You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .agents/skills/nemoclaw-maintainer-cut-release-tag/SKILL.md
+18-3Lines changed: 18 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -126,7 +126,7 @@ When the entry is waived, show the recorded waiver reason in the plan presentati
126
126
127
127
For the plan's full `origin/main` SHA, require a completed, successful `Release qualification` check from a pre-tag `.github/workflows/e2e.yaml` run.
128
128
The workflow planner derives the required jobs from the workflow's E2E metadata.
129
-
By default, the check requires every release-required E2E execution result, including `Exact staging Brev Launchable`, to succeed.
129
+
By default, the check requires every release-required execution result, including `Publish staging Brev Launchable image`, to succeed.
130
130
A repository administrator may waive one or more release-required E2E execution jobs for a documented release exception.
131
131
The waiver requires a comma-separated `release_qualification_waived_jobs` list and a `release_qualification_waiver_reason`.
132
132
The reason must begin with an ASCII letter or digit and contain 10-500 characters chosen from ASCII letters, digits, spaces, and `.,:;/_()'-`.
@@ -168,6 +168,20 @@ Before showing the confirmation prompt, present the candidate SHA, workflow URL,
168
168
For a waived run, also present the waived jobs, their outcomes, the waiver reason, and both recorded actor identities.
169
169
No release-note-only delta exception is currently defined.
170
170
171
+
After image publication succeeds, present this advisory manual validation:
172
+
173
+
- State that the image-publication job built and published the candidate image to the staging family used by the [NemoClaw staging Launchable](https://brev.nvidia.com/launchable/deploy/now?launchableID=env-3GdbIjswX4fs3VJ6cYRHr5zoQXo).
174
+
- Encourage the maintainer to deploy one instance and hand its Brev environment URL to a Codex session that invokes `nemoclaw-maintainer-validate-launchable`.
175
+
- Require the manual validation to compare the deployed concrete image with `launchable-image.json`; do not assume that the mutable family still points to the candidate.
176
+
- State that browser-control capability is required for Codex to click and verify the web interface.
177
+
- State that a securely supplied inference credential is required to complete hosted and sandbox inference validation. Never ask the maintainer to paste the credential into chat.
178
+
- Record the manual result as `complete pass`, `partially blocked`, `failed`, or `not run` when the maintainer provides it.
179
+
180
+
This manual validation is advisory while the automated Launchable path is blocked by issue #8924.
181
+
Its absence, partial result, or failure does not block the signing preflight, confirmation prompt, or release tag.
182
+
Do not describe successful image publication as successful Launchable, runtime, or inference validation.
183
+
Apply the temporary policy in [Pre-Tag E2E Evidence](../nemoclaw-maintainer-policies/references/release-train.md#temporary-staging-launchable-qualification-policy): NemoClaw maintainers own it while #8924 remains open, the successful exact image-publication job and artifact remain required release evidence under normal Actions retention, and the full automated lane returns only after a checksum-pinned Brev release passes deployment through verified cleanup on trusted `main`.
184
+
171
185
Run the release script's signing preflight before asking for confirmation:
172
186
173
187
```bash
@@ -322,10 +336,11 @@ If the Announcement is valid, return its URL with the release artifacts and mark
322
336
323
337
- Plan generation fails: fix the named precondition, then regenerate the plan.
324
338
- Planned changelog entry is missing or malformed: stop before plan generation and run the pre-tag `nemoclaw-contributor-update-docs` workflow. Use post-release recovery only when the tag already exists.
325
-
- Full-mode E2E waits in the Launchable concurrency queue: keep the run pending until the earlier Launchable E2E job finishes.
339
+
- Full-mode E2E waits in the Launchable concurrency queue: keep the run pending until the earlier Launchable image-publication job finishes.
326
340
- Full-mode E2E ran for another SHA: reject the run and dispatch full mode for the plan candidate SHA.
327
341
- No qualifying `Release qualification` exists: inspect the GitHub result and run pre-tag E2E for the planned SHA only when no qualifying run already exists. Use a job waiver only with explicit repository administrator authorization. Do not release until the release script accepts the canonical check.
328
-
- Launchable E2E or cleanup fails: inspect the diagnostic artifacts, correct the failure, and rerun the affected E2E work. Do not infer Launchable success from another workflow result.
342
+
- Launchable image publication fails: inspect `launchable-image.json` and the producer run, correct the failure, and rerun the affected work. Do not infer image publication from manual Launchable validation.
343
+
- Advisory Launchable validation is blocked or fails: record the exact partial result and continue the release flow. Do not convert the result into a release gate or an automated E2E pass.
329
344
-`origin/main` moved after plan generation: regenerate the plan and ask for the new confirmation phrase.
330
345
- Remote semver tag already exists: stop; do not retag unless the maintainer explicitly starts protected-tag remediation.
331
346
- Signing preflight fails: fix the reported Git signer or signing-key failure. Run the preflight again before requesting confirmation.
Copy file name to clipboardExpand all lines: .agents/skills/nemoclaw-maintainer-e2e/SKILL.md
+30-24Lines changed: 30 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
name: nemoclaw-maintainer-e2e
3
-
description: Dispatches and verifies trusted GitHub Actions E2E for NemoClaw maintainers, including manual PR E2E for the current PR head commit. Use for requests such as run E2E for PR #123, run the E2E suite, run the Launchable E2E, run the full E2E suite, deploy pre-release full E2E, run pre-tag full E2E, or run release-candidate E2E.
3
+
description: Dispatches and verifies trusted GitHub Actions E2E for NemoClaw maintainers, including manual PR E2E for the latest PR commit and staging Launchable image publication. Use for requests such as run E2E for PR #123, run the E2E suite, publish the Launchable image, run the Launchable E2E, run the full E2E suite, deploy pre-release full E2E, run pre-tag full E2E, or run release-candidate E2E.
4
4
---
5
5
6
6
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
@@ -34,14 +34,14 @@ The workflow does not rotate or revoke these API keys or messaging credentials.
34
34
Live targets can create external resources.
35
35
After a failure, inspect the artifacts and remove resources that target cleanup did not remove.
36
36
37
-
`Exact staging Brev Launchable` reads these credentials from repository Actions secrets:
37
+
`Publish staging Brev Launchable image` reads this credential from repository Actions secrets:
38
38
39
-
-`BREV_API_KEY` authenticates the Brev CLI for workspace operations in the organization identified by `BREV_ORG_ID`.
40
39
-`NEMOCLAW_IMAGE_DISPATCH_TOKEN` is exposed as `GH_TOKEN` only to the trusted host script. It grants Actions read/write access to `brevdev/nemoclaw-image`, which the script uses to dispatch the image workflow, inspect its run, and download its handoff artifact.
41
-
-`NVIDIA_INFERENCE_API_KEY` is exported into the Brev guest for the full E2E process. Code in the baked candidate checkout can read and use it.
42
40
43
-
These credentials remain valid until they expire or an administrator revokes them in their issuing services. If cleanup fails, remove the recorded Brev workspace. Rotate or revoke each credential to remove later access.
44
-
This Brev credential boundary applies only to trusted Launchable or full manual dispatches against `main`. It does not apply to `main` pushes or manual PR runs.
41
+
This credential remains valid until it expires or an administrator revokes it in GitHub. Rotate or revoke it to remove later access.
42
+
The job does not receive `BREV_API_KEY`, `BREV_ORG_ID`, or `NVIDIA_INFERENCE_API_KEY`.
43
+
It does not install or authenticate the Brev CLI, create a workspace, or run inference.
44
+
This image-publication credential boundary applies only to trusted Launchable or full manual dispatches against `main`. It does not apply to `main` pushes or manual PR runs.
45
45
46
46
For `managed-image-protected-runtime`, the workflow supplies the long-lived `NVIDIA_API_KEY` repository secret only to the trusted qualification step. Trusted host code uses it for NGC login and passes it as `NGC_API_KEY` and `NIM_NGC_API_KEY` to the temporary NIM container. Candidate managed sandboxes receive generated local route tokens instead of this key. The live fixture removes the temporary NIM container only if its exact ID, name, requested image, immutable image ID, cohort owner, and provider kind match the recorded authority. The test fails if evidence is missing or ambiguous, a name is reused, authority drifts, removal is indeterminate, or the exact ID or name remains. A cleanup refusal can leave the container and its API key in place until runner teardown. The final workflow step removes the job's isolated Docker credential directory and fails if that removal does not complete. The workflow does not revoke the NVIDIA API key. Revoke it, or rotate it and disable the old value, in the issuing NVIDIA service. Verify that the exposed key is no longer valid.
47
47
@@ -67,7 +67,7 @@ Require a review reason containing 10 to 500 printable characters.
67
67
Choose exactly one mode:
68
68
69
69
- For a PR revision run, leave `E2E_JOBS` empty. The run selects:
- these controller-selected registry targets: `ubuntu-policy-custom-missing-presets-negative`, `ubuntu-repo-cloud-langchain-deepagents-code`, `ubuntu-repo-cloud-openclaw`, and `ubuntu-repo-docker-post-reboot-recovery`.
73
73
The run skips `jetson-nvmap-gpu` unless `allow_jetson_dispatch` is `true`.
@@ -158,20 +158,25 @@ A changed head repository, head SHA, or base SHA invalidates the evidence and re
| “Run the E2E suite” | Ordinary | empty |`false`|
161
-
| “Run the Launchable E2E” | Launchable |`staging-brev-launchable`|`false`|
161
+
| “Publish the Launchable image” | Launchable image |`staging-brev-launchable`|`false`|
162
+
| “Run the Launchable E2E” | Clarify before dispatch | not applicable | not applicable |
162
163
| “Run the full E2E suite” | Full | empty |`true`|
163
164
| “deploy pre-release full E2E” | Full | empty |`true`|
164
165
| “run pre-tag full E2E” | Full | empty |`true`|
165
166
| “run release-candidate E2E” | Full | empty |`true`|
166
167
| “run pre-tag E2E with an administrator job waiver” | Administrator-waived full | empty |`true`|
167
168
168
169
A generic E2E request must not authorize the Brev Launchable path.
170
+
For “Run the Launchable E2E,” explain that issue #8924 blocks automated deployment, runtime, and inference validation.
171
+
Ask whether the maintainer wants image publication or advisory validation through `nemoclaw-maintainer-validate-launchable` against one deployed instance.
172
+
Do not dispatch until the maintainer selects one of those operations.
169
173
Do not infer full mode from words such as “all” or “complete.”
170
-
Ask for clarification only when the request contains conflicting mode phrases.
174
+
Ask for clarification when the request uses the legacy Launchable E2E phrase or contains conflicting mode phrases.
The `include_staging_brev_launchable` input adds the Launchable E2E job to that same run.
276
+
Empty `jobs` and `targets` select every default-selected workflow E2E except `Publish staging Brev Launchable image`.
277
+
The `include_staging_brev_launchable` input adds the Launchable image-publication job to that same run.
273
278
The trusted `main` workflow verifies that the dispatching and rerunning actors have
274
279
repository `maintain` or `admin` permission before the Launchable path's source
275
280
checkout. That role check is the authorization.
@@ -295,7 +300,7 @@ empty-selector manual run or enable explicit qualification selection. Set it
295
300
only after a repository administrator confirms an online DGX Spark runner in
296
301
the authoritative runner inventory.
297
302
If GitHub pauses the qualification job for the `approve-dgx-spark-image-qualification` environment, an authorized environment reviewer must approve it before qualification starts.
298
-
`Exact staging Brev Launchable` does not require environment approval.
303
+
`Publish staging Brev Launchable image` does not require environment approval.
299
304
300
305
Find the run by its unique title:
301
306
@@ -329,7 +334,7 @@ Wait for completion:
329
334
gh run watch "$RUN_ID" --repo NVIDIA/NemoClaw
330
335
```
331
336
332
-
Launchable and full modes can wait in the non-cancelling Launchable concurrency queue.
337
+
Launchable image and full modes can waitin the non-cancelling Launchable concurrency queue.
333
338
Queued, waiting, or accepted dispatch state is not success.
334
339
Classify the completed workflow and `Release qualification` job with the checks below.
335
340
@@ -351,20 +356,21 @@ Require `run-$RUN_ID.json` to report:
351
356
- `head_sha` equal to `CANDIDATE_SHA`;
352
357
- `status` equal to `completed`.
353
358
354
-
For ordinary, Launchable, and unwaived full modes, require `conclusion` equal to `success`.
359
+
For ordinary, Launchable image, and unwaived full modes, require `conclusion` equal to `success`.
355
360
For administrator-waived full mode, permit `conclusion` equal to `success` or `failure`.
356
361
A `failure` conclusion is acceptable only when one completed, successful `Release qualification` job and a valid exact-run waiver artifact with at least one canonical waived job failure both exist.
357
362
358
-
For Launchable mode, also require `jobs-latest-$RUN_ID.json` to contain one completed, successful
359
-
`Exact staging Brev Launchable` job. Return the workflow and job URLs.
363
+
For Launchable image mode, also require `jobs-latest-$RUN_ID.json` to contain one completed, successful
364
+
`Publish staging Brev Launchable image` job. Return the workflow and job URLs.
365
+
Require its artifact to contain `launchable-image.json`for the selected candidate SHA and concrete staging image URI.
360
366
361
367
For a full run, with or without a job waiver, require `jobs-latest-$RUN_ID.json` to contain one completed, successful
362
368
`Release qualification` job. Return its job URL with the workflow URL.
363
-
In full mode, that job waits for every default-required E2E result, including `Exact staging Brev Launchable`.
364
-
The Launchable job directly verifies the candidate checkout, in-guest full E2E result, and workspace cleanup before it succeeds.
365
-
Its `launchable-e2e.json`, `full-e2e.log`, and `cleanup.json` artifacts remain available for diagnosis.
369
+
In full mode, that job waits for every default-required result, including `Publish staging Brev Launchable image`.
370
+
The Launchable image job verifies only the exact candidate image producer receipt and staging-family publication.
371
+
Its `launchable-image.json` artifact records Launchable, runtime, and inference validation as not run.
366
372
A skipped, cancelled, queued, or failed `Release qualification` job is not evidence.
367
-
A Launchable-only run is not full-mode or pre-tag release evidence.
373
+
A Launchable image-only run is not full-mode or pre-tag release evidence.
368
374
369
375
For administrator-waived full mode, the job waits for every unwaived release-required result.
370
376
A waived execution job may fail without failing `Release qualification`.
0 commit comments