Repository navigation
Run the Claude engine in GitHub Actions #104
Description
Activity
Open questions before this can be implemented
I worked through the adopter-correctness set while you were away and stopped here deliberately. This issue names two decisions in its own body, and both are product calls rather than implementation details, so guessing would mean shipping a shape you did not choose.
1. What does the Claude path authenticate with?
Item 4 says the adapter "deliberately inherits whatever the
claudeCLI is already configured with, which suits a developer machine and means nothing on a fresh runner." So the hosted path needs a credential the local path does not have, and the choice is not obvious:- an Anthropic API key as a repository secret, symmetric with the Azure path, or
- something else you have in mind for how a customer pays for Claude usage
The second is the reason I did not pick: it is a commercial decision, not a technical one.
2. Both secrets optional, or separate jobs?
Item 3 already frames it:
workflow_callsecrets cannot be conditionally required. Either both engines' secrets become optional and the CLI enforces the pairing, or the engines get separate jobs.Optional-plus-CLI-enforcement is simpler and keeps one job, at the cost of a misconfiguration surfacing later than it could. Separate jobs make the contract explicit in the workflow and duplicate a lot of it. I lean to the first, now that #115 makes
preflightfail early and name what is missing, which removes most of the cost. But it is your call.Also worth knowing
This cannot be finished by the agent. It edits
.github/workflows/, and the App holds noworkflowspermission. Whoever takes it should expect a green gate followed by an escalation, or run the CLI locally under their own auth.Naming has moved. The Azure values are now
SIMPLYCUBED_AZURE_OPENAI_ENDPOINTandSIMPLYCUBED_AZURE_OPENAI_API_KEY, and the scheme isSIMPLYCUBED_<PROVIDER>_<THING>. An Anthropic key would beSIMPLYCUBED_ANTHROPIC_API_KEYunder it.Item 5 is partly done.
docs/setup.mdstill says the hosted path is Codex-only, which remains true, but the surrounding text was rewritten in #125.
The local half of #95 shipped in #102:
engine: claudeno longer demands Azure credentials it never uses, andcodex.WriteConfigis gated on the same condition. A local CLI run can use Claude today.The hosted path still cannot, and that half could not ship in the same pull request. It needs a change under
.github/workflows/, and the App holds noworkflowspermission by design, so the agent cannot push it. This is human work, or a local CLI run merged the usual way.What is missing
The reusable workflow installs the Codex CLI unconditionally, in both jobs, and declares
azure-openai-endpointandazure-openai-api-keyas required. A caller selecting Claude still has to supply Azure credentials to satisfy the workflow contract, and the CLI it needs is never installed.Work
engineinput to the reusable workflow, defaulting tocodexso no existing caller changes.anthropic-api-keysecret for the Claude path. This is the part worth thinking about rather than typing:workflow_callsecrets cannot be conditionally required, so either both become optional and the CLI enforces the pairing, or the engines get separate jobs.claudeCLI is already configured with, which suits a developer machine and means nothing on a fresh runner.docs/setup.mdwhich engines the hosted path supports, replacing the note added in Closes #95: engine: claude is selectable but cannot actually be used #102 that it is Codex-only.Acceptance
engine: claudeand an Anthropic credential gets a pull request from GitHub Actions, with no Azure variables set anywhere.