Skip to content

Refresh OpenShell CI token during long evals - #104

Draft
tarun-etikala wants to merge 2 commits into
RHEcosystemAppEng:mainfrom
tarun-etikala:codex/openshell-ci-gateway-auth
Draft

tarun-etikala wants to merge 2 commits into
RHEcosystemAppEng:mainfrom
tarun-etikala:codex/openshell-ci-gateway-auth

Conversation

@tarun-etikala

@tarun-etikala tarun-etikala commented Oct 2, 2026 •

Copy link
Copy Markdown

Long Forge evaluations can outlive the roughly five-minute OpenShell OIDC client-credentials token. The first sandbox starts, but later artifact downloads and the next case fail with ExpiredSignature because the CLI has no refresh token.

Refresh the CLI token cache every two minutes for the lifetime of the evaluate step. Each replacement is atomic, and the temporary response and cache stay private. This leaves the agent and scoring configuration unchanged.

Validation: YAML and shell syntax checks, plus 16 focused pipeline tests passed. In a clean-source run with Harness #9 and Flow #101, both cases completed after the refresh with no ExpiredSignature; the older image still failed the separate published_brief gate. With the fixture/image change in Flow #103, two clean-source runs succeeded all five Tasks and passed publication: run 1, run 2. The second run's first case lasted about 13 minutes and the next sandbox still started successfully.

Companion changes: Harness #9 and Flow #101/#103.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant