ci: self-merge Codex PRs via native auto-merge; retire the sweep (#3064)

With branch protection + "Allow auto-merge" now enabled on master, Codex
enables GitHub auto-merge on its own PR (gh pr merge --squash --auto) right
after opening it, so the PR lands the moment the required CI checks pass —
no polling sweep, and the green-CI gate is enforced by GitHub instead of by
gh pr checks in a cron. Removes auto-merge-codex.yml and updates the dispatch
and AGENTS.md accordingly.


Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL

Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
Asim Aslam
2026-06-25 10:13:24 +01:00
committed by GitHub
parent 95ee402c8b
commit 2def581408
3 changed files with 12 additions and 49 deletions
-42
View File
@@ -1,42 +0,0 @@
name: Auto-merge Codex PRs
# Part of the autonomous improvement loop (internal/docs/CONTINUOUS_IMPROVEMENT.md).
# Merges Codex's PRs once CI is green — no human involvement; CI (build, test,
# golangci-lint, harnesses) is the only gate. Scoped to PRs that are BOTH
# codex-labelled AND from a codex/* branch, so nothing else can auto-merge.
on:
schedule:
- cron: "*/15 * * * *" # sweep every 15 min
workflow_dispatch: {}
permissions:
contents: write
pull-requests: write
concurrency:
group: auto-merge-codex
cancel-in-progress: false
jobs:
merge:
runs-on: ubuntu-latest
steps:
- name: Merge green Codex PRs
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
run: |
gh pr list --repo "$REPO" --label codex --state open \
--json number,headRefName \
--jq '.[] | select(.headRefName | startswith("codex/")) | .number' \
| while read -r pr; do
[ -z "$pr" ] && continue
if gh pr checks "$pr" --repo "$REPO" >/dev/null 2>&1; then
echo "Checks green on #$pr — merging."
gh pr merge "$pr" --repo "$REPO" --squash --delete-branch \
|| echo "skip #$pr (not mergeable — conflicts?)"
else
echo "skip #$pr (checks pending/failing)"
fi
done
+6 -3
View File
@@ -5,8 +5,11 @@ name: Continuous Improvement
#
# A Claude Max subscription provides no API key for CI, so the loop is driven by
# Codex rather than Claude Code: on a cadence this opens a fresh tracking issue and
# posts an @codex instruction on it, and Codex runs one improvement increment + opens
# a PR. (See the per-issue rationale below.)
# posts an @codex instruction on it, and Codex runs one improvement increment, opens
# a PR (git push + gh pr create — the make_pr tool is a no-op stub), and enables
# GitHub auto-merge (gh pr merge --auto) so the PR lands once the required CI checks
# pass. No separate merge sweep — branch protection + native auto-merge is the gate.
# (See the per-issue rationale below.)
#
# Codex does NOT respond to comments authored by the github-actions bot, so the
# dispatch is GATED on a CODEX_TRIGGER_TOKEN secret (a PAT for a user account Codex
@@ -59,4 +62,4 @@ jobs:
ISSUE_NUM="${ISSUE_URL##*/}"
echo "Opened issue #$ISSUE_NUM — dispatching Codex."
gh issue comment "$ISSUE_NUM" --repo "$REPO" --body \
"@codex Run one continuous-improvement increment per internal/docs/CONTINUOUS_IMPROVEMENT.md, aligned to the North Star in internal/docs/THESIS.md (the holistic services → agents → workflows lifecycle). Pick the single highest-value roadmap/issue/improvement-radar item that advances that thesis, implement it, and verify \`go build ./...\`, \`go test ./...\`, and \`golangci-lint run ./...\`. Then open the PR YOURSELF from the shell — do NOT use the make_pr tool (in this environment it only records metadata and never creates a PR). Create a uniquely-named branch under the codex/ prefix and open the PR from it: \`git switch -c codex/increment-$ISSUE_NUM\`, then \`git push -u origin codex/increment-$ISSUE_NUM\`, then \`gh pr create --base master --label codex --title \"<title>\" --body \"<body, including 'Closes #$ISSUE_NUM'>\"\`. The branch MUST start with \`codex/\` and the PR MUST carry the \`codex\` label, or it will not be auto-merged. The gh CLI is installed and authenticated and origin points to $REPO. One concern per PR; stay out of brand/positioning copy and breaking public API."
"@codex Run one continuous-improvement increment per internal/docs/CONTINUOUS_IMPROVEMENT.md, aligned to the North Star in internal/docs/THESIS.md (the holistic services → agents → workflows lifecycle). Pick the single highest-value roadmap/issue/improvement-radar item that advances that thesis, implement it, and verify \`go build ./...\`, \`go test ./...\`, and \`golangci-lint run ./...\`. Then open the PR YOURSELF from the shell — do NOT use the make_pr tool (in this environment it only records metadata and never creates a PR). Create a uniquely-named branch under the codex/ prefix and open the PR from it: \`git switch -c codex/increment-$ISSUE_NUM\`, then \`git push -u origin codex/increment-$ISSUE_NUM\`, then \`gh pr create --base master --label codex --title \"<title>\" --body \"<body, including 'Closes #$ISSUE_NUM'>\"\`. Finally enable auto-merge so GitHub merges it once CI is green: \`gh pr merge --squash --auto --delete-branch\`. The gh CLI is installed and authenticated and origin points to $REPO. One concern per PR; stay out of brand/positioning copy and breaking public API."
+6 -4
View File
@@ -18,18 +18,20 @@ When a Codex task makes repository changes and the requested outcome is a PR:
```
5. Stage the intended files and commit on that branch.
6. Open the pull request yourself with the GitHub CLI, which is installed in the
environment and whose `origin` points at this repository:
environment and whose `origin` points at this repository, then enable
auto-merge so GitHub merges it once the required CI checks pass:
```sh
git push -u origin HEAD
gh pr create --base master --label codex \
--title "<concise title>" \
--body "<summary of the change and testing, including 'Closes #<issue>'>"
gh pr merge --squash --auto --delete-branch
```
The branch **must** start with `codex/` and the PR **must** carry the `codex`
label — the auto-merge sweep only matches PRs that satisfy both, so a branch
named `work` (or any non-`codex/` branch) will never be merged.
The branch should start with `codex/` and the PR should carry the `codex`
label. Auto-merge waits for the required status checks (build, tests,
golangci-lint) — never merge a PR manually before CI is green.
Do not just say that a PR was opened, and do **not** rely on the `make_pr` tool:
in this environment `make_pr` only records the title/body and never pushes a