Skip to content

AgentOps fleet rollout: scan, secure, test, optimize all repos #5

Description

@donny-devops

Objective

Roll out an AgentOps control plane across the full donny-devops repository fleet.

Scope

Apply scanning, status checks, debugging hooks, test gates, security controls, optimization checks, release hygiene, package validation, GitHub Actions standards, app/site checks, Telegram mini-app checks, MCP/A2A readiness, and Azure AI / Foundry / Quantum DevKit readiness where applicable.

Current fleet discovered

  • donny-devops-showcase
  • docker-flask-postgres-api
  • jenkins-pipeline-library
  • github-actions-templates
  • python-automation-scripts
  • postman-api-collections
  • infra-monitoring-dashboard
  • donny-devops
  • terraform-aws-modules
  • devops-toolkit
  • docker-compose-stacks
  • node-ts-api-gateway
  • openclaw-revenue-engine
  • gists
  • threathunter-api
  • dev-utils
  • fastapi-starter-kit
  • donny-devops.github.io
  • temperature-converter
  • five-agent-os
  • dotfiles
  • vigorous-saha-870a88
  • echozulu-agentops
  • netpulse

Rollout checklist

  • Create reusable GitHub Actions workflow for repo detection and quality gates.
  • Add secret scanning with Gitleaks or equivalent.
  • Add dependency review for pull requests.
  • Add Python gates: Ruff, pytest, Bandit, pip-audit, build smoke test.
  • Add Node gates: install, lint, test, npm audit.
  • Add Terraform gates: fmt, validate, optional Checkov/TFLint.
  • Add Docker / Compose validation.
  • Add release and package validation where packages exist.
  • Add repo-level docs for MCP servers, A2A communication patterns, model routing, async orchestration, secrets, Azure AI Foundry, and Quantum DevKit integration targets.
  • Convert repeated logic into a reusable workflow consumed by every repo.

Notes

five-agent-os already has a repo-local AgentOps Security Quality Gate workflow added. Next step is to promote that pattern into reusable templates and roll it out repo-by-repo with conflict checks.

Activity

  1. self-assigned this
    on May 26, 2026
  2. donny-devops commented on May 29, 2026

    @donny-devops
    OwnerAuthor

    Triaged as epic / enhancement / p2-normal. This is a multi-week initiative spanning 24 repos, not a single-PR fix.

    Why it's an epic, not an issue

    The checklist mixes infrastructure concerns at very different abstraction levels:

    • Concrete reusable-workflow work (Gitleaks, Ruff/pytest/Bandit/pip-audit, npm audit, terraform fmt) — buildable today
    • Standards work (GitHub Actions pinning, release hygiene, package validation) — needs per-repo audit pass first
    • R&D / readiness work (MCP servers, A2A patterns, model routing, Azure AI Foundry, Quantum DevKit) — needs design before code

    Trying to land this as one PR would either be enormous or skip half the scope. I'd recommend decomposing into ~5-8 child issues, each closeable as a single PR.

    Proposed phased decomposition (will open child issues in a follow-up):

    1. Promote five-agent-os's AgentOps Security Quality Gate into a reusable workflow in this repo (foundation)
    2. Roll out the reusable workflow to the 4 Python repos (docker-flask-postgres-api, fastapi-starter-kit, python-automation-scripts, threathunter-api)
    3. Add Node gate to node-ts-api-gateway + echozulu-agentops
    4. Add Terraform gate to terraform-aws-modules + infra-monitoring-dashboard
    5. Add Docker/Compose gate to docker-compose-stacks
    6. Cross-cutting: Gitleaks + dependency-review as a separate reusable workflow
    7. Standards pass: action-SHA pinning audit across all 24 repos
    8. Design doc: MCP / A2A / Azure Foundry / Quantum readiness criteria (deferred until phases 1-7 land)

    Will follow up with concrete sub-issues for phases 1-2 to start. Phases 3-8 can be opened as those land. Keeping this issue open as the umbrella tracker.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions