Skip to content

Document SSH publication for adopters - #212

Merged
s-hiraoku merged 10 commits into
mainfrom
agent/issue-205-publication-docs
Aug 9, 2026
Merged

s-hiraoku merged 10 commits into
mainfrom
agent/issue-205-publication-docs

Conversation

@s-hiraoku

@s-hiraoku s-hiraoku commented Aug 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • document the effective push URL as the selector for HTTPS broker or SSH publication
  • fail before installation unless HTTPS has a broker or SSH passes a non-interactive dry-run push
  • cover SSH success/failure and split fetch/push URL configurations with stubbed fixtures

Verification

  • bash onboarding/scripts/test-onboard.sh
  • bash scripts/run-pr-contracts.sh
  • sh -n onboarding/onboard.sh onboarding/scripts/test-onboard.sh
  • git diff --check

Risk

The SSH probe is a non-destructive git push --dry-run to a process-unique branch name. Fixtures intercept it and make no network calls; real SSH identity and host-key configuration remain operator-specific.

Closes #205

Summary by CodeRabbit

  • New Features
    • Onboarding now supports SSH-based repository access without requiring the GitHub publication broker.
    • Added guidance for configuring, validating, and troubleshooting SSH authentication.
  • Bug Fixes
    • Improved repository URL validation, including mixed protocols, multiple push URLs, and local URL rewrites.
    • Onboarding now provides clearer errors for unsupported or unauthenticated publication URLs.
  • Tests
    • Added comprehensive coverage for SSH and HTTPS publication checks and pre-installation failures.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@s-hiraoku, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 40 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository: kaizen-agents-org/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f32de7da-6e4e-4944-b7d1-3c7296443e2f

📥 Commits

Reviewing files that changed from the base of the PR and between 102a420 and 47a5bc9.

📒 Files selected for processing (2)
  • onboarding/onboard.sh
  • onboarding/scripts/test-onboard.sh
📝 Walkthrough

Walkthrough

Onboarding now validates origin fetch and publication URLs before installation. It supports HTTPS publication through the broker or SSH publication through an isolated dry-run push. Documentation and tests cover both paths, URL rewrites, and push-URL selection.

Changes

Publication authentication

Layer / File(s) Summary
Validate origin publication URLs
onboarding/onboard.sh, onboarding/scripts/test-onboard.sh
Onboarding rejects local Git URL rewrites and multiple publication URLs. It verifies that fetch and publication URLs identify the same GitHub repository. Tests cover these early failures.
Check HTTPS and SSH publication authentication
onboarding/onboard.sh, onboarding/ADOPTING.md
HTTPS publication checks broker configuration. SSH publication runs an isolated, non-interactive dry-run push with strict host-key checking. The guide documents both paths and their requirements.
Verify publication preflight behavior
onboarding/scripts/test-onboard.sh
Tests stub Git dry-run pushes and cover SSH success and failure, mixed fetch and push protocols, and pre-installation failure ordering.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Possibly related issues

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary documentation change: SSH publication guidance for adopters.
Linked Issues check ✅ Passed The PR documents supported authentication paths and validates publication before builder and verifier work, satisfying issue #205.
Out of Scope Changes check ✅ Passed The documentation, onboarding validation, and tests directly support issue #205 and the stated PR objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/issue-205-publication-docs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f7fa060d74

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/ADOPTING.md Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@onboarding/ADOPTING.md`:
- Around line 120-121: Update onboarding/ADOPTING.md at lines 120-121 to
document the required non-interactive SSH origin preflight, and update
onboarding/scripts/test-onboard.sh at lines 145-159 with a probing stub fixture
that verifies failure prevents installation and success probes before
installation; implement the corresponding onboard.sh flow so SSH origins run git
ls-remote origin before toolchain installation and refuse onboarding when the
probe fails.
- Around line 39-50: The SSH onboarding documentation must describe publication
based on the effective push URL, including remotes configured with
remote.origin.pushurl. Update the SSH wording and probe in
onboarding/ADOPTING.md lines 39-50 to cover SSH pushurl configurations; add
push-URL-only fetch/push permutations to onboarding/scripts/test-onboard.sh
lines 148-149, while onboarding/onboard.sh should derive the publication scheme
from remote.origin.pushurl or the fetch URL.
- Around line 5-6: Update the SSH publication prerequisites in ADOPTING.md to
validate push capability for the configured publication target, using a
non-destructive dry-run push or retaining git ls-remote origin alongside it.
Ensure the preflight checks SSH write access rather than only authentication and
read access.
- Around line 48-50: Update the documented git ls-remote SSH preflight to
include non-interactive SSH options, specifically BatchMode=yes and an explicit
host-key policy, while retaining the existing config isolation. Ensure the
command fails immediately rather than prompting for passphrases,
keyboard-interactive authentication, or host-key decisions.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: kaizen-agents-org/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b4769d5c-b9c7-4304-a07e-c7d2befe68d7

📥 Commits

Reviewing files that changed from the base of the PR and between a24500a and f7fa060.

📒 Files selected for processing (2)
  • onboarding/ADOPTING.md
  • onboarding/scripts/test-onboard.sh

Comment thread onboarding/ADOPTING.md
Comment thread onboarding/ADOPTING.md Outdated
Comment thread onboarding/ADOPTING.md Outdated
Comment thread onboarding/ADOPTING.md Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

PR guardian final audit

  • Head 1401052; ready for review, merge state CLEAN.
  • Required organization-contract and CodeRabbit statuses are successful; Closes #205 is recognized.
  • Paginated audit: 5/5 review threads resolved, no pending reviews, no unresolved actionable feedback.
  • The effective push URL, non-interactive SSH dry-run push, failure-before-install ordering, and both split fetch/push configurations are implemented and covered by fixtures.
  • Existing Node 20 Actions deprecation annotation is unrelated to this change. No unresolved blockers.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1401052ee2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f6bc602ff7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6a71774c1d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 435ee35a25

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 42f5964181

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@onboarding/onboard.sh`:
- Around line 156-164: Update the remote_url validation before slug extraction
in the onboarding flow to accept only exact supported GitHub URL forms,
rejecting lookalike hosts such as notgithub.com. Preserve the existing
repository identity comparison, and add a regression fixture asserting that a
lookalike hostname exits before the publication probe.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: kaizen-agents-org/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ec6941bd-dd52-4e4b-92a4-ecdc29141fb2

📥 Commits

Reviewing files that changed from the base of the PR and between f7fa060 and 102a420.

📒 Files selected for processing (3)
  • onboarding/ADOPTING.md
  • onboarding/onboard.sh
  • onboarding/scripts/test-onboard.sh

Comment thread onboarding/onboard.sh Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current HEAD ecf1ae3a09070084179e0886e312f5395dcdc9c8.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ecf1ae3a09

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current HEAD 56975a6a1b7c479138a178bf3411b6d114da05fc.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

PR guardian final audit

  • Head 56975a6; ready for review, MERGEABLE / CLEAN.
  • Pull Request Contracts run 31308916464 passed; CodeRabbit status is successful.
  • Paginated audit: 12/12 review threads resolved, no pending required approvals, no unresolved actionable feedback.
  • Review remediation covered effective push URLs, SSH write probing, prompt/hook isolation, multiple targets, local/worktree URL rewrites, exact GitHub host validation, and case-insensitive host handling. Every fix was regression-tested through the full PR-contract suite.
  • The Node 20 Actions deprecation annotation is pre-existing and non-blocking.
  • No merge blockers remain. Codex did not run another complete pass after the final one-line host-normalization follow-up because the guardian retry budget was exhausted; CodeRabbit and CI are terminal on the current head.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 56975a6a1b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread onboarding/onboard.sh Outdated
@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@codex review

Please review current HEAD 47a5bc999a52307c74d81b1ff5655cc7e57f04d3.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 9, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@s-hiraoku

Copy link
Copy Markdown
Contributor Author

PR Guardian update (HEAD 47a5bc999a52307c74d81b1ff5655cc7e57f04d3)

  • Fixed exact GitHub-host validation, including case-insensitive host handling.
  • Fixed URL-rewrite detection for rules loaded through local/worktree Git config includes.
  • Added regression fixtures for lookalike hosts, mixed-case GitHub hosts, and included URL rewrites; full onboarding fixture suite passes.
  • CI: Pull Request Contracts run 31309184472 PASS.
  • All 13 review threads are resolved after per-thread replies.
  • GitHub state: MERGEABLE / CLEAN.
  • External review gate remains pending: CodeRabbit is rate-limited on the current head, and Codex reports its code-review usage limit was reached for the current head.

No merge was performed.

@s-hiraoku
s-hiraoku merged commit 376afb0 into main Aug 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

An HTTPS-remote adopter cannot publish a pull request, and ADOPTING.md does not say how to configure one that can

1 participant