Watch
2
Run the dev-base docker build + main-only validations on PRs as build-only checks #456
Closed
coilyco-ops
wants to merge 0 commits from
issue-454 into main
pull from: issue-454
merge into: coilyco-flight-deck:main
coilyco-flight-deck:main
coilyco-flight-deck:release
coilyco-flight-deck:aos/claude/md68
coilyco-flight-deck:aos/claude/zc49-creature-numbers
coilyco-flight-deck:aos/claude/zc49-creature-background
coilyco-flight-deck:chore/full-name-attribution
coilyco-flight-deck:aos/claude/mt75-bundle-tag
coilyco-flight-deck:aos/claude/ad84-revert-voice
coilyco-flight-deck:aos/claude/ad84-voice
coilyco-flight-deck:aos/claude/tc69-abspath
coilyco-flight-deck:aos/claude/mt75-quiet-plan
coilyco-flight-deck:voice-no-rarity-statements
coilyco-flight-deck:aos/claude/mt75-netlify-remove
coilyco-flight-deck:aos/claude/ad84-titles
coilyco-flight-deck:aos/claude/ad84
coilyco-flight-deck:aos/claude/mt75-aterm-fullscreen
coilyco-flight-deck:aos/claude/mt75-netlify-wrap
coilyco-flight-deck:aos/claude/mt75-kubectl-context
coilyco-flight-deck:aos/claude/mt75
coilyco-flight-deck:aos/claude/mt75-ward-cut
coilyco-flight-deck:aos/claude/eb77
coilyco-flight-deck:aos/claude/fp87-ward-schema
coilyco-flight-deck:aos/claude/fp87-ward-posture
coilyco-flight-deck:aos/claude/fp87
coilyco-flight-deck:aos/claude/vt77
coilyco-flight-deck:aos/1105-require-issue-labels
coilyco-flight-deck:aos/claude/kb87-native-arch
coilyco-flight-deck:aos/claude/kb87-window-identity
coilyco-flight-deck:aos/claude/kb87
coilyco-flight-deck:aos/claude/tg69
coilyco-flight-deck:aos/claude/ff54-retire-issue-refs
coilyco-flight-deck:aos/claude/ff54
coilyco-flight-deck:aos/claude/rc44-bundle-version
coilyco-flight-deck:aos/claude/mu55-contract-tests
coilyco-flight-deck:aos/claude/mu55-sound-mark
coilyco-flight-deck:aos/claude/rc44
coilyco-flight-deck:aos/claude/mu55-identity-card
coilyco-flight-deck:aos/claude/mu55-doctor
coilyco-flight-deck:aos/claude/mu55-shadow-reap
coilyco-flight-deck:aos/claude/mu55-drop-windows
coilyco-flight-deck:aos/claude/mu55-dryrun-exits
coilyco-flight-deck:aos/claude/mu55-list-json
coilyco-flight-deck:aos/claude/mu55-title-order
coilyco-flight-deck:aos/claude/mu55-overlay-contract
coilyco-flight-deck:aos/claude/qu74
coilyco-flight-deck:aos/claude/ue86
coilyco-flight-deck:aos/claude/yq86
coilyco-flight-deck:aos/claude/vk48-harness-set
coilyco-flight-deck:aos/claude/vk48-default-agent
coilyco-flight-deck:aos/claude/vk48-completion
coilyco-flight-deck:aos/claude/vk48-release-fix
coilyco-flight-deck:aos/claude/vk48
coilyco-flight-deck:aos/claude/yb89
coilyco-flight-deck:aos/claude/sb46
coilyco-flight-deck:fix/agent-compose-pin-v3-roster
coilyco-flight-deck:aos/claude/ve67-defer
coilyco-flight-deck:aos/claude/ve67
coilyco-flight-deck:aos/claude/ur54
coilyco-flight-deck:aos/claude/tj49
coilyco-flight-deck:feat/acompose-v3-roster
coilyco-flight-deck:ops/393-retire-doc-size-alias
coilyco-flight-deck:ops/393-drop-em-dash-check
coilyco-flight-deck:feat/vendored-tree-exclude
coilyco-flight-deck:aos/claude/xlarge-band
coilyco-flight-deck:aos/claude/ue65
coilyco-flight-deck:aos/claude/identity-color-wins
coilyco-flight-deck:aos/claude/ap47
coilyco-flight-deck:aos/claude/zr44
coilyco-flight-deck:aos/claude/xk58
coilyco-flight-deck:aos/claude/aw85-skill-size-owner
coilyco-flight-deck:aos/claude/ym96-docs-bands
coilyco-flight-deck:aos/claude/wt57-pin-aos-bundle
coilyco-flight-deck:aos/claude/wt57-image-inputs-filter
coilyco-flight-deck:aos/claude/ym96-label-taxonomy
coilyco-flight-deck:ops/dev-base-pin-rust-1.90.0
coilyco-flight-deck:aos/claude/mg96-clean
coilyco-flight-deck:aos/claude/mg96
