Skip to content

Stabilize Forge OpenShell evals for full brief publication - #105

Open
tarun-etikala wants to merge 2 commits into
RHEcosystemAppEng:mainfrom
tarun-etikala:forge/eval-reliability-main
Open

tarun-etikala wants to merge 2 commits into
RHEcosystemAppEng:mainfrom
tarun-etikala:forge/eval-reliability-main

Conversation

@tarun-etikala

Copy link
Copy Markdown

Summary

  • Port verified OIDC token refresh, USER.md fixture, pinned SAW image, and published_brief gate onto main so clean-source OpenShell runs publish a full brief.json.
  • Add same-namespace NetworkPolicy templates and docs that match the canonical Pipeline name abevalflow-pipeline-openshell or app.kubernetes.io/part-of=abevalflow, preventing gateway preflight timeouts when Pipeline copies use other names.
  • Label the OpenShell Pipeline/PipelineRun example with app.kubernetes.io/part-of=abevalflow.

Why

In forge-nommen, clean upstream main failed evaluate preflight when PipelineRuns referenced renamed Pipeline copies that did not match CI NetworkPolicies (tekton.dev/pipeline=abevalflow-pipeline-openshell). Separately, upstream main lacked the publication gate / fixture / OIDC refresh needed for reliable full-brief runs.

Test plan

  • Apply NetworkPolicies in forge-nommen and confirm gateway TCP works for pods labeled with the canonical pipeline name / part-of
  • Two PipelineRuns with this branch + harness reliability branch complete prepare → evaluate → analyze → store → cleanup
  • Morning-briefing publishes brief.json with scope: full and passes published_brief
  • Usable logs/artifacts retained on the PipelineRun

Companion harness: https://github.com/tarun-etikala/agent-eval-harness/tree/forge/eval-reliability-main (GuyZivRH/agent-eval-harness#9 merged onto main)

Made with Cursor

tarun-etikala and others added 2 commits October 2, 2026 10:13
Port the verified OIDC refresh, USER.md fixture, pinned SAW image, and
published_brief gate onto main. Add same-namespace NetworkPolicy templates
that match the canonical Pipeline name or app.kubernetes.io/part-of=abevalflow
so ad-hoc Pipeline copies no longer time out on gateway preflight.

Co-authored-by: Cursor <cursoragent@cursor.com>
Depth-1 --branch fails for bare SHAs; fall back to full clone + checkout
so clean-source pins work the same way as the submission revision.

Co-authored-by: Cursor <cursoragent@cursor.com>
@tarun-etikala

Copy link
Copy Markdown
Author

Verification in forge-nommen (2026-10-02)

Upstream SHAs recorded

  • agentic_eval_flow main: 807c623353a812045d73346daac8bf02c1e1c2f4
  • agent-eval-harness main: 0aa3c91946996261d0af32acc36f4996bbae9b07

Clean upstream main (aeh-main-clean-repro2-hpj6r): gateway preflight OK after NP fix, but evaluate fails with Forge image workspace initialization failed (harness main lacks brief-reader/gateway fixes).

Two reliability runs (this branch + harness forge/eval-reliability-main):

  • aeh-reliability-8nndz — Succeeded (prepare→evaluate→analyze→store→cleanup); published_brief 100%; scope=full; mean reward 0.70; artifacts in s3://ab-eval-reports/20261002_142149_openclaw-forge_aeh-reliability-8nndz/
  • aeh-reliability-52ffv — Succeeded; published_brief 100%; scope=full; mean reward 0.675; artifacts in s3://ab-eval-reports/20261002_142155_openclaw-forge_aeh-reliability-52ffv/

Installed abevalflow-pipeline-openshell + Tasks in forge-nommen from this tip; applied config/forge-saw/networkpolicy-ci-openshell.yaml and broadened existing CI NetworkPolicies to also match app.kubernetes.io/part-of=abevalflow.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants