You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As a maintainer who sometimes takes the agent fleet offline deliberately (e.g. disabling CLAUDE_CODE_OAUTH_TOKEN to conserve quota),
I want "agents intentionally paused" to be a first-class, visible state,
so that a deliberate pause doesn't present as a mysterious fleet-wide outage — red dispatch runs on every event, silently stalled PRs, and hours of diagnosis to rediscover a decision the maintainer already made.
Problem — observed 2026-08-16→18
The maintainer disabled CLAUDE_CODE_OAUTH_TOKEN to limit token usage until the quota reset. Effects, none of which announced the cause:
A single explicit switch (suggestion: repo/org Actions variableAGENTS_PAUSED=true, since variables are visible where secrets are not) short-circuits agent dispatch workflows (dev-lead, pr-review trigger paths) as an early exit 0 step with a ::notice::agents paused by maintainer (AGENTS_PAUSED) — runs conclude green/neutral, not red.
When the required engine secret is absent and AGENTS_PAUSED is NOT set, the dispatch fails fast with an error that names the secret and links this issue — one clear line, not a secrets-evaluation stack error.
scripts/validate-engines.sh (already the engine-availability preflight) recognizes and reports the paused state distinctly from a misconfiguration.
The fleet monitor treats paused runs as healthy/neutral, not failures.
Docs: one paragraph in AGENTS.md on how to pause/resume the fleet deliberately.
Dev Notes
The reusable declares CLAUDE_CODE_OAUTH_TOKEN: required: true, so the failure happens at caller secrets evaluation — before any step runs. The pause check must therefore live in the caller stubs (or the requirement relaxed to required: false with an in-run check) — an in-reusable check alone never executes. Mind the caller-stub-freeze baselines when touching stubs (caller_stub_freeze.sh --update).
Story
As a maintainer who sometimes takes the agent fleet offline deliberately (e.g. disabling
CLAUDE_CODE_OAUTH_TOKENto conserve quota),I want "agents intentionally paused" to be a first-class, visible state,
so that a deliberate pause doesn't present as a mysterious fleet-wide outage — red dispatch runs on every event, silently stalled PRs, and hours of diagnosis to rediscover a decision the maintainer already made.
Problem — observed 2026-08-16→18
The maintainer disabled
CLAUDE_CODE_OAUTH_TOKENto limit token usage until the quota reset. Effects, none of which announced the cause:dev-lead / dispatchrun failed at secrets evaluation ("Secret CLAUDE_CODE_OAUTH_TOKEN is required, but not provided") across all event types — indistinguishable from breakage, and red ❌s accumulated on every PR (e.g. 3 on fix: restore trunk from #1378 re-corruption — engine.sh 13 fns duplicated again, prompts stomped (#1485 recurrence) #1519).Acceptance Criteria
AGENTS_PAUSED=true, since variables are visible where secrets are not) short-circuits agent dispatch workflows (dev-lead, pr-review trigger paths) as an earlyexit 0step with a::notice::agents paused by maintainer (AGENTS_PAUSED)— runs conclude green/neutral, not red.AGENTS_PAUSEDis NOT set, the dispatch fails fast with an error that names the secret and links this issue — one clear line, not a secrets-evaluation stack error.scripts/validate-engines.sh(already the engine-availability preflight) recognizes and reports the paused state distinctly from a misconfiguration.Dev Notes
CLAUDE_CODE_OAUTH_TOKEN: required: true, so the failure happens at caller secrets evaluation — before any step runs. The pause check must therefore live in the caller stubs (or the requirement relaxed torequired: falsewith an in-run check) — an in-reusable check alone never executes. Mind the caller-stub-freeze baselines when touching stubs (caller_stub_freeze.sh --update).References