Skip to content

Daily Autohealing Report — 2026-09-29 #1459

Description

@fro-bot

Daily Autohealing Report — 2026-09-29 (UTC)

Errored PRs

None. Only one open PR (#1449, changeset-release/main, authored by mrbro-bot[bot]) exists and all its checks (Lint, Type Check, Test, Package smoke, CodeQL, Renovate) are passing.

Security

None. gh api repos/marcusrbrown/infra/dependabot/alerts returned HTTP 200 with zero open alerts. No security-labeled or vulnerable-dependency PRs are open.

Code Quality & Repo Hygiene

Check Result Action
Stale TODOs 0 found None — full-repo scan (excluding node_modules/.git/dist/.cache) found no code-level TODO/FIXME/HACK annotations; only matches were this workflow's own prompt text and doc references about an unrelated cross-repo TODO marker
Convention drift ✅ Clean Mechanical structural checks are gated by ESLint + packages/cli/src/conventions.test.ts, both passing
AGENTS.md accuracy ✅ Current All apps/* and packages/* directories match root AGENTS.md STRUCTURE; per-package AGENTS.md command trees match actual source layout
Code-aware drift ✅ Clean Spot-checked gateway (WORKSPACE_PERMISSION_POLICY, REQUIRED_ENV_VARS, egress host allowlist), dashboard (compose hardening block), cliproxy (config.yaml skip-if-exists), and CLI (x-management-key header, multiselect import) — all match documented behavior

Workflow Integrity

Check Result Action
SHA pinning ✅ Clean All 77 third-party uses: refs across 20 workflow files pinned to full commit SHAs with trailing # vX.Y.Z/# name@X.Y.Z comments
Least privilege ✅ Clean Workflow-level permissions: mostly contents: read; elevated scopes (packages: write, id-token: write, issues: write) scoped to the specific jobs that need them. scorecard.yaml's workflow-level read-all is overridden by a minimal job-level block per this repo's own permissions-replacement convention
Fork/secret boundary ✅ Clean renovate-changesets.yaml (pull_request_target) gates on head.repo.fork == false + actor allowlist before checkout; fro-bot.yaml's comment-triggered job always checks out default branch first and only resolves a trusted head SHA for same-repo PRs
Cross-org secrets: inherit ✅ Clean No secrets: inherit usage anywhere; the two bfra-me/.github reusable-workflow calls and one reusable action call pass secrets explicitly
Deploy router/approval gates ✅ Intact deploy.yaml fans out to 7 per-app reusable workflows, each with its own environment: block (keeweb/cliproxy/gateway/umami/vpn/dashboard/broker) gating required-reviewer approval

Quality Gates

Check Result Action
Lint ✅ Clean 0 errors, 73 pre-existing warnings (no-console in server/CLI logging code, no-non-null-assertion in test files) — no failures to fix
Type check ✅ Clean bunx tsc --noEmit — no errors
Tests ✅ Clean bun test --recursive: 3248 pass, 1 skip, 0 fail across 103 files, 8579 expect() calls
KeeWeb build ✅ Pass DROPBOX_APP_SECRET=placeholder bun run --cwd apps/keeweb build succeeded; dist/ contains index.html and config.json

Developer Experience

  • No fixes needed this run — lint/type-check/tests are all clean; no PR opened.

Deploy Pipeline Health

App Check Status Details
keeweb Last deploy-keeweb run ✅ Pass run 26855044047 (2026-06-02, last time apps/keeweb/** changed on main)
keeweb kw.igg.ms reachable ✅ 200 curl HTTP 200
keeweb Env secrets ✅ Set DEPLOY_SSH_KEY, DROPBOX_APP_SECRET present in keeweb environment
keeweb Host keys ✅ Current box.heatvision.co ed25519/ecdsa/rsa entries present
cliproxy Last deploy-cliproxy run 🚫 Stranded (queued) #1437 updated — oldest run 35942067776 (v7.3.16) still waiting ~5d; 3 intermediate bumps auto-cancelled; newest 36306810708 (v7.3.20) pending. Prod still on v7.3.15
cliproxy cliproxy.fro.bot reachable ✅ 401 Proxy up, auth enforced (expected)
cliproxy Env secrets ✅ Set CLIPROXY_SSH_KEY, CLIPROXY_MANAGEMENT_KEY, CLIPROXY_DOMAIN present
cliproxy Host keys ✅ Current cliproxy.fro.bot domain + droplet-IP entries present
cliproxy Auth monitor scheduled run ✅ Healthy run 36517298629 (2026-09-29T03:28Z) — probe=healthy reason=ok. No stale cliproxy-auth-monitor issue open (both prior instances closed)
gateway Last deploy-gateway run 🚫 Stranded (queued) #1412 updated — 36056140040 still waiting ~4d7h; newest 36480447585 pending behind it. Prod still on run 35648619590
gateway Env secrets ✅ Set All 9 required vars present (GATEWAY_SSH_KEY, GATEWAY_HOST, DISCORD_*, AWS_*, S3_*) plus operator-auth/push secrets
gateway Host keys ✅ Current gateway.fro.bot domain + droplet-IP entries present
umami Last deploy-umami run ✅ Pass run 35201011582 (2026-09-17, deploy-umami success)
umami metrics.fro.bot reachable ✅ 200 curl HTTP 200 on /api/heartbeat
umami Env secrets ✅ Set UMAMI_SSH_KEY, UMAMI_DOMAIN, UMAMI_APP_SECRET, UMAMI_DB_PASSWORD, UMAMI_ADMIN_PASSWORD present
umami Host keys ✅ Current metrics.fro.bot domain + droplet-IP entries present
dashboard Last deploy-dashboard run 🚫 Stranded (queued) #1440 updated — now 5 versions behind: prod on 2026.09.19; versions 2026.09.20 (still waiting) through 2026.09.24 (pending, newest) never reached success (3 intermediate cancelled)
dashboard dashboard.fro.bot/api/healthz reachable ✅ 200 curl HTTP 200
dashboard Env secrets ✅ Set All 8 required vars present
dashboard Host keys ✅ Current dashboard.fro.bot domain + droplet-IP entries present
vpn Last deploy-vpn run 🚫 Stranded (queued) #1436 updated — same queue as gateway (36056140040 waiting, 36480447585 pending)
vpn Env secrets ✅ Set VPN_SSH_KEY, VPN_HOST, VPN_PEERS present
vpn Host keys ✅ Current Hashed static-IP entries for 52.208.116.13 present
broker Last deploy-broker run ✅ Pass run 34741248035 (2026-09-13, deploy-broker success)
broker broker.fro.bot/healthz reachable ✅ 200 curl HTTP 200
broker Env secrets/variable ✅ Set BROKER_SSH_KEY, BROKER_HOST, CLIPROXY_MANAGEMENT_KEY secrets + BROKER_AUD variable present
broker Host keys ✅ Current broker.fro.bot domain + droplet-IP entries present

Stranded-deploy note: gateway, vpn, cliproxy, and dashboard are all parked behind their required_reviewers approval gates with growing unactioned queues (dashboard now 5 versions behind). This is intentional gate behavior, not a bug — existing trackers #1412, #1436, #1437, #1440 were updated in place this run with the latest queue state. No approvals or deploys were performed.

Live Site Review

Check Status Details
Page load ✅ OK HTTP 200; console confirms App started in 1047ms
App init ✅ Rendered Launcher UI (Open/New/Demo/More) rendered immediately, no stuck spinner
Dropbox option visible ✅ Yes Collapsed under More by default (expected); visible alongside WebDAV/Google Drive/OneDrive after expanding
Console errors ✅ None Only benign log/info entries; zero error/warning entries; no requests to Dropbox API endpoints on page load
Service worker ✅ Registered navigator.serviceWorker.getRegistrations() confirms active registration scoped to https://kw.igg.ms/
Security headers ✅ Present content-security-policy, x-content-type-options, x-frame-options, strict-transport-security, referrer-policy all present
Mobile layout (375px) ✅ OK No horizontal overflow (scrollWidth === clientWidth === 375); all controls remained visible/clickable

No issues filed — every check passed on the first pass.

Cross-Project Intelligence (Inbound)

Baseline: @bfra.me/eslint-config@0.54.0, @bfra.me/prettier-config@0.16.13, @bfra.me/tsconfig@0.13.2, fro-bot/agent@v0.117.0. All six focus repos were reachable; none is ahead of infra on @bfra.me config versions or fro-bot/agent (sparkle/gpt/renovate-config match infra's fro-bot/agent@v0.117.0; containers/copiloting are behind).

Repo Finding Actionable for infra? Priority
sparkle regenerate-docs.yaml auto-detects source changes via path filters, rebuilds generated docs, diffs, and opens a bot PR only when output changed — a tighter, push-triggered mechanism than relying on the daily autoheal's category-3 sweep to catch AGENTS.md drift once a day. Model a push-triggered, path-filtered workflow around the existing generating-project-docs skill that opens a PR on detected drift. Low

Checked with nothing actionable: containers (only behind on prettier-config/fro-bot-agent, no transferable tooling), gpt (Vitest/Playwright/Lighthouse don't map — infra has no in-repo frontend UI source), copiloting (all configs well behind infra), .github (no package.json; main.yaml uses an older prettier-action pattern than infra's own flat-config lint setup). Note: infra already runs its own CodeQL (codeql.yaml, javascript-typescript, passing) and Scorecard (scorecard.yaml) workflows, so no gap exists there relative to renovate-config's setup.

Progressive Improvement

  1. Extend the "fail-closed on stale dispatches" guard beyond dashboard. Evidence: ci: fail closed on stale dashboard dispatches #1254 already implements auto-cancel-on-newer-dispatch for dashboard, yet Gateway deploy awaiting manual approval since 2026-09-21T20:02Z (now 2 runs queued) #1412/VPN deploy awaiting manual approval since 2026-09-24T20:37Z (run 36056140040) #1436/CLIProxy deploy awaiting manual approval since 2026-09-24T01:14Z (2 runs queued) #1437/Dashboard deploy awaiting manual approval since 2026-09-23T22:49Z (2 runs queued) #1440 show the oldest queued run in each app's approval gate can still sit unactioned for 4–5+ days with no escalation beyond the daily autoheal narrative. Value: bounds production/main drift (dashboard is now 5 versions behind). Effort/risk: Medium — purely additive (a time-threshold notification, not an auto-approval), but requires editing .github/workflows/deploy-*.yaml, which is outside this run's write scope (workflow files are report-only for autoheal). Adoption path: a human-directed follow-up PR adding a scheduled check that pings Discord/opens-once when a waiting deploy run exceeds e.g. 48h, without touching the approval gate itself.
  2. Adopt a docs-drift-on-push workflow modeled on sparkle's regenerate-docs.yaml. Evidence: today's category-3 sweep found AGENTS.md accurate, but that's only checked once daily; a path-filtered, diff-gated PR workflow (see Cross-Project Intelligence above) would catch drift the moment a relevant path changes rather than up to 24h later. Effort/risk: Low — additive workflow, PR-only, no impact on existing gates. Adoption path: wire the existing generating-project-docs skill into a new push-triggered workflow scoped to apps/**/AGENTS.md-adjacent paths.

Agent-Ready Notes

  1. Outcome: Bound the age of unactioned deploy-approval queues without weakening the required-reviewer gate. Evidence: Gateway deploy awaiting manual approval since 2026-09-21T20:02Z (now 2 runs queued) #1412, VPN deploy awaiting manual approval since 2026-09-24T20:37Z (run 36056140040) #1436, CLIProxy deploy awaiting manual approval since 2026-09-24T01:14Z (2 runs queued) #1437, Dashboard deploy awaiting manual approval since 2026-09-23T22:49Z (2 runs queued) #1440 (all updated 2026-09-29) show oldest-queued runs unactioned for 4–5+ days each, with dashboard now 5 versions behind production. Paths/surfaces: .github/workflows/deploy-*.yaml, .github/workflows/deploy.yaml (environment approval blocks). Safety constraints: must never auto-approve or bypass required_reviewers; notification-only. Verification target: a synthetic queued run older than the chosen threshold produces exactly one deduped notification and zero approval/deploy side effects.
  2. Outcome: Give AGENTS.md drift detection push-triggered coverage instead of waiting for the next daily autoheal cycle. Evidence: marcusrbrown/sparkle's regenerate-docs.yaml (path-filtered rebuild + diff + bot PR); this repo's existing .agents/skills/generating-project-docs skill already contains the regeneration logic. Paths/surfaces: new .github/workflows/*.yaml, .agents/skills/generating-project-docs/. Safety constraints: PR-only output, never a direct push to main. Verification target: touching a documented path with no actual structural change produces a no-op run (no PR opened); touching it with a real structural change produces exactly one draft PR with the corrected doc.

Needs Human Attention

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions