Skip to content

fix(#1382): skip Vertex credential mounts for OpenAI runs - #1502

Merged
waynesun09 merged 8 commits into
fullsend-ai:mainfrom
amastbau:aisdlc-127/1382-openai-host-files
Oct 1, 2026
Merged

waynesun09 merged 8 commits into
fullsend-ai:mainfrom
amastbau:aisdlc-127/1382-openai-host-files

Conversation

@amastbau

@amastbau amastbau commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Lets OpenAI-backed agents run on the six inference harnesses without a GCP credential file. Each ${GOOGLE_APPLICATION_CREDENTIALS} mount gets the existing provider-neutral optional: true. No harness schema change.

Coordination

Needs fullsend 114478fb6 or later (fullsend#7718, merged). That runner selects the provider per agent. On Vertex it prepares WIF on GitHub Actions and checks this optional mount before the pre-script. On an older runner, a Vertex run with GOOGLE_APPLICATION_CREDENTIALS unset gets past the pre-script and fails Vertex auth inside the sandbox. Release builds fetch agents at their own tag, so this affects only dev builds from before #7718.

Changes

  • optional: true on the GCP credential mount in code, fix, prioritize, retro, review and triage.
  • Scribe is unchanged. Its Drive access runs in the pre-script with its own credentials.

Validation

  • make lint: grade A, all checks passed. go test ./... passed.

  • Live GitHub Actions runs on a disposable per-repo install. The triage harness was loaded by URL from this branch at 3171b0c (same harness content as this head), and the runner was fullsend at the #7718 head:

    Runtime and model GCP secrets Result
    pi, openai/gpt-5.6-luna none ✅ triage completed
    claude, sonnet WIF ✅ triage completed
  • Local OpenShell 0.1.2 runs with this harness: pi on OpenAI with no GCP credentials ✅, pi on xai-vertex/xai/grok-4.6 with ADC ✅.

Generated with Codex

Assisted-by: Codex
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
@amastbau
amastbau requested a review from a team as a code owner September 25, 2026 15:45
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Functional tests are running

Authorization passed for this commit. See the Functional Tests workflow for results.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Skip Vertex credential mounts for OpenAI harness runs

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Skip empty Vertex credential mounts during OpenAI runs in six fleet harnesses.
• Preserve required credentials for Vertex runs and Scribe’s Google Drive pre-script.
• Depend on Fullsend runner support for the new host-file annotation.
Diagram

graph TD
  H["Six harnesses"] --> C["Annotated mount"] --> R["Fullsend runner"] --> D{"OpenAI run?"}
  D -- "Yes" --> S["Skip empty source"]
  D -- "No" --> M["Require credential"]
  SC["Scribe harness"] --> M
Loading
High-Level Assessment

The targeted runner-supported annotation is the best approach. Separate OpenAI harness definitions would duplicate configuration, while making credentials universally optional would weaken Vertex validation; the current change preserves Vertex fail-fast behavior and intentionally excludes Scribe.

Files changed (6) +6 / -0

Bug fix (6) +6 / -0
code.yamlAllow OpenAI code runs without Vertex credentials +1/-0

Allow OpenAI code runs without Vertex credentials

• Marks the Google application credential mount as optional specifically for OpenAI code-agent runs. Vertex runs continue requiring the credential source.

harness/code.yaml

fix.yamlAllow OpenAI fix runs without Vertex credentials +1/-0

Allow OpenAI fix runs without Vertex credentials

• Adds provider-aware optional handling to the fix harness’s Google credential mount without changing required review inputs or Vertex behavior.

harness/fix.yaml

prioritize.yamlAllow OpenAI prioritization without Vertex credentials +1/-0

Allow OpenAI prioritization without Vertex credentials

• Annotates the prioritization harness’s Vertex credential mount so empty sources are skipped for OpenAI runs.

harness/prioritize.yaml

retro.yamlAllow OpenAI retrospectives without Vertex credentials +1/-0

Allow OpenAI retrospectives without Vertex credentials

• Makes the retrospective harness’s Google credential mount optional only when the runner uses OpenAI.

harness/retro.yaml

review.yamlAllow OpenAI reviews without Vertex credentials +1/-0

Allow OpenAI reviews without Vertex credentials

• Adds the OpenAI-specific optional annotation to the review harness’s Vertex credential mount while preserving Vertex requirements.

harness/review.yaml

triage.yamlAllow OpenAI triage without Vertex credentials +1/-0

Allow OpenAI triage without Vertex credentials

• Marks the triage harness’s Google credential mount as skippable for OpenAI-only execution.

harness/triage.yaml

@qodo-code-review

qodo-code-review Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Harness changes require human approval ✗ Dismissed
Description
The pull request modifies six files under the protected harness/ path to change credential-mount
behavior. These infrastructure changes require explicit human review even though the linked issue
and description explain the intended OpenAI-specific scope.
Code

harness/code.yaml[45]

+    optional_for_openai: true
Relevance

●●● Strong

Recent precedent confirms protected harness changes require explicit human approval; this finding
matches repository governance policy.

PR-#1313
PR-#1251

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
PR Compliance ID 1538392 requires a finding whenever protected governance or infrastructure paths
are modified; harness/ is explicitly listed as protected. The PR changes protected harness files
and provides issue #1382 plus an implementation explanation, so this is a justified protected-path
change requiring human approval.

harness/code.yaml[45-45]
harness/fix.yaml[55-55]
harness/prioritize.yaml[29-29]
harness/retro.yaml[29-29]
harness/review.yaml[36-36]
harness/triage.yaml[29-29]
Skill: pr-review


Grey Divider

Context sources
✅ Compliance rules (platform): 58 rules
✅ Skills: 4 invoked
  code-review
  code-implementation
  pr-review
  docs-review
✅ Cross-repo context — repo relationships
  ⚠️ Failed to retrieve: fullsend-ai/fullsend
Review mode: 🚀 Fast: This is a localized, repetitive YAML configuration change with six equivalent annotations and no new runtime logic, making it straightforward to verify in one light pass.

Grey Divider

Tip of the day
💡 Did you know, you can keep summaries lean with Findings visible per group, which tucks the rest behind a View link

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread harness/code.yaml Outdated
Assisted-by: Codex
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
…nai-host-files

Signed-off-by: Amos Mastbaum <amastbau@redhat.com>

@waynesun09 waynesun09 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two review findings on the harness changes (inline below).

Comment thread harness/code.yaml Outdated
Comment thread harness/code.yaml
Assisted-by: Codex
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
Assisted-by: Codex
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
@amastbau

Copy link
Copy Markdown
Contributor Author

via Codex review: Current-head re-review summary for 003877f1:

  • The description now matches the seven-file diff.
  • Six inference harnesses use generic host_files[].optional: true for the GCP credential mount.
  • Scribe's OpenAI provider is removed so Scribe remains Vertex-only.
  • Fullsend companion PR #7718 performs Vertex-only GCP setup and validates the optional mount before pre-script side effects.
  • No optional_for_openai schema is introduced.

Still open: explicit human approval for protected harness changes, exact-head live regressions, and authorization-skipped hosted functional workloads.

Assisted-by: Codex (OpenAI)

@waynesun09

Copy link
Copy Markdown
Member

@amastbau fullsend#7718 is now in the merge queue. I'm taking this PR to mergeable: I'll merge current agents main (providers/vertex-ai.yaml on this base still has _NOOP_VERTEX_AI, which OpenShell 0.1.2 rejects), review it and validate it live. My commits will go on top of 003877f without rewriting yours. Please hold pushes until I confirm here that I'm done.

Assisted-by: Claude (fix, review)
Signed-off-by: Wayne Sun <gsun@redhat.com>
Scribe's Drive access runs in the pre-script with its own credentials, so it
does not depend on the inference provider. Keep scribe's openai provider as
every other fleet harness has it; this PR only makes the six mounts optional.

Assisted-by: Claude (fix, review)
Signed-off-by: Wayne Sun <gsun@redhat.com>
@waynesun09

Copy link
Copy Markdown
Member

@amastbau I'm done; the branch is yours again. Head is eb65587: a merge of current agents main, plus scribe put back to main's version. Scribe's Drive access runs in the pre-script with its own credentials, so it doesn't need to be Vertex-only. The diff is now the six optional: true lines. All checks pass, including the functional tests (code, fix, retro, review, triage) and behaviour. The description has the live runs: pi on OpenAI with no GCP secrets, and claude on Vertex through WIF.

@waynesun09
waynesun09 added this pull request to the merge queue Oct 1, 2026
Merged via the queue into fullsend-ai:main with commit d8c8397 Oct 1, 2026
40 of 41 checks passed

This branch was successfully deployed

1 active deployment
dev — eb655875 Deployed Oct 1, 2026 by waynesun09 via behaviour #257
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants