Skip to content

ci: validate every org's resources on every pull request - #76

Open
scott-lowe-vapi wants to merge 1 commit into
ci/workflow-hardeningfrom
ci/validate-resources
Open

scott-lowe-vapi wants to merge 1 commit into
ci/workflow-hardeningfrom
ci/validate-resources

Conversation

@scott-lowe-vapi

@scott-lowe-vapi scott-lowe-vapi commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Value

V.A.L.U.E. tier: small — touches .github/workflows/ (a blast-radius path), and changes what customer forks see on their pull requests.

Heads-up for forks: plain push only warned about these errors, so a repo may already carry some. The first PR after this lands will show them, whatever it changes. The troubleshooting guide covers it. apply already refused those configs, so this moves an existing failure earlier rather than adding a new one.

Evidence of value

tests/ci-validate-workflow.test.ts runs the job's real step, read from ci.yml, against copies of the starter example:

Case Result
No org folders passes, "nothing to validate"
Two valid orgs passes, both validated
One org with a 41+ character assistant name, one valid fails; both validated, the error names only the bad org and the reason ("Vapi caps at 40")
A folder that isn't a valid org name fails, naming it
The job's secrets none; checkout doesn't persist credentials; the only key is the placeholder

Mutation: making the loop ignore validate's exit code fails the two failure-case tests.

Testing plan

Refs TEST-141

🤖 Generated with Claude Code

Nothing ran `npm run validate` before merge. A config that `apply`
refuses (name length, structured-output lockstep, duplicated prompts, the
maxTokens floor, voice schema) could merge green, and deploys and
promotion out of main then stopped until a fix landed. Plain `push` only
warns, and can fail partway with an API 400.

- ci.yml gets a Validate resources job: validate for every folder under
  resources/, reporting every failing org rather than stopping at the
  first. validate makes no network call; the engine's config only needs a
  key to be set, so the step sets a placeholder that is never sent. The
  job has no secrets, so forks get it too. No engine change.
- tests/ci-validate-workflow.test.ts runs the step itself against fixture
  orgs: no orgs, all valid, one invalid org among valid ones, an invalid
  folder name, and no secrets or persisted credentials.
- README, AGENTS.md (change loop), the workflows, PR checks and
  troubleshooting guides, and improvements.md #37 describe it.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant