Skip to content

Update docs-agent.yml - #348

Merged
Avi-Akeyless merged 1 commit into
v1.0from
Avi-Akeyless-patch-2
Oct 11, 2026
Merged

Avi-Akeyless merged 1 commit into
v1.0from
Avi-Akeyless-patch-2

Conversation

@Avi-Akeyless

Copy link
Copy Markdown
Collaborator

Summary

Adds a new docs-agent.yml workflow (manually triggered via workflow_dispatch) that lets authorized users kick off Claude Code to create or update documentation in this repo and open a PR automatically.

  • Accepts either a free-text feature description or a Jira ticket key/link; when a ticket is given, the workflow fetches its summary and description from Jira Cloud and feeds that to Claude as reference material.
  • A doc_action choice input tells Claude whether to create a new doc or edit an existing one.
  • All credentials (GitHub write token, Anthropic API key, Jira email + API token) are fetched just-in-time from Akeyless using GitHub's built-in OIDC token — nothing is stored as a GitHub secret.
  • Secrets are wired per-step via step outputs (export-secrets-to-environment: false), not broadcast job-wide, so each credential is only visible to the specific step that needs it.
  • GITHUB_OUTPUT heredoc writes use a randomized delimiter to prevent injection from attacker-influenced ticket text.
  • --disallowedTools "Task" is set on the Claude Code step so it can't delegate research to a background subagent it would never get a response from in this one-shot run — without this, a run could report success while doing nothing.
  • Run restricted to an actor allowlist (Avi-Akeyless, EldadH89).

Validation

  • Manually triggered the workflow multiple times via workflow_dispatch, iterating through and fixing: a YAML heredoc indentation error, a missing Akeyless secret path (404), an empty repo variable, an expired/invalid Anthropic API key, and a run that "succeeded" but produced no PR (background-subagent issue, now fixed).
  • Verified YAML validity locally with yaml.safe_load after every edit.
  • Confirmed Jira ticket fetch and Anthropic authentication both succeed in the latest run log.
  • Next run (with the Task fix) will confirm Claude completes inline and actually produces a branch/commit/PR.

Safety Checklist

  • No GitHub secrets added to this repo; all credentials come from Akeyless via OIDC.
  • Secrets scoped to the minimum steps that need them (step outputs, not $GITHUB_ENV).
  • All fetched secret values explicitly masked in logs.
  • Workflow restricted to a named actor allowlist.
  • Jira ticket content treated as untrusted data in the prompt (explicitly labeled as reference info, not instructions) to reduce prompt-injection risk.
  • Claude's tool access scoped (--allowedTools) and background delegation disabled (--disallowedTools "Task").
  • Open/known issue: --allowedTools does not appear to fully restrict Claude's visible toolset in the SDK init message (not yet root-caused; tracked separately, not a blocker for this PR).

Jira

N/A — this PR is the Docs Agent tooling itself, not a documentation change tied to a specific ticket.

@coderabbitai

coderabbitai Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository: akeylesslabs/technical-documentation/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 22442fe4-881c-466c-b39f-be872cd06760

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@Avi-Akeyless
Avi-Akeyless merged commit 05724d8 into v1.0 Oct 11, 2026
6 checks passed
@Avi-Akeyless
Avi-Akeyless deleted the Avi-Akeyless-patch-2 branch October 11, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant