The pr_reviewer webhook only fires on PR open and does not re-trigger on
branch updates or recall. Document the manual API trigger and the loop of
posting the review + response to the PR as comments, so future sessions
can iterate on reviews.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- CI/CD: stop deleting the steward namespace on every deploy; use
kubectl apply (dry-run -> apply) so the PVC and conversation memory
survive deployments.
- core: bound _histories with an LRU eviction (max 1000 active threads)
to prevent unbounded memory growth.
- core: wrap knowledge-base context in KB START/END delimiters and
instruct the LLM to treat it as data, mitigating indirect prompt
injection.
- matrix: wrap message processing in try/except so failures are logged
instead of silently dropped.
- telegram: remove now-dead flush/tags prompt constants (centralized in
core).
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
image to the SHA for idempotent rollbacks.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add the full table of secrets and variables the build/deploy workflow reads
from the gitea repo, including the Matrix and Ollama Cloud options.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add STEWARD__MATRIX__* literals to the deployment secret so the Matrix
appservice bot is configured when the cluster secret is created. Values
come from gitea repo vars/secrets (MATRIX_HOMESERVER_URL, MATRIX_AS_TOKEN,
etc.) and are only populated when those are set.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- Add Matrix bot to the feature list and prerequisites.
- Add a Matrix Appservice section covering config, Synapse registration,
and the shared conversation pipeline.
- Document the matrix config section in CONFIGURATION.md.
- Add a ready-to-use Synapse appservice registration template
(matrix/steward_appservice.yaml).
- Document the Gitea Actions build/deploy workflow and kube manifests.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Introduce a shared ConversationService (steward/bot/core.py) that owns the
LLM call, history, knowledge-base search, and thread-memory keying behind a
normalized ThreadKey, so both Telegram and Matrix drive the same pipeline.
- Add steward/bot/matrix.py: a mautrix-python appservice bot that receives
Synapse transactions and replies via the client-server API.
- Refactor telegram.py handlers into thin wrappers over ConversationService.
- Generalize ThreadMemoryStore/ThreadSummary to platform-scoped keys with
legacy chat_id:thread_id migration.
- Add a matrix config section (homeserver, tokens, room/user allowlists).
- Rewrite main.py as async, starting Telegram and/or Matrix on one event loop.
- Add mautrix>=0.21.0 dependency.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Mirror the pr_reviewer deployment pattern: Gitea Actions builds a multi-arch
image in the gitea-runner namespace, pushes to git.aridgwayweb.com, recreates
the steward namespace with regcred + env secret, and applies kube manifests.
Add .omo/ to .gitignore.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Map all author variations to Daniel Wagner <dw@danieljw.net>:
- daniel <daniel@hp.k8sx.com>
- Daniel <dw@danieljw.net>
- Daniel Wagner <daniel.wagner89@gmail.com>
This ensures consistent author attribution across all commits.
The mailmap is used by GitHub and git tools for display.
- Add Initial Setup section with uv installation and venv creation steps
- Include pre-commit hook setup with clear explanation of automation
- Update Code Style section to mention pre-commit auto-fixing
- Update Running Tests Locally with venv activation and linting commands
- Add note clarifying pre-commit integration in CI/CD workflow
This ensures new developers/agents know how to:
1. Install dependencies properly with uv
2. Set up pre-commit for automatic linting and testing
3. Run tests and linting commands manually when needed
- Replace deprecated class Config pattern with model_config = ConfigDict(...)
- Add ConfigDict import from pydantic
- Fixes PydanticDeprecatedSince20 warning in test output
- Maintains all existing functionality
All 73 tests pass without warnings.
- Add astral-sh/ruff-pre-commit as official ruff hook
- Enable ruff with --fix for automatic linting fixes
- Add ruff-format for code formatting
- Keep pytest hook for test running
Now pre-commit will automatically fix linting issues and run tests before commits.
- Add .pre-commit-config.yaml with hooks for ruff check and pytest
- Expand README with quick start guide and development instructions
- Include pre-commit setup instructions
- Add references to AGENTS.md and CONFIGURATION.md
To use pre-commit:
pip install pre-commit
pre-commit install
Hooks run automatically on commit (ruff check + pytest).
- Add tests/conftest.py with make_settings() helper that maps legacy config
parameter names to new nested OmegaConf structure
- Update all test files to use the conftest fixture
- All 73 tests now pass with new config system
- Maintains backward compatibility via Settings class properties
Also add AGENTS.md with comprehensive AI agent guidelines:
- Project overview and key technologies
- Directory structure reference
- Development workflow and common tasks
- Testing strategy and patterns
- CI/CD pipeline overview
- Common pitfalls and best practices
- Debugging guide for agents working on the project
Only include the 4 required environment variables:
- STEWARD__TELEGRAM__BOT_TOKEN
- STEWARD__OPENAI__API_KEY
- STEWARD__TELEGRAM__ALLOWED_USER_IDS
- STEWARD__TELEGRAM__GROUP_IDS
All other settings have sensible defaults in config_schema.yaml and can be
overridden if needed. This keeps the example file clean and focused.
Configuration changes:
- Replace pydantic-settings with OmegaConf for flexible config management
- Support YAML config files via CONFIG_FILE environment variable
- Support environment variables with STEWARD__SECTION__KEY format
- Add config_schema.yaml as default configuration schema
- Create pydantic models for each configuration section for type safety
- Maintain backward compatibility via properties on Settings class
- Add CONFIGURATION.md with comprehensive setup and usage guide
- Update pyproject.toml to include config_schema.yaml in package data
Build/deployment changes:
- Replace pip with uv in Dockerfile for faster dependency installation
- Create docker-compose.dev.yml for local development (build .)
- Keep docker-compose.yml for production (uses ghcr.io/djw4/steward:latest)
- Update .env.example with new STEWARD__* variable format
This setup is designed for Kubernetes deployment:
- Non-sensitive config goes in ConfigMap (config.yaml)
- Secrets go in Secret resources (environment variables)
- Single unified configuration system for all environments
- Add TELEGRAM_GROUP_IDS configuration setting to enable optional group/channel filtering
- Add _is_group_enabled() authorization check to all command handlers
- Add group/channel authorization check to message_handler
- All handlers now verify both user authorization and group authorization
- If TELEGRAM_GROUP_IDS is not configured, bot accepts messages from any group
- If TELEGRAM_GROUP_IDS is configured, bot only processes messages from those groups
This enables the bot to be used in group chats and channels with Topics/Threads support.