Skip to content

About

Disposable, secret-free GitHub Actions laboratory for typed execution experiments

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

GitHub Actions Experiment Lab

A public, secret-free execution laboratory for disposable experiments triggered through the existing bounded GitHub actuator.

Control path

ChatGPT
  -> Base44 GitHubCommand
  -> OCI GitHub actuator worker
  -> allowlisted workflow_dispatch
  -> GitHub-hosted runner
  -> public result / replay / conflict receipt
  -> GitHub read connector

The lab is intentionally separate from production repositories. Do not add production secrets or deployment authority here.

Typed invocation contract

The allowlisted workflow is .github/workflows/actuator-v3-acceptance.yml.

Inputs:

  • actuator_command_id: durable invocation identity
  • marker: harmless typed experiment input used by the current canary harness

Semantics:

  • first use of an invocation ID + input -> execute and write results/<id>.json
  • same invocation ID + same input -> do not execute again; write replays/<id>.json with RECONCILED
  • same invocation ID + different input -> preserve the canonical result, write conflicts/<id>.json, and fail with IDEMPOTENCY_CONFLICT
  • GitHub concurrency serializes runs sharing the same invocation ID

Proven 2026-08-23

  • end-to-end observed run: 32624825545 -> success
  • replay-fence primary run: 32624913343 -> success
  • replay-fence replay run: 32624934290 -> reconciled
  • input-fence canonical run: 32625366707 -> success
  • conflicting-input run: 32625385775 -> failed closed with IDEMPOTENCY_CONFLICT
  • same-input replay after conflict: 32625418431 -> reconciled and successful

The private actuator acceptance repository was restored after the canary; its temporary workflow was removed.

Known relay limitations

  1. dispatch_workflow currently accepts duplicate Base44 rows with the same command_id and dispatches another GitHub run. Correctness is therefore fenced in this lab workflow; the relay itself is still at-least-once at the run-allocation layer.
  2. The relay currently discards GitHub's workflow run ID in its Base44 receipt. The lab writes GitHub's own github.run_id into result/replay/conflict receipts so the independent GitHub read plane can retrieve jobs and logs.
  3. A malformed workflow currently consumes the relay retry budget and terminates as MAX_ATTEMPTS_EXCEEDED rather than failing fast on a permanent workflow-definition error.

Next hardening, only if needed

Patch the existing relay, not a new actuator:

  • enforce atomic admission uniqueness for command_id
  • preserve the GitHub run ID returned/observed by dispatch
  • classify permanent dispatch errors separately from transient/ambiguous failures

Until then, this repository is suitable for secret-free experimental workloads whose actual effect is fenced by invocation ID and input hash.

About

Disposable, secret-free GitHub Actions laboratory for typed execution experiments

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors