Skip to content

Centralize Java team-memory coordination in Java Pack - #1769

Merged
Changyong Gong (chagong) merged 5 commits into
mainfrom
chagong-java-team-memory-coordinator
Oct 10, 2026
Merged

Changyong Gong (chagong) merged 5 commits into
mainfrom
chagong-java-team-memory-coordinator

Conversation

@chagong

@chagong Changyong Gong (chagong) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Use Java Pack as the opt-in central coordinator for the microsoft/vscode-java-pack wiki. This PR changes only the source push workflow and central coordinator workflow. The entire local .github/actions/queue-team-memory directory is removed, including implementation, tests, and README; dedicated local test CI is also removed. Implementation, tests, and shared-action documentation belong in microsoft/IssueLens.

Both remote actions are pinned to a81d2d96167fc0e69ac631c2edc85f858e693289, including merged microsoft/IssueLens#51 and microsoft/IssueLens#53. No unmerged prerequisite or runtime deployment is required for action reuse.

  • The source push workflow invokes only the standalone IssueLens queue-team-memory dispatcher with caller-owned source_repository, source_run_id, source_run_attempt, push_before, and push_after strings. Destination main is independent of a source default branch such as develop.
  • The coordinator invokes the shared IssueLens issuelens action directly. Source validation, bounded complete range/PR discovery, Azure OIDC login, submission, and final receipt validation belong to IssueLens; no local provenance/invocation implementation, identity artifacts, or runtime client checkout remains.
  • Keep the trusted eight-source repository-ID configuration, independent scoped source-read authentication, and fixed issuelens-team-memory-wiki-microsoft-vscode-java-pack group with queue: max and cancel-in-progress: false. Automatic range and manual merged-PR reconciliation share this queue through receipt validation. GitHub supports one active and at most 100 pending runs, not guaranteed/exactly-once delivery. Source policy must select this wiki and is never overridden; unverified Spring candidates remain excluded.

Range inputs authorize ancestor-range reconciliation, not original push-boundary attestation. The source run establishes push_after/head, not the original push_before or push flags. Accepted dispatch or completed SSE does not imply successful publication. Invalid, wrong-wiki, missing, or partial receipts and incomplete streams fail; dispatch and invocation are not automatically retried. Investigate ambiguous outcomes before manual reconciliation through the same queue.

Only Java Pack's own caller changes here. Other Java sources migrate in later PRs; existing issue-loop/direct consumers and extension behavior remain unchanged.

Opt-in prerequisites

Both workflows remain gated by ISSUELENS_TEAM_MEMORY_COORDINATOR_ENABLED=true; the existing legacy gate does not activate them. No settings, App installations, credentials, workflow enablement, wiki maintenance, deployment, or merge is performed by this PR.

Java Pack's own caller uses its job token with Contents read and Actions write. External sources require central ISSUELENS_SOURCE_READ_APP_CLIENT_ID/ISSUELENS_SOURCE_READ_APP_PRIVATE_KEY for a selected-source App token with Actions/Contents/Pull requests read, and a separate dispatch token with Contents read plus Actions write on Java Pack. Source and dispatch installations may differ; mint separate tokens. Do not distribute the hosted IssueLens App private key to callers. Independently verify the central workflow_dispatch Azure OIDC subject, existing endpoint secrets (AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_SUBSCRIPTION_ID, ISSUELENS_AGENT_URL, ISSUELENS_AGENT_SCOPE), and hosted source-read/wiki-write access under source policy/privacy.

Validation

Published cleanup commit 4312340df120299c69ddbb7365158e1881fe26dc and verified the live PR head. Both the workspace and published Git tree have no local queue action directory; the only remaining queue-action reference is the pinned remote uses entry. Both runtime workflows are byte-for-byte unchanged by the cleanup, and patch whitespace checks pass. Shared-action tests remain owned by IssueLens.

The CI build and E2E AutoTest succeeded on the previous head 69833dd5eaf953cb1e300cf2f1cce1f1b1943477. The final cleanup deletes only the README and empty directories; it makes no runtime change. Automatic checks on the cleanup head have started, with no failure reported at the last inspection; those results are not represented as completed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Replace artifact provenance and the local coordinator adapter with the pinned generic dispatcher and shared invocation action. Preserve trusted source IDs, scoped read authentication, the central wiki queue, and validated reconciliation receipts.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The workflows are opt-in, least-privileged, immutably pinned, and comprehensively covered by contract tests.

0 open findings

What changed in this PR

Centralizes opt-in Java team-memory reconciliation in Java Pack using immutable shared IssueLens actions.

Changes:

  • Adds centralized dispatch and reconciliation workflows.
  • Enforces source allowlisting, scoped authentication, and serialized processing.
  • Adds comprehensive offline contract tests and setup documentation.
File Description
.github/​workflows/​team-memory-tests.yml Runs pinned offline contract checks.
.github/​workflows/​team-memory-post-merge.yml Dispatches validated push metadata to the coordinator.
.github/​workflows/​team-memory-coordinator.yml Adds centralized reconciliation, authentication, and queueing.
.github/​actions/​queue-team-memory/​tests/​test_team_memory.py Tests dispatch, provenance, authorization, discovery, and receipts.
.github/​actions/​queue-team-memory/​README.md Documents architecture, prerequisites, and operations.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Remove Java Pack's duplicate contract suite and dedicated test workflow. Retain shared-action runtime consumers and document IssueLens test ownership.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep only the remote IssueLens workflow consumers. Remove the remaining local setup README; prerequisites remain in the PR description.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Production behavior depends on externally configured App permissions, Azure OIDC, secrets, and source policy that require human operational verification.

0 open findings

🧠 Review effort: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants