fix(#1382): skip Vertex credential mounts for OpenAI runs - #1502
Conversation
Assisted-by: Codex Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
Functional tests are runningAuthorization passed for this commit. See the Functional Tests workflow for results. |
PR Summary by QodoSkip Vertex credential mounts for OpenAI harness runs
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
Code Review by Qodo
1.
|
Assisted-by: Codex Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
…nai-host-files Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
waynesun09
left a comment
There was a problem hiding this comment.
Two review findings on the harness changes (inline below).
Assisted-by: Codex Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
Assisted-by: Codex Signed-off-by: Amos Mastbaum <amastbau@redhat.com>
|
via Codex review: Current-head re-review summary for
Still open: explicit human approval for protected harness changes, exact-head live regressions, and authorization-skipped hosted functional workloads. Assisted-by: Codex (OpenAI) |
|
@amastbau fullsend#7718 is now in the merge queue. I'm taking this PR to mergeable: I'll merge current agents main ( |
Assisted-by: Claude (fix, review) Signed-off-by: Wayne Sun <gsun@redhat.com>
Scribe's Drive access runs in the pre-script with its own credentials, so it does not depend on the inference provider. Keep scribe's openai provider as every other fleet harness has it; this PR only makes the six mounts optional. Assisted-by: Claude (fix, review) Signed-off-by: Wayne Sun <gsun@redhat.com>
|
@amastbau I'm done; the branch is yours again. Head is eb65587: a merge of current agents main, plus scribe put back to main's version. Scribe's Drive access runs in the pre-script with its own credentials, so it doesn't need to be Vertex-only. The diff is now the six |
Summary
Lets OpenAI-backed agents run on the six inference harnesses without a GCP credential file. Each
${GOOGLE_APPLICATION_CREDENTIALS}mount gets the existing provider-neutraloptional: true. No harness schema change.Coordination
Needs fullsend 114478fb6 or later (fullsend#7718, merged). That runner selects the provider per agent. On Vertex it prepares WIF on GitHub Actions and checks this optional mount before the pre-script. On an older runner, a Vertex run with
GOOGLE_APPLICATION_CREDENTIALSunset gets past the pre-script and fails Vertex auth inside the sandbox. Release builds fetch agents at their own tag, so this affects only dev builds from before #7718.Changes
optional: trueon the GCP credential mount in code, fix, prioritize, retro, review and triage.Validation
make lint: grade A, all checks passed.go test ./...passed.Live GitHub Actions runs on a disposable per-repo install. The triage harness was loaded by URL from this branch at 3171b0c (same harness content as this head), and the runner was fullsend at the #7718 head:
openai/gpt-5.6-lunasonnetLocal OpenShell 0.1.2 runs with this harness: pi on OpenAI with no GCP credentials ✅, pi on
xai-vertex/xai/grok-4.6with ADC ✅.Generated with Codex