coilyco-flight-deck:backup/fix/bake-precommit-hooks
coilyco-flight-deck:rescue/aos-test-timeout
coilyco-flight-deck:aos/claude/issues-977-979-agents-base
coilyco-flight-deck:aos/claude/sx87
coilyco-flight-deck:refactor/remove-context-budget-json
coilyco-flight-deck:issue-946
coilyco-flight-deck:aos/codex/20260806t050901z-50407-6291ab0a
coilyco-flight-deck:aos/codex/standalone-shadow-workspace
coilyco-flight-deck:backup/aos/codex/20260806t061240z-10127-754d7de2
coilyco-flight-deck:aos/codex/standalone-local-service-route
coilyco-flight-deck:aos/codex/aosterm-aoscompose-wrapper
coilyco-flight-deck:aos/codex/agents-launch-profile-source
coilyco-flight-deck:aos/codex/launch-profiles-yaml
coilyco-flight-deck:aos/codex/20260806t031603z-7731-c76c17f2
coilyco-flight-deck:backup/aos/codex/20260805t183628z-5916-617bb239
coilyco-flight-deck:backup/aos/codex/20260805t025242z-30811-fbb135ff
coilyco-flight-deck:aos/codex/aos-v2-roster-852
coilyco-flight-deck:aos/codex/20260801t164712z-64119-69ee8bb6
coilyco-flight-deck:backup/aos/codex/20260801t164900z-67616-2ad2d0e3
coilyco-flight-deck:issue-834
coilyco-flight-deck:aos/codex/pr-829-1130
coilyco-flight-deck:issue-824-agent-proxy-model-routing
coilyco-flight-deck:task-merge-pr818
coilyco-flight-deck:fix/aos-ci-20260730
coilyco-flight-deck:issue-671
coilyco-flight-deck:issue-734
coilyco-flight-deck:issue-484
coilyco-flight-deck:issue-498
coilyco-flight-deck:issue-622
coilyco-flight-deck:issue-512
coilyco-flight-deck:issue-679
coilyco-flight-deck:backup/issue-785-first-person
coilyco-flight-deck:issue-785-first-person
coilyco-flight-deck:director-pr784
coilyco-flight-deck:restore-language-images
coilyco-flight-deck:recovery/2026-07-28-triaged-branch-archive
coilyco-flight-deck:recovery/2026-07-27-local-work
coilyco-flight-deck:recovery/aos-local-build-20260727
coilyco-flight-deck:codex/land-pr-733
coilyco-flight-deck:codex/aos-ci-watch
coilyco-flight-deck:issue-642
coilyco-flight-deck:issue-682-goose-yaml
coilyco-flight-deck:issue-656-goose-context
coilyco-flight-deck:safety/aos-local-main-09347d0
coilyco-flight-deck:issue-611-specialist-images
coilyco-flight-deck:fix-action-run-list-page
coilyco-flight-deck:issue-454-v2
coilyco-flight-deck:experiment/no-ops-forgejo
coilyco-flight-deck:feat/dev-base-image
No reviewers
Labels
Clear labels
burndown-2026-06
Backlog burndown June 2026
burndown-2026-08
Closed in the 2026-08-26 backlog burn-down. Reopen freely: state:closed label:burndown-2026-08 recovers the whole set.
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
coherence-core
Core review set for the warded control plane coherence milestone. These issues form the release spine; adjacent milestone issues are stretch or supporting work.
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
qa-fixture
Disposable issue admitted to the bounded Ward QA verification lane.
role/advocate
requires work from the Developer Advocate seat
role/director
requires work from the Portfolio Director seat
role/exec
requires work from the exec role
role/frontend
requires work from the Frontend Engineer seat
role/gamedev
requires work from the Game Developer seat
role/human
requires a person, and specifically not an agent seat
role/platform
requires work from the Platform Engineer seat
role/qa
requires work from the QA role
role/science
requires work from the Applied Scientist seat
role/sysadmin
requires work from the Systems Administrator seat
state
ambient
ambient and ephemeral work, held as a maintained document rather than a queue
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/agentic-os!456
Loading…
Reference in a new issue
No description provided.
Delete branch "issue-454"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Shift the validations that only ran on main left onto every pull request, so the aos#452 class (main going red on a merge no PR ever exercised) is caught on the PR that causes it.
publish-dev-baseinto a shared./actions/dev-base-buildcomposite. release.yml runs it withpush: "true"(unchanged multi-arch publish), ci.yml runs it on every PR with the defaultpush: "false"- build every tier, exercise the in-imageCLIGUARD_NO_SANDBOX=1 ward doctorgate, no push, no tag, no registry auth. One definition, so the two paths cannot drift apart.gatenow also dry-runs the release tag computation (actions/tag-bumpwithcreate_tag: false), anduv run pytestalready covers thetests/test_dev_base_image.pypin-consistency checks on PRs.docs/pr-dev-base-build-validation.mdwalkthrough, with pointers from ci-in-dev-base.md, dev-base-image.md, and release.md. Newtests/test_dev_base_build_action.pypins the sharing contract (build-only default, push side effects guarded, only release.yml holdsREGISTRY_TOKEN).mirror-to-github.ymlis a deploy and stays main-only,dep-bump.yml/freshness.ymlare scheduled and stay as-is.Follow-up for branch protection: require the new
ci / build-dev-basecontext alongsideci / gate(admin-side setting, and theward ops forgejosurface in this container is degraded so the agent could not set it).closes #454
ward.workflow: pull-request-and-merge
Status of this PR's checks, from the engineer run (claude-linux-6dfbe4beef5b-da08-she-her):
ci / gate- green, including the new compute-only tag-bump step and thetest_dev_base_image.pypin checks.ci / build-dev-base- red, and that red is the new check doing its job: it is the live aos#452 incident surfaced pre-merge, not a defect in this branch. The in-imageCLIGUARD_NO_SANDBOX=1 ward doctorgate fails identically on main's ownpublish-dev-base(run 1005, three attempts).Diagnosis, verified by building/running ward versions against this branch's
.ward/bundle:WARD_VERSION=0.567.0(the current core pin) predates the aos#433 bundle-filename reshape and fails wantingward-kdl.defaults.kdl/ward-kdl.fleet.kdl/ward-kdl.forgejo.guardfile.kdl.forgejo.swagger.lock.json, which aos#435 deliberately removed from the bundle.ward.bundle.kdlops manifest (ops { forgejo "guardfile.forgejo.kdl" }), and with that present they still hard-require the swagger lock (bundleForgejoSpecLockPathincmd/ward/configsource.go, unchanged at ward main HEAD).So no shipped ward version passes doctor against the current bundle, and the unblock is ward-side (ward#1064 / ward#1082 territory), exactly as aos#452 predicted. Once ward ships bundle loading that does not hard-require the removed lock, the remaining aos work is the aos#452 pin bump (
WARD_VERSIONplus thetest_dev_base_image.pyliterals). This check then goes green with no further change to this branch, because the build definition is shared with release.yml by design.The branch is merge-ready on its own scope: merging it does not change what main builds (release.yml runs the same steps it always ran, now via the shared composite), it only makes every PR show the breakage main already has. Branch-protection enrollment of
ci / build-dev-baseis deliberately deferred to #457 so the context does not hard-block PRs while aos#452 is unresolved.WARD-OUTCOME: blocked 🛑
details
workflow: pull-request-and-merge; review summary: skipped (in-container review gate intentionally skipped, the temporary ward default pending brokered QA)
PR: #456.
ci / gateis green on run 1014.ci / build-dev-baseis red on the same run after 2m24s. The branch content is merged withmain, but the dev-base build still fails in the shared build/verify step. The blocker is still the ward-side bundle compatibility issue already diagnosed in the thread, so this repo cannot clear the check alone.Retrospective: the wiring held. The surprise was that the
mainmerge did not move the live build result. Confidence: high in the diagnosis, low that more repo-only edits will help. Follow-up: wait for the ward-side fix, then rerun the PR.WARDED_WORKFLOW: blocked 🛑
details
workflow: pull-request-and-merge; review summary: skipped (in-container review gate intentionally skipped, review gate skipped by ~/.ward/config.yaml default)
PR: #456.
ci / gatepassed on run 1233.ci / build-dev-basefailed on the same run after 3m25s. The branch change here was doc-only, so the failure is still the shared dev-base build path, not this docs edit. Confidence: high that this is the same external blocker seen before. Follow-up: wait for the ward-side build/doctor compatibility fix, then rerun the PR.too many merge conflicts
WARDED_WORKFLOW: blocked 🛑
details
workflow: pull-request-and-merge; review summary: skipped (in-container review gate intentionally skipped, the temporary ward default pending brokered QA)
PR: #456.
ci / gatepassed on the reopened run.ci / build-dev-basefailed again after 4m4s on the merge ref for this PR. The branch-protection write formainis still blocked from this runner with 403 on the Forgejo branch-protection API, so the required-check follow-up cannot be completed from here. Confidence: high this is the same external dev-base blocker seen before. Follow-up: wait on the ward-side build/doctor compatibility fix and the admin-side protection update, then rerun.Retrospective: the branch wiring held, and the failure reproduced exactly as before. The surprise was that reopening the PR immediately re-queued the same failing merge-ref run without any new code drift.
Pull request closed