Files
pmg/internal/audit/cloud_env_resolver.go
T
6087bc922f feat: populate CI invocation context on cloud events (#304)
* feat: add CloudSinkEnvResolver interface with default implementation

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add GitHub Actions environment resolver for cloud sink

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: populate invocation context with CI environment on cloud events

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address lint errors in cloud sink tests

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor: use getter-based CloudSinkCIResolver with nil-when-no-CI

Rename to CloudSinkCIResolver with focused CI concern. Factory returns
nil when no CI is detected, removing the need for IsCI() and a default
resolver. Leaves room for a separate agent resolver in the future.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add CI metadata support using updated API SDK

Update SDK to include SetMetadata on EndpointCIContext. Add Metadata()
to CloudSinkCIResolver interface and GitHub Actions implementation
(workflow, job, run_attempt, server_url). Wire metadata into
buildInvocationContext.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor: address review comments on CI resolver

- Inject CloudSinkCIResolver as dependency into newCloudSink for testability
- Check both GITHUB_ACTIONS and GITHUB_RUN_ID for GHA environment detection
- Make factory and constructor package-private (newCloudSinkCIResolver,
  newGithubActionsCIResolver)
- Attach invocation context only to session complete events, not every event

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: fail fast on os.Getwd error instead of swallowing it

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-05-28 19:12:12 +05:30

47 lines
1.3 KiB
Go

package audit
import (
"os"
controltowerv1 "buf.build/gen/go/safedep/api/protocolbuffers/go/safedep/messages/controltower/v1"
)
// CloudSinkCIResolver resolves CI/CD environment context for the cloud
// sink. Implementations detect CI providers from environment variables
// and expose individual fields. The cloudSink assembles the
// EndpointCIContext proto from these.
type CloudSinkCIResolver interface {
// Provider returns the detected CI provider.
Provider() controltowerv1.EndpointCIProvider
// RunId returns the CI run identifier.
RunId() string
// Repository returns the repository being built.
Repository() string
// Branch returns the branch being built.
Branch() string
// CommitSha returns the commit SHA being built.
CommitSha() string
// Actor returns the user or bot that triggered the build.
Actor() string
// PrNumber returns the pull request number, if applicable.
PrNumber() string
// Metadata returns provider-specific key-value pairs.
Metadata() map[string]string
}
// newCloudSinkCIResolver detects the CI environment and returns the
// appropriate resolver. Returns nil when no CI provider is detected.
func newCloudSinkCIResolver() CloudSinkCIResolver {
if os.Getenv("GITHUB_ACTIONS") != "" && os.Getenv("GITHUB_RUN_ID") != "" {
return newGithubActionsCIResolver()
}
return nil
}