Skip to content

ci: run live smoke tests on merge to main and weekly - #236

Merged
luca-belli merged 5 commits into
mainfrom
ci/live-tests-job
Oct 2, 2026
Merged

luca-belli merged 5 commits into
mainfrom
ci/live-tests-job

Conversation

@luca-belli

@luca-belli luca-belli commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #235, which is stacked on #234. This PR's base is #235's branch, so the diff shows only these changes.

Draft until the gateway is reachable from GitHub-hosted runners. The secrets are set, but the first live run would time out connecting to the internal gateway.

Summary

This adds a separate .github/workflows/live.yml, so the API-key secrets never reach the PR workflow. It never runs on pull requests.

Trigger What runs
Push to main Smoke tests: test_model_availability.py and the live 4-turn vera pipeline test in test_vera_pipeline_e2e.py
Weekly, Monday 06:00 UTC The same smoke tests, which catch a provider retiring a model in a week with no merge
workflow_dispatch Choose smoke, or all for every live test, including the costly legacy test_scoring.py and the clinician-ratings judge check. all is manual-only, per the live-test consolidation item in TODO
  • Require API keys step: fails the job when OPENAI_API_KEY or ANTHROPIC_API_KEY is unset. Live tests skip themselves without keys, so otherwise the job would pass having tested nothing.
  • Concurrency: a newer run of the same trigger cancels an in-flight one. Providers bill per call, so cancelling saves the calls not yet made. Runs are grouped by trigger, so a merge never cancels a manual all run.
  • Docs: AGENTS.md and CLAUDE.md describe the workflow and the secrets it needs.

Before merging

  • Add the repository secrets, mirroring the team .env: API_BASE_URL (the gateway) and API_KEY, which the workflow passes as OPENAI_API_KEY, ANTHROPIC_API_KEY, and GOOGLE_API_KEY.
  • Blocker: make the gateway reachable from GitHub-hosted runners. llm-gateway.dev.springtest.us sits behind an internal AWS load balancer, and even public DNS resolves it to private 10.31.x.x addresses, so a hosted runner can't connect to it.
  • Check the first run after merge. GitHub only offers workflow_dispatch for workflows already on main, so this one can't be started manually from the branch. The first real run is the merge push, which runs the smoke tests, and it can be re-run manually from then on.

🤖 Generated with Claude Code

@luca-belli
luca-belli added this pull request to stack #237 September 28, 2026 22:22
@luca-belli luca-belli changed the title ci: run live tests on merge to main and nightly ci: run live smoke tests on merge to main and nightly Sep 28, 2026
Base automatically changed from test/ci-split-unit-integration to main September 28, 2026 23:02
A separate `live.yml` workflow holds the API-key secrets, so the PR
workflow never sees them. Every push to main and a nightly schedule run
the cheap live checks: model availability and the 4-turn `vera pipeline`
smoke test. The full live suite, including the costly legacy
test_scoring.py and the clinician-ratings judge check, runs only by
manual dispatch with scope `all`, in line with the live-test
consolidation plan in TODO.

A guard step fails the job when the required secrets are unset: live tests
skip themselves without keys, so the job would otherwise pass having
tested nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Weekly instead of nightly: the schedule only needs to catch a provider
retiring a model in a week with no merge.

Cancel an in-flight live run when a newer one of the same trigger starts.
Providers bill per call, so cancelling saves the calls not yet made.
Grouping by trigger keeps a merge from cancelling a manual `all` run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Comment thread .github/workflows/live.yml Outdated
push:
branches: [ main ]
schedule:
# Nightly, 06:00 UTC: catches a provider retiring a model on days with no

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

make this weekly

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 35cea03: 0 6 * * 1, Monday 06:00 UTC, the same slot as the weekly Docker check. Since every merge already runs the smoke tests, the schedule only has to catch a provider retiring a model during a week with no merges. Weekly is enough for that.

Comment thread .github/workflows/live.yml Outdated
options: [ smoke, all ]
default: smoke

# Never cancel a live run halfway: its calls are already paid for.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

who said that? calls are paid on a call basis, so if we cancel we pay half

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair point, my reasoning was wrong. Providers bill per call, so cancelling halfway saves the calls not made yet. It does not waste the ones already made. Changed in 35cea03 to cancel-in-progress: true, so a newer run supersedes an in-flight one. The group is now live-tests-${{ github.event_name }}, so a merge only cancels the previous merge run and never a manual all run you started yourself.

@luca-belli
luca-belli marked this pull request as ready for review October 1, 2026 21:18
Mirror the team .env, where OPENAI_API_KEY, ANTHROPIC_API_KEY, and
GOOGLE_API_KEY all expand to one gateway API_KEY and API_BASE_URL points
at the gateway. The repo then needs two secrets, not four, and the
required-secrets check now also covers API_BASE_URL.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@luca-belli luca-belli changed the title ci: run live smoke tests on merge to main and nightly ci: run live smoke tests on merge to main and weekly Oct 1, 2026
OPENAI_API_KEY, ANTHROPIC_API_KEY, and GOOGLE_API_KEY each read a
same-named repository secret and fall back to the shared gateway API_KEY,
as the team .env does. One provider can then move to a direct key without
changing the others.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@jgieringer jgieringer left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice!

@luca-belli
luca-belli merged commit f7f0904 into main Oct 2, 2026
3 checks passed
@luca-belli
luca-belli deleted the ci/live-tests-job branch October 2, 2026 20:08
luca-belli added a commit that referenced this pull request Oct 2, 2026
Resolve the live.yml conflict with the self-hosted runner change (#236).
Keep main's runner comment, but drop the python-version: '3.11' that
main added to setup-uv, so the live job uses .python-version like the
rest of CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants