DevOps Roadmap¶
This document tracks CI/CD pipeline improvements for hermes-agent-helm.
Items are derived from a source-control and DevOps review of the current
.github/workflows/ configuration.
Grouped by area and ordered by priority within each group.
Source Control¶
🔴 High priority¶
- [ ] Enable branch protection on
main - Require at least one PR before merging (no direct push to
main) - Add
validate-chartas a required status check -
Risk today: a broken commit can hit
mainand immediately triggerrelease-chart.yamlwithout any CI gate -
[ ] Include workflow file changes in
validate-charttrigger - Current path filter watches
charts/hermes-agent/**and.github/workflows/validate-chart.yamlonly - Changes to
cron-fetch-image.yaml,release-chart.yaml,propose-release.yaml, etc. land onmainunvalidated - Add
.github/workflows/**to thepaths:trigger (or at minimum lint YAML withactionlint)
🟡 Medium priority¶
- [ ] Resolve the unused
devbranch strategy validate-charttriggers on[dev, main]but all work goes directly tomain; thedevbranch has never been used in practice- Either adopt a
dev → mainmerge flow, or removedevfrom trigger lists and clean upCONTRIBUTING.mdso the documented strategy matches reality
Pipeline Design¶
🟡 Medium priority¶
- [ ] Split
release-chartinto independent OCI and gh-pages jobs - Currently a single job runs OCI push → gh-pages deploy in sequence
- If OCI push succeeds but gh-pages fails, re-running skips everything (tag-existence guard) - partial deployment with no automatic recovery
-
Splitting into two jobs (with a shared
needs:on a tagging step) allows each to be re-run independently -
[ ] Close the "release commit is not tested" gap
- Changesets release PRs touch only generated version metadata,
Chart.yaml, docs, andCHANGELOG.md, sofunctional=false→ kind cluster test is skipped - The last merged commit before shipping is never integration-tested
- Options: (a) add a lightweight smoke test that always runs on a release PR, or (b) document the gap and accept it as a known trade-off given that the preceding feature commit was tested
🟢 Low priority¶
- [ ] Abstract the runner label into a repository variable
- All workflows hard-code
ubuntu-26.04-arm; if that image is deprecated or has an outage, every workflow fails simultaneously - Use
runs-on: ${{ vars.RUNNER_LABEL || 'ubuntu-latest' }}so the fallback can be changed without a code edit - See fallback design note below
Security¶
🟢 Low priority¶
- [ ] Add Helm template security scanning
- No
kubesec,trivy,checkov, orkube-scorescan on rendered templates today - Suggested insertion point: new step in
validate-chart / lintjob, runninghelm template | trivy config -orkubesec scan - -
Cosign signing proves provenance but does not validate what was signed
-
[ ] Generate and attach SBOM to each release
release-chart.yamlsigns the OCI artifact but produces no Software Bill of Materialssyftorcosign attest --predicate(CycloneDX/SPDX) can be added as a post-push step
Operations¶
🟢 Low priority¶
- [ ] Prune old chart packages from gh-pages
release-chart.yamluseskeep_files: true; every release accumulates a new.tgzon thegh-pagesbranch indefinitely-
Add a cleanup step that retains the last N versions (e.g., 10) and removes older
.tgzfiles before regeneratingindex.yaml -
[ ] Harden the AI advisor fallback in
upstream-review - If the NVIDIA NIM endpoint is down or quota is exhausted, the
upstream-reviewjob silently fails or produces no GitHub issue - Add explicit
continue-on-error: truewith a step that posts a fallback comment/issue when the AI call fails, so the failure is visible
Notes¶
Runner fallback note¶
GitHub Actions does not natively support "try runner A, fall back to runner B."
The runs-on: [label-a, label-b] array syntax means all labels must match,
not first available. The repository-variable approach is the lowest-overhead
workaround: a single settings change propagates to all workflows instantly.
Functional diff filter design¶
The changes job in validate-chart deliberately skips the kind cluster
test for release-only commits (version bump + docs). This is an intentional
cost/speed trade-off; the item above ("release commit is not tested") captures
the known gap for future review, not necessarily for immediate fixing.
Last reviewed: 2026-06-29