Skip to content

[AIAA] Build preflight: verify cloud agent preconditions for cncf/techdocs #364

Description

@nate-double-u

This is the preflight for the AI-assisted TechDocs assessment build
(spec: PR #363, section 16). The administrator/platform owner works
through the section 11 preconditions and records each answer here. These
are organization and repository settings, not files, so this item closes
with recorded answers rather than a PR.

The probe delegation (spec section 16, as amended by 09a92bf) starts
after this issue closes; it carries the platform observations build
step 1 used to hold. Locally drafted build steps, step 1 (workflow
labels) included, do not wait on this issue.

Preconditions (spec section 11)

  • Cloud agent policy enabled for cncf/techdocs, and the repository
    not opted out (org Copilot policy).
    Recorded state: verified 2026-08-13, copilot-swe-agent is in
    the repository's assignable actors (read-only GraphQL
    suggestedActors, capability CAN_BE_ASSIGNED). Supporting
    evidence: cncf/mentoring's cloud-agent PRs #1527, #1631, #1668
    (Dec 2025 to Feb 2026).
  • MCP policy enabled at the organization level.
    Recorded state:
  • Repository MCP configuration at its read-only default: no custom
    MCP servers configured for cncf/techdocs. Platform defaults noted
    (GitHub MCP server, read-only, scoped to this repository;
    Playwright MCP server, localhost-only).
    Recorded state:
  • Writer access confirmed for everyone who will delegate to the
    agent during the build (delegation is permission-gated to write
    access; P-1).
    Recorded state: nate-double-u is the sole delegator during the
    build and holds ADMIN (verified 2026-08-13, read-only GraphQL
    viewerPermission). Anyone added later is confirmed then.
  • Credit cap reviewed. Spending beyond included credits is enabled
    by default at the org level; record the budget decision.
    Recorded state: reviewed 2026-08-13 by nate-double-u; currently
    unlimited for CNCF folks per the CNCF Copilot Enterprise
    arrangement
    (https://contribute.cncf.io/blog/2025/12/16/github-copilot-enterprise-for-maintainers/).
    No per-org budget cap in effect; revisit if the arrangement
    changes.

Additions beyond section 16's list (flagged as such)

  • No secrets exposed to the agent environment: no Actions
    environment named copilot, or it is empty (section 11 secrets
    policy).
    Recorded state: the copilot environment exists with zero
    secrets and zero variables (verified 2026-08-13, read-only API,
    names-only listing). Compliant; re-checked if an exception is
    ever proposed.
  • Probot Settings app status for .github/settings.yml (the file
    shows drift from live labels, so sync looks inactive). The answer
    decides whether step 1's labels apply on merge or by hand with
    gh label create (HC-4 permits the by-hand fallback).
    Recorded state: installed (org-level installation of the
    repository-settings app, listed on the repo's GitHub Apps page,
    so it has access) but not syncing on this repository. File
    changes from 2022-11-07 (60a8818) and 2026-02-06 (993afda) never
    applied live. Cross-check: the same app works in cncf/mentoring,
    where a 2026-06-25 commit (9d88251) recolored an existing label
    and live matches the file exactly. Prime suspect here: this
    file's three unquoted # colors (YAML parses them as comments,
    color becomes null); mentoring's colors are un-prefixed and parse
    fine. The 2022 failure predates that bug and stays unexplained.
    Step 1 therefore reconciles the file to live before adding
    labels: fixing the quoting likely wakes the app, and a real
    declarative sync deletes any live label missing from the file.
    Fallback to gh label create if merge still applies nothing.

Spec references

Covers the section 16 preflight; preconditions from section 11; bound by
P-1 (human-gated) and HC-1 (write boundary: MCP and secrets are its two
documented widening mechanisms).

Metadata

Metadata

Assignees

Labels

adminTechDocs administration activities

Type

No type

Projects

Status
Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions