Skip to content

docs(agents): Anthropic API labels and the workflow-secrets lint plan text - #2178

Merged
Smana merged 4 commits into
mainfrom
docs/agent-factory-followups
Oct 3, 2026
Merged

Smana merged 4 commits into
mainfrom
docs/agent-factory-followups

Conversation

@Smana

@Smana Smana commented Oct 2, 2026

Copy link
Copy Markdown
Owner

What

Two follow-ups from the 2026-10-02 external review (#2173) — R13 (the diagrams still present Bedrock/Vertex as the internal provider) and R01 (the SP3 plan's workflow-secrets lint text does not implement its own contract) — plus the two spec sentences the same review flagged as stale.

R13 — the internal provider is the Anthropic API (direct)

Per ADR-0054, the internal model provider relabels from the per-cloud Bedrock/Vertex story to the Anthropic API (direct):

  • docs/architecture/agent-factory.drawio — the internal-data node now reads Anthropic API (direct) · internal data · gateway-held key; Bedrock and Vertex collapse into one optional node (optional, per cloud), so no node presents either as the internal provider. The Bedrock mark is replaced by the established Claude mark; the collapsed node drops its single-product icon rather than assert the wrong thing.
  • docs/architecture/ai-platform.drawio (page 2) — the Claude gateway box's sub-line becomes Anthropic API (direct) (bold "Claude" and its mark stay; the model is still Claude).
  • The agent-factory.svg alt text follows; gateways.md and status.md already carry the ADR-0054 wording (verified, unchanged).
  • Both svgs re-exported with the pinned drawio (30.3.6); normalized diffs show only the label/icon/restyle changes.

R01 — the SP3 plan's workflow-secrets lint text

docs/superpowers/plans/2026-09-27-agent-dark-factory-plan.md, Task 6.3:

  • Step 3 script block now implements the write-permission allowlist the task's Interfaces bullet specifies: sarif-upload (security-events), render-diff-comment (pull-requests), build-and-push (packages, security-events), and notify-main-broken: issues recorded as a push-gated exception (its if: pins github.event_name == 'push', so the write never coincides with PR code). Allowlisted jobs that run PR code — a run: step or a checkout of the PR head — fail the lint.
  • Step 1 test block gains the matching fixtures: workflow-level write, unlisted job-level write, and the push-gated exception both ways (gated passes, ungated fails).
  • Extraction-proofed: both blocks pulled verbatim from the plan and run — the test passes (exit 0) and shellcheck is clean, where the pre-fix extraction failed 4 assertions.

Stale spec sentences

  • SP1 spec T13 — drops the trailing "until that ci.yaml fix lands" clause; the fix landed in fix(ci): scope write permissions to jobs that run no PR code #2171 (security-events: write is job-level on sarif-upload only, confirmed against the tree).
  • SP3 spec phase-ordering row — phase 9's backend is the Anthropic API via the agentgateway migration phase I (ADR-0054), not "SP4's Bedrock backend".

Verification

Run in the worktree after the commits:

./scripts/ci/validate-links.sh        # all relative Markdown links resolve (0 allowlisted) — exit 0
./scripts/ci/validate-doc-claims.sh   # all 32 claims match (57 page checks) — exit 0
./scripts/ci/verify-doc-paths.sh      # every backticked repo path exists — exit 0

Detail and review evidence: .superpowers/sdd/2026-09-27-agent-dark-factory-plan/f24-docs-report.md in the o1-agent-observability worktree (branch fix/ci-image-build-split in the same SDD stream carries the build-and-push split this plan's lint anticipates — see its own PR).

Smana added 3 commits October 2, 2026 23:22
…finish the R01 plan text

Deferred review follow-ups (external review R13, R01).

- agent-factory.drawio: no node presents Bedrock or Vertex as the internal
  provider (ADR-0054). The internal default is the Anthropic API, direct,
  with a gateway-held key; Bedrock and Vertex AI are optional per cloud.
  The Bedrock mark becomes the Claude mark from icons/, and the optional
  box goes plain — one mark cannot label two products.
- ai-platform.drawio (gateways page): the Claude box names the Anthropic
  API (direct) instead of Bedrock · Vertex AI.
- agents/_index.md: the agent-factory diagram alt text follows the labels.
- SP3 plan Task 6.3: the test-workflow-secrets block gains the R01
  fixtures the Interfaces bullet already specifies — a workflow-level
  write and an unlisted job holding write both fail, naming file and
  permission/job.
- SP1 spec T13: the R01 residual is stale — security-events: write has
  lived only on sarif-upload since 04d7f00 (#2171).
- SP3 spec phase table: phase 6 waits on the Anthropic API backend
  (agentgateway migration phase I, ADR-0054), not SP4's Bedrock backend.

SVGs regenerated (export-diagrams.sh, pinned drawio 30.3.6);
ci-pipeline.svg churned unrelatedly and was restored.
…llowlist

Review fix (round 1, Important): the Step 1 R01 fixtures demand
write-permission parsing the Step 3 implementation block never had, so an
executor copying it verbatim could not make Step 4 pass.

check-workflow-secrets.sh now implements what the task's Interfaces bullet
specifies, on top of the unchanged T8 secrets check:

- workflow-level write in a pull_request/pull_request_target workflow fails,
  naming file and permission;
- a job-level write outside the script's own allowlist fails, naming file
  and job (sarif-upload: security-events, render-diff-comment:
  pull-requests, build-and-push: packages, security-events);
- an allowlisted job with a actions/checkout of the PR head or any run:
  step fails. pull_request's default checkout ref is the PR merge commit;
  pull_request_target's is the base, so only an explicit pull_request ref
  counts there.

The allowlist lives in the script (a gate path, R17). build-and-push's
split out of the PR path is its own fix(ci) PR; until it lands the lint
flags the job, and the entry stays so the split cannot quietly widen it
again.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔍 Rendered manifest diff — this PR vs main (desired state)

No changes to the rendered desired state. ✅

@Smana
Smana merged commit e38da25 into main Oct 3, 2026
14 checks passed
@Smana
Smana deleted the docs/agent-factory-followups branch October 3, 2026 07:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant