You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Follow-up to #6943, #7050, and the implementation merged in #7270.
Summary
Make pre-release and pre-tag full E2E a first-class maintainer workflow that runs the ordinary full GitHub Actions E2E suite together with the exact staging Brev Launchable qualification for one candidate SHA.
A maintainer should be able to ask an agent to “deploy a pre-release full E2E” or “run pre-tag full E2E” and receive one trusted GitHub Actions run whose evidence proves both the default suite and the Exact staging Brev Launchable job ran successfully against the intended candidate.
The release-tag skill must verify that job-level evidence before it treats the run as release evidence. Overall workflow success is insufficient because the Brev job may be skipped.
Current behavior
PR #7270 added staging-brev-launchable as a protected job in the existing .github/workflows/e2e.yaml, but the maintainer workflow is not composed yet:
No maintainer skill owns a natural-language request to deploy pre-release or pre-tag full E2E.
A default manual E2E dispatch runs default-enabled tests but skips staging-brev-launchable because the jobs input does not select it.
A selective dispatch with jobs=staging-brev-launchable can select the Brev job, but it does not also select the ordinary default suite.
The NEMOCLAW_BREV_LAUNCHABLE_E2E_ENABLED repository variable is an infrastructure-readiness gate and is currently not configured.
nemoclaw-maintainer-cut-release-tag audits an evidence ledger but does not dispatch missing pre-tag evidence.
A successful workflow conclusion does not prove the Brev job ran; the job may have concluded skipped.
A generic request such as “run the E2E suite” is ambiguous and may run local live E2E or an ordinary Actions dispatch without image qualification.
Proposed design
1. Add a per-run pre-tag input
Add an explicit boolean workflow-dispatch input such as:
include_staging_brev_launchable:
description: Include exact staging Brev Launchable qualificationtype: booleandefault: false
When the input is true, a manual dispatch with empty jobs and targets must run both:
the ordinary default-enabled full E2E suite; and
staging-brev-launchable in the same workflow run.
Keep selective jobs and targets unchanged unless the caller explicitly selects the Brev job. Make the Brev job discoverable in the Actions input descriptions.
Do not toggle repository variables around individual runs. Treat NEMOCLAW_BREV_LAUNCHABLE_E2E_ENABLED as a persistent infrastructure-readiness switch that a release administrator enables once the protected environment, secrets, staging Launchable ID, and ownership are ready. A requested pre-tag run must fail closed with an actionable prerequisite when readiness is disabled.
2. Add a small general maintainer E2E skill
Add nemoclaw-maintainer-e2e as the single agent-facing entry point for trusted GitHub Actions E2E dispatches. Keep the skill small and make its language routing explicit:
“run the E2E suite” runs the ordinary default-enabled GitHub Actions E2E suite without Brev Launchable qualification;
“run the full E2E suite” runs the ordinary default-enabled suite plus Exact staging Brev Launchable;
“deploy pre-release full E2E,” “deploy pre-tag full E2E,” and “run release-candidate E2E” select the same full mode and bind its evidence to the intended candidate SHA.
The skill must not interpret a generic E2E request as permission for the protected, billable Brev path. It must use trusted GitHub Actions for these maintainer requests rather than substituting local npm run test:live-e2e, unless the maintainer explicitly asks for local execution.
The skill must:
Resolve and record the selected origin/main SHA for every Actions dispatch.
For ordinary mode, dispatch .github/workflows/e2e.yaml from trusted main with the default full-suite inputs and without Brev qualification.
For full mode, confirm the persistent Brev qualification readiness gate is enabled without reading or handling cloud credentials.
Dispatch .github/workflows/e2e.yaml from trusted main with the default full-suite inputs and include_staging_brev_launchable=true.
Record the workflow run URL and verify its head_sha equals the selected SHA.
Wait for the workflow and, in full mode, protected-environment approval without treating dispatch acceptance as success.
In full mode, require the Exact staging Brev Launchable job itself to conclude success; skipped, cancelled, queued, or failed is not evidence.
Verify that full-mode qualification evidence identifies the same SHA and that cleanup evidence reports verified workspace absence.
Return the run URL and conclusion in ordinary mode; additionally return the Brev job URL, attempt number, qualification identity, and cleanup result in full mode.
Mark a full run against current origin/main as provisional release evidence when no release plan exists. Invalidate or rerun it when a later release candidate differs, except under any separately accepted narrow release-note-only delta policy.
3. Integrate with release tagging
Update nemoclaw-maintainer-cut-release-tag and the higher-level evening/release orchestration so that, for the release-plan candidate SHA, they:
invoke nemoclaw-maintainer-e2e in full mode when applicable green evidence does not already exist;
inspect job-level evidence rather than accepting the workflow-level conclusion;
require a successful Exact staging Brev Launchable job for the exact candidate SHA;
reject a run in which the Brev job was skipped or ran against another SHA;
map the successful run, job URL, and attempt into the canonical pre-tag E2E evidence ledger; and
stop before the release confirmation phrase when evidence is absent, unless the maintainer records an explicit itemized exception under the existing release policy.
Evidence accumulated from an earlier candidate must be discarded when the release plan changes, except for any separately accepted narrow release-note-only delta policy.
Acceptance criteria
Add one small nemoclaw-maintainer-e2e skill as the agent-facing entry point for trusted GitHub Actions E2E dispatch.
“Run the E2E suite” selects ordinary mode and does not run Brev Launchable qualification.
“Run the full E2E suite” selects full mode and runs the default-enabled suite plus Exact staging Brev Launchable.
Pre-release, pre-tag, and release-candidate E2E requests select full mode and bind evidence to the intended candidate SHA.
Manual workflow dispatch exposes a documented per-run control for including staging Brev Launchable qualification.
One pre-tag full dispatch runs the default-enabled E2E suite and Exact staging Brev Launchable in the same workflow run.
Ordinary selective E2E and generic agent requests do not unexpectedly incur the Brev qualification path.
The persistent readiness variable is never temporarily toggled by the skill.
A disabled or incomplete readiness configuration fails closed with an actionable message.
Full mode binds the workflow run, Brev job, qualification evidence, and cleanup evidence to the selected SHA.
skipped Brev jobs are rejected as release evidence even when the workflow conclusion is successful.
nemoclaw-maintainer-cut-release-tag dispatches or consumes applicable Brev qualification evidence before requesting release confirmation.
A candidate-SHA change invalidates stale evidence and triggers requalification or an explicit policy exception.
Skill tests or deterministic fixtures cover routing, dispatch inputs, exact-SHA verification, job-level evidence, invalidation, and handoff to tag cutting.
Non-goals
Moving latest or lkg, or promoting a production image.
Parent epic: #7051
Follow-up to #6943, #7050, and the implementation merged in #7270.
Summary
Make pre-release and pre-tag full E2E a first-class maintainer workflow that runs the ordinary full GitHub Actions E2E suite together with the exact staging Brev Launchable qualification for one candidate SHA.
A maintainer should be able to ask an agent to “deploy a pre-release full E2E” or “run pre-tag full E2E” and receive one trusted GitHub Actions run whose evidence proves both the default suite and the
Exact staging Brev Launchablejob ran successfully against the intended candidate.The release-tag skill must verify that job-level evidence before it treats the run as release evidence. Overall workflow success is insufficient because the Brev job may be skipped.
Current behavior
PR #7270 added
staging-brev-launchableas a protected job in the existing.github/workflows/e2e.yaml, but the maintainer workflow is not composed yet:staging-brev-launchablebecause thejobsinput does not select it.jobs=staging-brev-launchablecan select the Brev job, but it does not also select the ordinary default suite.NEMOCLAW_BREV_LAUNCHABLE_E2E_ENABLEDrepository variable is an infrastructure-readiness gate and is currently not configured.nemoclaw-maintainer-cut-release-tagaudits an evidence ledger but does not dispatch missing pre-tag evidence.skipped.Proposed design
1. Add a per-run pre-tag input
Add an explicit boolean workflow-dispatch input such as:
When the input is true, a manual dispatch with empty
jobsandtargetsmust run both:staging-brev-launchablein the same workflow run.Keep selective jobs and targets unchanged unless the caller explicitly selects the Brev job. Make the Brev job discoverable in the Actions input descriptions.
Do not toggle repository variables around individual runs. Treat
NEMOCLAW_BREV_LAUNCHABLE_E2E_ENABLEDas a persistent infrastructure-readiness switch that a release administrator enables once the protected environment, secrets, staging Launchable ID, and ownership are ready. A requested pre-tag run must fail closed with an actionable prerequisite when readiness is disabled.2. Add a small general maintainer E2E skill
Add
nemoclaw-maintainer-e2eas the single agent-facing entry point for trusted GitHub Actions E2E dispatches. Keep the skill small and make its language routing explicit:Exact staging Brev Launchable;The skill must not interpret a generic E2E request as permission for the protected, billable Brev path. It must use trusted GitHub Actions for these maintainer requests rather than substituting local
npm run test:live-e2e, unless the maintainer explicitly asks for local execution.The skill must:
origin/mainSHA for every Actions dispatch..github/workflows/e2e.yamlfrom trustedmainwith the default full-suite inputs and without Brev qualification..github/workflows/e2e.yamlfrom trustedmainwith the default full-suite inputs andinclude_staging_brev_launchable=true.head_shaequals the selected SHA.Exact staging Brev Launchablejob itself to concludesuccess;skipped, cancelled, queued, or failed is not evidence.origin/mainas provisional release evidence when no release plan exists. Invalidate or rerun it when a later release candidate differs, except under any separately accepted narrow release-note-only delta policy.3. Integrate with release tagging
Update
nemoclaw-maintainer-cut-release-tagand the higher-level evening/release orchestration so that, for the release-plan candidate SHA, they:nemoclaw-maintainer-e2ein full mode when applicable green evidence does not already exist;Exact staging Brev Launchablejob for the exact candidate SHA;Evidence accumulated from an earlier candidate must be discarded when the release plan changes, except for any separately accepted narrow release-note-only delta policy.
Acceptance criteria
nemoclaw-maintainer-e2eskill as the agent-facing entry point for trusted GitHub Actions E2E dispatch.Exact staging Brev Launchable.Exact staging Brev Launchablein the same workflow run.skippedBrev jobs are rejected as release evidence even when the workflow conclusion is successful.nemoclaw-maintainer-cut-release-tagdispatches or consumes applicable Brev qualification evidence before requesting release confirmation.Non-goals
latestorlkg, or promoting a production image.npm run test:live-e2eequivalent to release-candidate image qualification.