You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Handoff docs. New docs/spec-sync-runbook.md covers the operational half that was only ever encoded in workflow files and Slack copy: the #ade-sdk-pipeline channel and its threading, what to do when new drift lands behind an open sync PR (merge vs close, and why), the aging nudge, the QA/release handoff after merge, the secrets a new owner must reissue, and known gaps.
CONTRIBUTING keeps the mechanism and links to it. One correction there: release-gate.sh is committed but not wired into release.yml, so the production gate is the e2e suite — the text claimed otherwise.
Operational guide split out from CONTRIBUTING (which keeps the mechanism):
the Slack channel carrying drift alerts and how its threading works, what to
do when new drift lands behind an open sync PR, the QA/release handoff after
merge, the secrets a new owner must reissue, and known gaps.
Also corrects CONTRIBUTING's release gate claim: release-gate.sh is committed
but not wired into release.yml, so the production gate is the e2e suite.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- V1's AI step has a shell and runs format/lint; only V2 is shell-less.
- Invented `client.v2` paths are caught by check-v2-paths in CI; scope the
by-hand check to V1 resources.
- SLACK_SPEC_SYNC_WEBHOOK is not a general fallback — the lifecycle workflow
(gate failures, aging, merged) passes only the bot token.
- The production key must be environment-only and branch-restricted to main,
and must NOT have required reviewers (release.yml blocks on that job).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A GitHub App installation token cannot be dropped into the existing secret without workflow changes: installation tokens expire after one hour and must be minted per run from App credentials. The same claim also appears in CONTRIBUTING.md, so both locations should explain the required token-generation step rather than promising a no-change replacement.
| `LANDINGAI_ADE_STAGING_APIKEY` | pr-gates `contract-tests` | Gated behind the **`spec-sync-contract`** Environment. Configure a **required reviewer** there — this job executes AI-authored code with the staging key in env. |
| `LANDINGAI_ADE_PRODUCTION_APIKEY` | `e2e-production.yml` (release gate 0) | **Environment secret on `production-e2e` only — do not also store it as a repo secret**, which every branch can read and which defeats the branch rule. Under that Environment's "Deployment branches and tags", restrict to **`main`**: that rule, not the workflow's `if`, is the real control — a `workflow_dispatch` runs the selected ref's copy of the workflow file, which could drop the `if`. Unlike the staging Environment, do **not** add required reviewers here: `release.yml` blocks on this job, so every release would pause for a manual approval. |
| `SLACK_BOT_TOKEN` | `.github/actions/slack-notify` | `xoxb-…`. Threading exists **only** on this path. Must be in `#ade-sdk-pipeline`. |
| `SLACK_SPEC_SYNC_WEBHOOK` | `spec-sync.yml` only | Incoming webhook, used only when the bot token is empty. Flat, no threading — and **not a general fallback**: `spec-sync-lifecycle.yml` (gate failures, aging nudge, PR merged) passes only the bot token, so a webhook-only setup silently loses those three messages. |
Not a secret but part of the handoff: the **required reviewer** on the `spec-sync-contract` Environment is a named person too (`production-e2e` deliberately has none — see its row above).
`production-e2e` Environments are named people too.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Handoff docs. New
docs/spec-sync-runbook.mdcovers the operational half that was only ever encoded in workflow files and Slack copy: the#ade-sdk-pipelinechannel and its threading, what to do when new drift lands behind an open sync PR (merge vs close, and why), the aging nudge, the QA/release handoff after merge, the secrets a new owner must reissue, and known gaps.CONTRIBUTING keeps the mechanism and links to it. One correction there:
release-gate.shis committed but not wired intorelease.yml, so the production gate is the e2e suite — the text claimed otherwise.Mirrored in
ade-typescript.