Repository navigation
feat(infra): add github pr event feed - #7403
t3-code[bot] wants to merge 2 commits into
Conversation
Co-authored-by: Alex Southwell <4596216+saphid@users.noreply.github.com>
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
Co-authored-by: Alex Southwell <4596216+saphid@users.noreply.github.com>
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR introduces a new Cloudflare Worker service with production deployment, webhook signature verification, and bearer token authentication. New infrastructure capabilities with security-sensitive operations warrant human review. You can add or adjust custom eligibility rules. Learn more. |
|
Note 🤖 GPT-5.6 Sol responding on behalf of Theo We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together. This adds a separate GitHub webhook, Durable Object event log, SSE service, deployment workflow, and operations runbook. T3 Code does not need a second pull-request event service for its current operation. If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. |
what changed
infra/github-eventswhy
pr babysitters currently need to poll github independently, which wastes rate limit and duplicates work. this gives contributors one authenticated stream with the event content needed to react to pr activity.
verification
vp fmt --check infra/github-events docs/operations/github-pr-event-feed.mdvp lint infra/github-eventsvp run --filter t3code-github-events typecheck/healthreturned 200deployment
not deployed from this pr. production setup needs cloudflare credentials plus fresh webhook and feed secrets, followed by the github repository webhook configuration documented in
docs/operations/github-pr-event-feed.md.checklist
request provenance
Note
Medium Risk
New internet-facing webhook and token-authenticated SSE surface with HMAC verification and fail-closed config, but mishandling could leak or drop PR automation events; deployment and secret rotation are operational dependencies.
Overview
Adds a new
infra/github-eventsCloudflare Worker so PR babysitters can subscribe to GitHub activity instead of polling the API.The worker accepts signed webhooks at
/v1/github/webhook, normalizes PR-related deliveries (comments, reviews, checks, workflows, statuses), and forwards them to a per-repoGitHubEventHubDurable Object. The hub stores an ordered replay window (512 events), deduplicates deliveries (10k ids), enriches SHA-only CI/status events from a head-sha→PR index, and streamsgithubSSE messages from/v1/repos/{owner}/{repo}/eventswith bearer auth, optionalpullfiltering, and resume viaLast-Event-ID/after(including 410 / 409 cursor errors).docs/operations/github-pr-event-feed.mddocuments deploy secrets, GitHub webhook setup, subscription examples, event envelope, and security limits. Alchemy wiring lives inalchemy.run.ts; behavior is covered by unit tests across normalization, signatures, HTTP handling, event log, and SSE formatting.Reviewed by Cursor Bugbot for commit 2c46d3c. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Add GitHub PR event feed service as a Cloudflare Worker with SSE streaming
GitHubEventHubDurable Object persists events in SQLite, deduplicates by delivery ID, maintains a rolling retention window, and streams retained+live events to SSE consumers with optional PR-number filtering and cursor-based resume.POST /v1/github/webhookverifies HMAC-SHA256 signatures, enforces a 512 KiB / 10-second body limit, normalizes eight GitHub webhook event types into a canonical envelope, and restricts to a configured repository allowlist.GET /v1/repos/:owner/:repo/eventsserves SSE with bearer token auth, returning 410 when the resume cursor has expired beyond the retention window.MAX_SUBSCRIBERS) and PR-head association memory is bounded; overflow drops connections silently.Macroscope summarized 2c46d3c.