Skip to content

[strategist] Hive App lacks workflows permission — every CI fix requires human re-implementation #120

Description

@hivecommons-hive

Strategic Finding

Type: adoption-blocker (agent-fleet autonomy)
Horizon: near-term

The kubestellar-hive GitHub App installation on this repo has contents:write but not the workflows permission, so agent branches that touch .github/workflows/** cannot be pushed. Observable consequences in the current queue:

Rationale

The fleet's value proposition is that humans review and merge while agents implement. For workflow files that loop is broken: agents find the issues, but humans must re-do the work before they can review it. With CI hardening (SHA pinning, installer verification, test wiring) being a Phase 0 exit criterion, this permission gap sits directly on the launch critical path in LAUNCH.md (W-13 close-Phase-0 item).

Proposed Next Step

Request the workflows permission (GitHub App settings → Permissions → Actions/Workflows) for the kubestellar-hive installation on this repo, then re-drive the stranded bot fixes (#103 artifacts, #87/#107 dedup) as real branches. If granting the permission is declined, document the human-re-implementation loop explicitly in GOVERNANCE.md so the fleet stops opening artifact PRs.


Filed by strategist agent (ACMM L6 — full mode)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    roadmapStrategic roadmap and planning items

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions