Skip to content

[oblt-aw] Control Plane Dashboard #3963

Description

Control Plane Dashboard

Use this dashboard to enable or disable agentic workflows for this repository.
Click the checkboxes below to toggle workflows on or off.

Observability (obs)

Workflow Maturity Description
Agent Suggestions 🟠 experimental Suggests agentic workflows and improvements for the repository based on analysis of current setup. inner-workflows: obs-aw-agent-suggestions.yml
Automated Documentation 🟢 stable Analyzes documentation for gaps, outdated content, and inconsistencies; creates issues and PRs to improve docs. inner-workflows: obs-aw-autodoc.yml
Automerge 🟢 stable Enables auto-merge for allowed bot PRs (same authors as dependency-review) with oblt-aw/ai/merge-ready when validation and approval gates pass; GitHub enforces required checks at merge time. inner-workflows: obs-aw-automerge.yml
Dependency Review 🟢 stable Analyzes dependency-update PRs from bots, applies merge-ready labels when criteria are met. inner-workflows: obs-aw-dependency-review.yml
Duplicate Issue Detector 🟠 experimental Detects potential duplicate issues when a new issue is opened or when the entrypoint is run manually. inner-workflows: obs-aw-duplicate-issue-detector.yml
Issue Triage 🟡 early-adoption Triages newly opened issues using the generic issue-triage agentic workflow. inner-workflows: obs-aw-issue-triage.yml
Issue Fixer 🟠 experimental Executes generic issue fixes requested with /ai implement comments, excluding specialized security and resource-not-accessible flows. inner-workflows: obs-aw-issue-fixer.yml
Mention in Issue 🟡 early-adoption AI assistant for issues — answers questions, debugs problems, and creates PRs on demand when triggered with a /ai comment. inner-workflows: obs-aw-mention-in-issue.yml
Security 🟡 early-adoption Runs static security checks on workflows, shell scripts, and dependency manifests per the security scanning ruleset; opens issues for findings. inner-workflows: obs-aw-security-fixer.yml, obs-aw-security-issue-superseder.yml, obs-aw-security-triage.yml, obs-aw-security-injection-detector.yml, obs-aw-security-supply-chain-detector.yml, obs-aw-security-secrets-detector.yml, obs-aw-security-least-privilege-detector.yml
Resource Not Accessible by Integration 🟡 early-adoption Detects 'Resource not accessible by integration' occurrences in workflow logs, creates triage issues, triages newly opened issues, and executes fixes for issues labeled ready to fix. inner-workflows: obs-aw-resource-not-accessible-by-integration-detector.yml, obs-aw-resource-not-accessible-by-integration-fixer.yml, obs-aw-resource-not-accessible-by-integration-triage.yml
PR Buildkite Detective 🟢 stable Analyzes Buildkite CI failures for a PR when a Buildkite status check fails; posts a diagnostic comment on the pull request. inner-workflows: obs-aw-estc-pr-buildkite-detective.yml

Enable / Disable

Click a checkbox to enable or disable a workflow:

  • Agent Suggestions
  • Automated Documentation
  • Automerge
    • GitHub Actions bumps — Auto-merge for GitHub Actions and composite action version bumps.
    • pre-commit hook updates — Auto-merge for pre-commit hook dependency updates.
    • Python dependencies — Auto-merge for Python package and lockfile updates.
    • Go dependencies — Auto-merge for Go module and sum updates.
    • Update beats — Auto-merge for elastic-agent update-beats PRs (NOTICE, go modules, beats submodule).
    • Node dependencies — Auto-merge for npm/yarn/pnpm manifest, lockfile, and JS bundled dist updates.
    • Terraform / OpenTofu — Auto-merge for Terraform, OpenTofu, and Terragrunt dependency updates.
    • Open Policy Agent — Auto-merge for OPA policy and version file updates.
    • VM / container images — Auto-merge for CI runner or container image pin updates.
    • Package version — Auto-merge for .package-version bump automation.
  • Dependency Review
  • Duplicate Issue Detector
  • Issue Triage
  • Issue Fixer
  • Mention in Issue
  • Security
    • Injection Detection — Checks for script-injection vulnerabilities in workflow expressions.
    • Supply-chain Hardening — Flags unpinned third-party actions and missing provenance checks.
    • Secret Management — Detects token exposure, secrets in command strings, and improper token scoping.
    • Least Privilege — Flags excessive workflow permissions and dangerous token patterns.
  • Resource Not Accessible by Integration
  • PR Buildkite Detective

Instructions

  • Enable a workflow: Check the checkbox next to the workflow.
  • Disable a workflow: Uncheck the checkbox, then reply on this issue with a short deactivation reason (an audit comment will ask for it and mention @elastic/observablt-ci).
  • Sub-features: Indented checkboxes under a parent refine which parts of that workflow run. Sub-features take effect only while the parent workflow checkbox is enabled.
  • Audit trail: Enable/disable changes are recorded as comments on this issue (when / what / who).
  • Changes are applied at runtime when the client runs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions