You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7810bc2
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+17-5Lines changed: 17 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,7 +44,7 @@ The whole thing runs on GitHub Actions, event-driven, with no server and no VM f
44
44
What this buys you:
45
45
46
46
- Your code stays in your repos. SimplyCubed never receives it.
47
-
- Your model provider keys, your `GITHUB_TOKEN`, and any other secrets stay in your GitHub secret store. They are read by your own Actions runs and never transit our infrastructure.
47
+
- Your model provider keys, the GitHub App's private key, and any other secrets stay in your GitHub secret store. They are read by your own Actions runs and never transit our infrastructure.
48
48
- The agent holds no deploy credentials and has no path to production. The most it can do is open a pull request against a branch. A human and your branch protection rules decide what happens next.
49
49
50
50
Setup files are written locally by `simplycubed init` and merged by a human, because the runtime holds no `workflows` permission and cannot add its own workflow files.
@@ -76,13 +76,25 @@ request.
76
76
77
77
To run the loop inside your own GitHub Actions:
78
78
79
-
1. In the adopter repo, run `simplycubed init --workflow`. That writes `.github/simplycubed.yml`, writes `.github/workflows/simplycubed.yml`, and creates the `sc:*` labels through your local `gh` auth.
80
-
2. Fill in the real `gate:` in `.github/simplycubed.yml`.
81
-
3. Add the repository variable `AZURE_OPENAI_ENDPOINT` and the repository secret `AZURE_OPENAI_API_KEY`.
82
-
4. Optionally add a PAT as `SIMPLYCUBED_GH_TOKEN`. This is strongly recommended: pushes and pull requests authored with `GITHUB_TOKEN` do not trigger downstream workflows, so without a PAT the agent's PRs can miss their `check` runs and required checks block merge. If you set it, use a dedicated non-admin machine account's PAT, never a human reviewer's PAT, because the fix-on-request loop resolves the token identity and skips self-authored reviews. The reusable workflow falls back to `github.token` only when no PAT is set; issue #31 replaces this later with an App token.
79
+
1. Create and install the GitHub App, `simplycubed-code`.
80
+
Repository permissions: `Contents`, `Pull requests`, and `Issues` only.
81
+
Do not grant `Workflows`, `Administration`, `Environments`, or `Secrets`.
82
+
Disable the App webhook: the App is an identity that mints per-job tokens, and there is no SimplyCubed server to receive deliveries.
83
+
Set install visibility to `Any account`.
84
+
Install it on the repo.
85
+
2. In the adopter repo, run `simplycubed init --workflow`. That writes `.github/simplycubed.yml`, writes `.github/workflows/simplycubed.yml` pinned to a released reusable-workflow tag, and creates the `sc:*` labels through your local `gh` auth.
86
+
3. Fill in the real `gate:` in `.github/simplycubed.yml`.
The private key secret must be the full PEM contents, including the `-----BEGIN` and `-----END` lines.
83
89
5. Open a setup pull request in the adopter repo and merge it yourself. Setup files are written locally by `simplycubed init` and merged by a human, because the runtime holds no `workflows` permission and cannot add its own workflow files.
84
90
6. File an issue and apply `sc:go`. Reviews submitted on the resulting pull request call back into the same reusable workflow for the fix-on-request loop.
85
91
92
+
Each reusable-workflow job mints its own installation token for the current
93
+
repository and asks only for `contents`, `pull requests`, and `issues`. The
94
+
workflow then probes an Actions-administration endpoint and expects a denial, so
95
+
the run log shows the token does not carry the workflow/admin scope the App was
96
+
deliberately denied.
97
+
86
98
## Configuration
87
99
88
100
Configuration lives in `.github/simplycubed.yml`. A minimal file looks like this:
0 commit comments