance): automated image update 2026-08-07 13:37:05 +00:00
flux-bot
e949efaad2 chore(cassandra): automated image update 2026-08-07 13:34:00 +00:00
flux-bot
1ed2ba1ebc chore(cassandra): automated image update 2026-08-07 13:29:11 +00:00
flux-bot
2b1b2f9198 chore(cassandra): automated image update 2026-08-07 13:28:58 +00:00
flux-bot
a4a23609e6 chore(cassandra): automated image update 2026-08-07 12:33:50 +00:00
flux-bot
075689ba98 chore(cassandra): automated image update 2026-08-07 12:29:46 +00:00
flux-bot
015fd3b0d5 chore(cassandra): automated image update 2026-08-07 12:25:57 +00:00
flux-bot
b550271a4a chore(cassandra): automated image update 2026-08-07 12:25:47 +00:00
flux-bot
35b064f3bc chore(cassandra): automated image update 2026-08-07 11:18:36 +00:00
flux-bot
0f16a845f0 chore(cassandra): automated image update 2026-08-07 11:15:32 +00:00
flux-bot
facd720fde chore(cassandra): automated image update 2026-08-07 11:11:34 +00:00
flux-bot
1a2ff71f63 chore(cassandra): automated image update 2026-08-07 11:10:44 +00:00
Brad Stein
4e8edf9fac Add SCM poll trigger to cassandra Jenkins job
The cassandra pipelineJob had no trigger, so Gitea's notifyCommit
webhook found no matching job and pushes only built when started
manually. Poll every 5 minutes like lesavka/typhon so pushes build
within one poll cycle and the webhook race disappears.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 06:52:27 -03:00
flux-bot
785e9bcf7d chore(maintenance): automated image update 2026-08-07 08:32:54 +00:00
flux-bot
1b48914a9b chore(maintenance): automated image update 2026-08-07 08:11:31 +00:00
jenkins
0855e38c0f feat(ariadne): turn on suggested fixes for unpatchable findings
Most of the SonarQube backlog is refactors too diffuse for an anchored patch,
so without this the majority of what static analysis knows never reaches a
maintainer. Deduped on the rule like the pull requests, so one root cause
yields one issue.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 05:00:25 -03:00
jenkins
10a629d5a7 feat(ariadne): sweep seven projects, and stop advertising the wrong model
The sweep covered four projects because only four had a write allowlist.
ananke (Go, cmd/ and internal/), pegasus (Go backend, TS frontend) and
atlasbot (Python) all have SonarQube projects and mapped repositories; they
were excluded only for want of prefixes and suffixes, which are now set from
each repository's actual layout.

The per-sweep ceiling rises to seven, one per project. With rule-level dedupe
a project stops producing proposals once every rule it has is already under
review, so this is a ceiling rather than a rate - the backlog cannot become a
queue nobody drains.

The Hermes deployment annotation still advertised gpt-5.6-terra as primary.
The config has had claude-opus-5 as default and primary for some time, so the
annotation was telling operators the wrong thing about which model made a
decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 04:45:15 -03:00
flux-bot
5db36f9d78 chore(cassandra): automated image update 2026-08-07 06:29:55 +00:00
flux-bot
1ce9c6f383 chore(cassandra): automated image update 2026-08-07 06:25:56 +00:00
flux-bot
372bd9324f chore(cassandra): automated image update 2026-08-07 06:22:13 +00:00
flux-bot
9233e0d1a4 chore(cassandra): automated image update 2026-08-07 06:21:58 +00:00
flux-bot
01b2814889 chore(maintenance): automated image update 2026-08-07 05:15:42 +00:00
flux-bot
1a183d6075 chore(cassandra): automated image update 2026-08-07 05:03:24 +00:00
flux-bot
3288c6e2e9 chore(cassandra): automated image update 2026-08-07 05:03:16 +00:00
flux-bot
d429ab3c89 chore(maintenance): automated image update 2026-08-07 04:54:17 +00:00
flux-bot
8e6977adc2 chore(maintenance): automated image update 2026-08-07 03:52:04 +00:00
flux-bot
32f548a462 chore(maintenance): automated image update 2026-08-07 03:41:56 +00:00
flux-bot
770a7c05bc chore(maintenance): automated image update 2026-08-07 03:25:49 +00:00
flux-bot
17dd91814e chore(maintenance): automated image update 2026-08-07 03:16:02 +00:00
jenkins
8c47328b23 feat(ariadne): sweep four services, and link proposals to the finding
Only one pull request appeared because the sweep was scoped to one project at
one proposal per hour - a throttle I set deliberately while nothing had ever
run, not a limit of the mechanism. It has now run, so it widens to every
project whose job also has a write allowlist: ariadne, metis, soteria and
bstein-dev-home. The rest are left out because without allowed prefixes
nothing is patchable, and a sweep would spend a SonarQube call to discover it
has nowhere to write.

Still one proposal per project per hour. The backlog is 139 findings on
Ariadne alone; the constraint that matters is how many pull requests a person
will actually read, not how many the mechanism could open.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 00:06:33 -03:00
flux-bot
e1be7ef351 chore(maintenance): automated image update 2026-08-07 02:56:19 +00:00
flux-bot
15e04f75bb chore(maintenance): automated image update 2026-08-07 02:27:09 +00:00
jenkins
1bfb29388a feat(ariadne): link pull requests to the Hermes run that wrote them
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 23:17:06 -03:00
flux-bot
de2d680f17 chore(cassandra): automated image update 2026-08-07 02:02:23 +00:00
flux-bot
88b81c1ba7 chore(cassandra): automated image update 2026-08-07 01:59:02 +00:00
flux-bot
b29f9ec60c chore(cassandra): automated image update 2026-08-07 01:55:00 +00:00
flux-bot
7c4662a095 chore(cassandra): automated image update 2026-08-07 01:54:22 +00:00
jenkins
00af41891c fix(ariadne): read the SonarQube token from a path Ariadne can already reach
The sweep's token was injected from kv/data/atlas/quality/sonarqube-oidc,
which the maintenance role cannot read. I granted that path on the live policy
and verified the read, but the grant was reverted by whatever manages Vault
policy, and the next rollout wedged: vault-agent-init retries a 403 forever, so
the pod never initializes and the Deployment cannot roll. The old replica kept
serving, which is the only reason this was not an outage.

A template block that depends on a grant outside this repository is the actual
defect. The token now lives beside Ariadne's other credentials in
kv/data/atlas/maintenance/ariadne-db - a path its role has always been able to
read - so no policy change is needed and nothing outside this repo can revoke
it. Existing keys at that path were merged, not replaced.

Guarded with an if, so a deployment whose secret predates the key renders an
empty value and starts normally instead of blocking on a missing field. The
sweep then reports an empty token and skips, which is the right failure: no
sweep is much better than no Ariadne.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 22:42:23 -03:00
flux-bot
542ccfae6c chore(maintenance): automated image update 2026-08-07 01:40:41 +00:00
flux-bot
e78edf213f chore(maintenance): automated image update 2026-08-07 01:38:08 +00:00