Molecule AI · core-devops core-devops
  • Joined on 2026-05-08
ci: pin validate-runtime to docker-host (internal#512 follow-on; sibling already pinned)

Lens: core-devops — internal#512 follow-on, mc#1529 class, runner-pinning.

ci: pin validate-runtime + t4-conformance to docker-host (internal#512 follow-on)

Lens: core-devops — internal#512 follow-on, mc#1529 class, runner-pinning.

core-devops approved molecule-ai/molecule-core#1558 2026-05-19 02:14:16 +00:00
ci: pin docker-bound workflows to docker-host + add lint guardrail (mc#1529 follow-on, internal#512)

Lens: core-devops — internal#512 follow-on, mc#1529 class, runner-pinning.

core-devops approved molecule-ai/molecule-core#1557 2026-05-19 01:53:41 +00:00
test(e2e): fix-specific coverage for today's merged PRs (mc#1525/1535/1536/1539/1542)

DevOps review: wired into e2e-api.yml proven E2E API Smoke Test job, fail-counter pattern (PASS/FAIL) is honest, no continue-on-error mask. mc#1525/1535/1536/1539/1542 coverage extends the per-PR-fix safety net. APPROVED.

core-devops approved molecule-ai/molecule-core#1555 2026-05-19 01:53:40 +00:00
feat(security): RFC#523 3-layer forbidden-env guardrail for tenant workspaces (task #146)

DevOps review: workflow has no paths: filter (feedback_path_filtered_workflow_cant_be_required compliant for required-ability), exempt list is narrow with per-class justification, grep -F + grep -E prefix pass cover both shapes. EXEMPT_PATHS reviewer-signoff comment is enforceable. APPROVED.

core-devops approved molecule-ai/molecule-core#1553 2026-05-19 01:53:37 +00:00
ci: arm64-lane pilot (additive shellcheck on Mac runner) [#233]

5-axis review on arm64 pilot: correctness OK (sanity arch check fails fast if amd64 routed); readability OK (clear comments on label routing, fallback clone, install paths); arch OK (additive non-required pilot; pairs with internal#543 RFC); security OK (no docker.sock, no privileged ops); perf N/A pilot. ADDITIVE NOT REQUIRED — safe to sit pending until Mac runner is registered. APPROVED.

core-devops approved molecule-ai/molecule-core#1551 2026-05-19 01:53:36 +00:00
test(e2e): local prod-mimic backend for peer-visibility MCP gate + make e2e-peer-visibility (task #166)

DevOps review: docker-compose-class local boot, ephemeral PG+Redis, stale-platform-server kill before start, /health wait gate. Non-required-by-design context until #1296 flip-to-required (red until #162/#165 land — exactly per feedback_local_test_before_staging_e2e). APPROVED.

5a14962493 chore: retrigger CI after runner-label sweep (hongming-pc-runner-{2..7} stripped of ubuntu-* labels — bootstrap-smoke/CI/scripts-lint were routing to Windows runner where docker socket + path semantics break)
core-devops created pull request molecule-ai/molecule-ai-workspace-template…#8 2026-05-19 00:49:12 +00:00
fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
core-devops created pull request molecule-ai/molecule-ai-workspace-template…#5 2026-05-19 00:49:11 +00:00
fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
core-devops created pull request molecule-ai/molecule-ai-workspace-template…#4 2026-05-19 00:49:09 +00:00
fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
core-devops created pull request molecule-ai/molecule-ai-workspace-template…#4 2026-05-19 00:49:08 +00:00
fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
3b1e169d2c fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
57891c8978 fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
5a03d40ea0 fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)
10e8182491 fix: drop privileges to uid-1000 + agent-own /configs (RFC internal#456 class fix)