Migrate fleet Actions scripts to one-line run steps #613
Labels
No labels
burndown-2026-06
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#613
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The actions-run-one-line hook authored in coilyco-flight-deck/agentic-os#673 rejects multiline run commands in GitHub and Forgejo workflows and composite actions. Before the hook joins the managed default catalog, migrate existing consumers to tracked scripts while preserving expression interpolation, env wiring, shell choice, working-directory behavior, and executable modes.
A 2026-07-23 read-only workspace audit found 139 block-scalar run steps across 11 repos:
Done when every listed repo passes the released actions-run-one-line hook, each migration is locally validated and landed through that repos workflow, and no inline script body remains. This issue owns migration only. The existing agentic-os-pin-converge Ansible role owns hook propagation after agentic-os enables the hook in its managed default list.
WARD-WORKFLOW: done ✅
details
workflow: merge-remote-main; review summary: skipped by design for role-separated QA
landed:
86fc595936988cb52180d1e061bf7b27c5080c32validation: pre-commit, Yamllint, ShellCheck, released actions-run-one-line hook, and canonical Forgejo CI passed.
felt: clean extraction, with one security-sensitive pre-authorization checkout wrinkle.
confidence: high.
surprise: a concurrent landing superseded two runs; its green merge contains the candidate.
follow-up: none. The in-container review gate was intentionally skipped because implementation and QA are role-separated. QA is a separate, opt-in exact-commit verification role bound to the candidate commit above.
WARD-WORKFLOW: reservation-released
release details
Run finished with
WARD-WORKFLOW: done ✅.ward container reapreleased containerengineer-codex-infrastructure-613(--harness codex): the terminal outcome supersedes the reservation, so a later redispatch no longer needs--override-reservation.— Codex, via
ward agent