The pr_reviewer webhook only fires on PR open and does not re-trigger on
branch updates or recall. Document the manual API trigger and the loop of
posting the review + response to the PR as comments, so future sessions
can iterate on reviews.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- CI/CD: stop deleting the steward namespace on every deploy; use
kubectl apply (dry-run -> apply) so the PVC and conversation memory
survive deployments.
- core: bound _histories with an LRU eviction (max 1000 active threads)
to prevent unbounded memory growth.
- core: wrap knowledge-base context in KB START/END delimiters and
instruct the LLM to treat it as data, mitigating indirect prompt
injection.
- matrix: wrap message processing in try/except so failures are logged
instead of silently dropped.
- telegram: remove now-dead flush/tags prompt constants (centralized in
core).
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
image to the SHA for idempotent rollbacks.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Add STEWARD__MATRIX__* literals to the deployment secret so the Matrix
appservice bot is configured when the cluster secret is created. Values
come from gitea repo vars/secrets (MATRIX_HOMESERVER_URL, MATRIX_AS_TOKEN,
etc.) and are only populated when those are set.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
- Add Matrix bot to the feature list and prerequisites.
- Add a Matrix Appservice section covering config, Synapse registration,
and the shared conversation pipeline.
- Document the matrix config section in CONFIGURATION.md.
- Add a ready-to-use Synapse appservice registration template
(matrix/steward_appservice.yaml).
- Document the Gitea Actions build/deploy workflow and kube manifests.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Introduce a shared ConversationService (steward/bot/core.py) that owns the
LLM call, history, knowledge-base search, and thread-memory keying behind a
normalized ThreadKey, so both Telegram and Matrix drive the same pipeline.
- Add steward/bot/matrix.py: a mautrix-python appservice bot that receives
Synapse transactions and replies via the client-server API.
- Refactor telegram.py handlers into thin wrappers over ConversationService.
- Generalize ThreadMemoryStore/ThreadSummary to platform-scoped keys with
legacy chat_id:thread_id migration.
- Add a matrix config section (homeserver, tokens, room/user allowlists).
- Rewrite main.py as async, starting Telegram and/or Matrix on one event loop.
- Add mautrix>=0.21.0 dependency.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Mirror the pr_reviewer deployment pattern: Gitea Actions builds a multi-arch
image in the gitea-runner namespace, pushes to git.aridgwayweb.com, recreates
the steward namespace with regcred + env secret, and applies kube manifests.
Add .omo/ to .gitignore.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>