feat(ops): add @ops agent — Gitea instance administrator
A comment-mode operator agent (opus) for administering Gitea itself from issues in gitea/ops: create orgs/users/repos, manage labels & Actions secrets, and mint least-privilege per-user tokens. - agents.json: new @ops role (comment-mode, skill gitea-admin, confirms before destructive ops). - skill-gitea-admin.sh: SKILL.md documenting org/user/repo/label/secret ops + the create-user → mint-scoped-token → store-as-secret flow (never printing tokens). Gated on NAME=ops so the admin how-to is written ONLY for @ops; permission.skill also denies it to other agents. - agent.yml: wire the skill step (uses AGENT_TOKEN — an admin PAT during bootstrap). Bootstrap note: AGENT_TOKEN is admin for now, so every agent's process technically holds an admin credential (skill-scoping hides the doc, not the env var). Once @ops is minting scoped per-user tokens, narrow AGENT_TOKEN and inject a dedicated admin token only for @ops. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
4cbbc9b2d7
commit
74d3e1d229
@@ -12,6 +12,7 @@ Shared **AI dev-team** workflow for Gitea Actions, reusable across repos. It giv
|
||||
| `@senior` | `ollama-cloud/glm-5.2:cloud` | no | pr | `gitea-api`, `node1-ssh` | Senior dev — complex, multi-file implementation (GLM-5.2 via Ollama Cloud, text-only). |
|
||||
| `@lead` | `anthropic/claude-opus-4-8` | yes | pr | `gitea-api`, `node1-ssh` | Tech lead — the hardest problems, architecture, and final calls. |
|
||||
| `@qa` | `ollama-cloud/minimax-m3:cloud` | yes | comment | `gitea-api` | QA — verifies things work. Drives a headless browser (Playwright) to open a URL/web app, click through it, screenshot, and report bugs or confirm behavior. Comments findings; opens no PRs. |
|
||||
| `@ops` | `anthropic/claude-opus-4-8` | no | comment | `gitea-admin` | Gitea operator — administers the instance itself (create orgs/users/repos, labels, secrets, scoped per-user tokens, bootstrap repos). Comments only; never edits code. Confirms before destructive actions. |
|
||||
|
||||
`agent.yml`'s agent registry is the source of truth for this mapping — if you change a model
|
||||
or an agent's skills there, update this table too.
|
||||
|
||||
Reference in New Issue
Block a user