-
Notifications
You must be signed in to change notification settings - Fork 3
Added codex-generated AGENTS.md #16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
metachris
wants to merge
1
commit into
main
Choose a base branch
from
codex-init
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+37
−0
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
@@ -0,0 +1,37 @@ | ||||||
# Repository Guidelines | ||||||
|
||||||
## Project Structure & Module Organization | ||||||
- Go module entrypoint `cmd/system-api/main.go`; runtime config in repo root (`systemapi-config.toml`, TLS fixtures). | ||||||
- Core HTTP handlers, middleware, config loaders in `systemapi/`; shared logging/version helpers in `common/`; TLS primitives in `crypto/`. | ||||||
- Tests live beside code (`systemapi/server_test.go`); docs and measurement fixtures under `docs/`; build artifacts land in `build/`. | ||||||
|
||||||
## Build, Test, and Development Commands | ||||||
- Use tabs instead of spaces for indentation. | ||||||
- Always run `make fmt` and `make lint` (and `make test`) before committing. | ||||||
- `make run` starts the API with the default config; pass `GOFLAGS` or `--config` for overrides. | ||||||
- `make build` emits `build/system-api` with version metadata from `common.Version`. | ||||||
- `make test`, `make test-race`, and `make cover` cover the unit suite, race detector, and coverage report respectively. | ||||||
- `make fmt` then `make lint` ensure gofmt, gofumpt, gci, go vet, staticcheck, and golangci-lint all pass before review. | ||||||
|
||||||
## Coding Style & Naming Conventions | ||||||
- Code is gofmt/gofumpt formatted with tabs; prefer explicit names (`eventStore`, `tlsCertPath`) and singular file names. | ||||||
- Document exported symbols with concise GoDoc comments and keep configuration passed through structs instead of globals. | ||||||
- Secrets, ports, and paths should be injected via config or env; never hardcode sensitive values. | ||||||
|
||||||
## Testing Guidelines | ||||||
- Mirror the table-driven patterns in `systemapi/server_test.go` when adding cases; colocate new `*_test.go` files. | ||||||
- Iterate with `go test ./systemapi -run <Name>` as needed, then finish with `make test-race` before pushing. | ||||||
- Add coverage for authentication, TLS, and upload branches when touched; store ad hoc fixtures under `docs/` or temp dirs. | ||||||
- Validate new config keys by asserting defaults, validation errors, and hot-reload behavior where relevant. | ||||||
|
||||||
## Commit & Pull Request Guidelines | ||||||
- Use imperative commit subjects similar to `git log` (`Add TLS reload hook`, optional `(#123)` suffix for PRs). | ||||||
- PR descriptions should summarize behavior, list verification commands, and reference BuilderNet tickets or incidents. | ||||||
- Attach screenshots or curl transcripts when API responses change; call out config updates in both the PR and `README.md`. | ||||||
- Confirm `make fmt`, `make lint`, and `make test` in PR checklists; ensure reviewers can reproduce your steps quickly. | ||||||
|
||||||
## Security & Configuration Tips | ||||||
- Maintain `basic-auth-hash.txt` outside version control; rotate secrets through the `/api/v1/set-basic-auth` endpoint. | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Consider adding guidance on proper file permissions for
Suggested change
Copilot uses AI. Check for mistakes. Positive FeedbackNegative Feedback |
||||||
- Regenerate local certificates with the `cmd/tls-gen` helpers before shipping TLS changes. | ||||||
- Keep `systemapi-config.toml` modifications minimal and documented so operators can diff with their deployments. | ||||||
- Run `make clean` to clear generated binaries and temporary TLS assets before packaging artifacts. |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This guideline should specify that environment variables containing secrets should be clearly documented and mention potential risks of environment variable exposure in process lists.
Copilot uses AI. Check for mistakes.