Repository navigation
AgentOps fleet rollout: scan, secure, test, optimize all repos #5
Copy link
Copy link
Closed
0 / 10 of 1 issue completedClosed
0 / 10 of 1 issue completed
Copy link
Labels
Description
Activity
- addedenhancementNew feature or requestNew feature or request
on May 20, 2026 Triaged as epic / enhancement / p2-normal. This is a multi-week initiative spanning 24 repos, not a single-PR fix.
Why it's an epic, not an issue
The checklist mixes infrastructure concerns at very different abstraction levels:
- Concrete reusable-workflow work (Gitleaks, Ruff/pytest/Bandit/pip-audit, npm audit, terraform fmt) — buildable today
- Standards work (GitHub Actions pinning, release hygiene, package validation) — needs per-repo audit pass first
- R&D / readiness work (MCP servers, A2A patterns, model routing, Azure AI Foundry, Quantum DevKit) — needs design before code
Trying to land this as one PR would either be enormous or skip half the scope. I'd recommend decomposing into ~5-8 child issues, each closeable as a single PR.
Proposed phased decomposition (will open child issues in a follow-up):
- Promote
five-agent-os's AgentOps Security Quality Gate into a reusable workflow in this repo (foundation) - Roll out the reusable workflow to the 4 Python repos (docker-flask-postgres-api, fastapi-starter-kit, python-automation-scripts, threathunter-api)
- Add Node gate to node-ts-api-gateway + echozulu-agentops
- Add Terraform gate to terraform-aws-modules + infra-monitoring-dashboard
- Add Docker/Compose gate to docker-compose-stacks
- Cross-cutting: Gitleaks + dependency-review as a separate reusable workflow
- Standards pass: action-SHA pinning audit across all 24 repos
- Design doc: MCP / A2A / Azure Foundry / Quantum readiness criteria (deferred until phases 1-7 land)
Will follow up with concrete sub-issues for phases 1-2 to start. Phases 3-8 can be opened as those land. Keeping this issue open as the umbrella tracker.
Objective
Roll out an AgentOps control plane across the full
donny-devopsrepository fleet.Scope
Apply scanning, status checks, debugging hooks, test gates, security controls, optimization checks, release hygiene, package validation, GitHub Actions standards, app/site checks, Telegram mini-app checks, MCP/A2A readiness, and Azure AI / Foundry / Quantum DevKit readiness where applicable.
Current fleet discovered
Rollout checklist
Notes
five-agent-osalready has a repo-local AgentOps Security Quality Gate workflow added. Next step is to promote that pattern into reusable templates and roll it out repo-by-repo with conflict checks.