GitHub Actions Integration¶
kedge integrates with GitHub Actions as a push-triggered check for drift detection and a scheduled workflow for full remediation.
All kedge commands run from the code repo root, where kedge.toml lives. GitHub Actions checks out the repo by default with actions/checkout. kedge auto-clones the docs repo from [[repos.docs]] in kedge.toml, so no separate checkout step is needed for docs.
Drift detection on push¶
Run kedge check on every push to the default branch:
name: Documentation Drift Check
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
kedge-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # full history needed for legacy SHA provenance
- name: Install kedge
run: |
curl -fsSL https://raw.githubusercontent.com/danielhirt/kedge/main/install.sh | sh
- name: Check for drift
run: kedge check
env:
KEDGE_CODE_REPO_URL: ${{ github.server_url }}/${{ github.repository }}
Note:
fetch-depth: 0is only required if you use legacy SHA-based provenance. With content-addressedsig:provenance, a shallow clone is sufficient.Why
KEDGE_CODE_REPO_URL? kedge auto-detects the code repo URL fromgit remote get-url origin, butactions/checkoutsetsorigintohttps://github.com/org/repo(no.gitsuffix). If your anchors usegit@github.com:org/repo.gitorhttps://github.com/org/repo.git, the URLs won't match. SettingKEDGE_CODE_REPO_URLavoids this mismatch.
Full pipeline on schedule¶
Run detect-triage-remediate on a cron schedule. Use --no-stamp because docs live in a separate repo. Run kedge sync after agent MRs merge to advance provenance.
name: Documentation Remediation
on:
schedule:
- cron: '0 6 * * 1' # every Monday at 06:00 UTC
workflow_dispatch: # allow manual trigger
jobs:
kedge-update:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install kedge
run: |
curl -fsSL https://raw.githubusercontent.com/danielhirt/kedge/main/install.sh | sh
- name: Install steering files
run: kedge install --workspace
- name: Run full pipeline
run: kedge update --no-stamp
env:
KEDGE_CODE_REPO_URL: ${{ github.server_url }}/${{ github.repository }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
After agent MRs merge, run kedge sync in the docs repo to advance provenance for no_update anchors and commit the result.
PR status check¶
Use kedge check as a required status check on pull requests. When drift is detected (exit code 1), the PR is blocked until the author either updates the docs or runs kedge sync.
name: Kedge PR Gate
on:
pull_request:
branches: [main]
jobs:
drift-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install kedge
run: |
curl -fsSL https://raw.githubusercontent.com/danielhirt/kedge/main/install.sh | sh
- name: Drift check
run: kedge check --report drift-report.json
env:
KEDGE_CODE_REPO_URL: ${{ github.server_url }}/${{ github.repository }}
- name: Upload drift report
if: failure()
uses: actions/upload-artifact@v4
with:
name: drift-report
path: drift-report.json
Using Docker instead of the installer¶
If you prefer not to run the shell installer:
jobs:
kedge-check:
runs-on: ubuntu-latest
container:
image: danielhirt/kedge:latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- run: kedge check
env:
KEDGE_CODE_REPO_URL: ${{ github.server_url }}/${{ github.repository }}
Secrets¶
Store API keys as repository secrets:
| Secret | When needed |
|---|---|
ANTHROPIC_API_KEY |
Triage provider is anthropic |
OPENAI_API_KEY |
Triage provider is openai |
Environment variables¶
| Variable | Purpose |
|---|---|
KEDGE_CODE_REPO_URL |
Override code repo URL. Auto-detected from git remote get-url origin when not set. |
KEDGE_DOCS_PATH |
Use a local docs path instead of cloning from [[repos.docs]]. For local testing or monorepos. |
KEDGE_DOCS_REPO_URL |
Docs repo URL for agent payloads. Only needed with KEDGE_DOCS_PATH in a two-repo setup. |
kedge detects the GITHUB_ACTIONS environment variable and defaults kedge install to --workspace mode.