Skip to content

feat(worker): route reviews through the internal fundi gateway, with metadata-only tracing - #24

Merged
bryanfawcett merged 3 commits into
mainfrom
feat/internal-agents-gateway-tracing
Oct 4, 2026
Merged

bryanfawcett merged 3 commits into
mainfrom
feat/internal-agents-gateway-tracing

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

Refs #23

What

The PR-review agent in worker/ (shamwari-github-mcp) is internal tooling — it acts only on Nyuchi's allowlisted repositories, mentions only work for OWNER/MEMBER/COLLABORATOR, MCP callers must be in the Nyuchi org — so its inference moves to fundi, the internal agents gateway (owner: "all agents carry the fundi name"; consumer-triggered in-app AI stays on shamwari, staff chat is nyuchi-ai).

  • AI_GATEWAY_ID = "fundi"; binding is pre-authenticated, no token stored. skipCache: true.
  • Gateway metadata { worker, job: "pr_review", repo, trigger } — the trigger is its kind only, so a GitHub login no longer lands in the cost log. ≤5 scalar entries, no content.
  • No guardrails on this path.
  • Waste: the "already reviewed this head commit?" check now runs before the diff fetch and the model call (a webhook redelivery used to pay for a whole review and then discard it); a post with no head SHA fails before the model. Diff cap (200 KB) and the REVIEW_ENABLED kill switch were already in place.
  • REVIEW_MODEL may name a dynamic route (dynamic/review): the code speaks both request shapes. It stays on the direct model until the owner publishes the route.
  • Tracing: [observability.traces] enabled = true (sampling 1 and persist kept). Custom harness → one invoke_agent span per review with a nested chat span; identity attrs (gen_ai.agent.name shamwari-github-mcp, gen_ai.agent.id shamwari-github-mcp/review, gen_ai.conversation.id repo#PR) plus counts — no prompts, diffs or responses. cloudflare:workers is imported lazily so Node tests run without a tracer.
  • No daily budget counter: this Worker has no Durable Object or D1 (KV isn't atomic), and the gateway shows ~zero review traffic in 30 days; the mention allowlist and kill switch bound spend.

Validation (in worker/)

  • npm run build (tsc) — pass
  • npm test — 161/161 pass
  • npx wrangler deploy --dry-run — pass (AI_GATEWAY_ID ("fundi"))
  • prettier on changed TS — clean

🤖 Generated with Claude Code

https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq

bryanfawcett and others added 3 commits October 4, 2026 10:00
… metadata-only tracing

The review agent is internal tooling (Nyuchi's own allowlisted repos, team
members only), so its inference moves to the `nyuchi-agents` AI Gateway and
off the consumer Shamwari gateway. The binding is pre-authenticated, so no
gateway token is stored. Cache stays off.

- Gateway metadata: worker, job, repo and the trigger KIND — a mention no
  longer puts the commenter's login in the cost log.
- Ask "already reviewed?" before fetching the diff or calling the model, so
  a webhook redelivery or re-request no longer pays for a review it then
  discards. A post without a head sha now fails before the model call too.
- Workers traces on (100%), and each review is an invoke_agent span with a
  nested chat span carrying identity, model, diff size and token counts —
  never the prompt, diff or response.

Refs #23

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
A dynamic route speaks the OpenAI chat-completions shape, so the
structured-output request and the answer's location differ from a native
Workers AI model. Both are handled, so pointing REVIEW_MODEL at
dynamic/review is a one-line var change once the route exists.

Refs #23

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
The owner renamed the internal agents gateway: all agents carry the
fundi name, and `nyuchi-agents` was deleted before it carried traffic.
A review is an agent run fired by a GitHub event or a team member's
mention, so it rides `fundi` — not consumer `shamwari`, not staff chat
`nyuchi-ai`.

Refs #23

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
@bryanfawcett
bryanfawcett merged commit 574235b into main Oct 4, 2026
14 checks passed
@bryanfawcett
bryanfawcett deleted the feat/internal-agents-gateway-tracing branch October 4, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant