From b30db8a4c924f66efb01580c75a5d06b33b20f77 Mon Sep 17 00:00:00 2001 From: Felix Faerber Date: Mon, 27 Jul 2026 16:43:05 +0300 Subject: [PATCH] chore: switch @lead/@ops from Anthropic to xAI grok-4.5 Removes the last Anthropic-model usage from the agent registry. XAI_API_KEY was already provisioned as an org secret; wire it into the run-agent step and update every doc/comment that referenced ANTHROPIC_API_KEY or claude-opus-4-8. --- .gitea/workflows/agent.yml | 2 +- .gitea/workflows/scripts/agents.json | 4 ++-- .gitea/workflows/scripts/build-activity-log.sh | 2 +- .gitea/workflows/scripts/install-opencode.sh | 2 +- .gitea/workflows/scripts/run-agent.sh | 2 +- .gitea/workflows/scripts/skill-gitea-admin.sh | 2 +- README.md | 6 +++--- 7 files changed, 10 insertions(+), 10 deletions(-) diff --git a/.gitea/workflows/agent.yml b/.gitea/workflows/agent.yml index 76227ec..45a0c29 100644 --- a/.gitea/workflows/agent.yml +++ b/.gitea/workflows/agent.yml @@ -211,7 +211,7 @@ jobs: id: run env: SCRIPTS: ${{ runner.temp }}/agents-scripts - ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }} + XAI_API_KEY: ${{ secrets.XAI_API_KEY }} # SELF_TOKEN = the RUNNING agent's OWN token (TOKEN_PM for @pm, TOKEN_OPS for @ops, …). # Only this agent's token is placed in its process env, so no agent can act as another. # Powers the gitea-api / gitea-admin skills — each agent calls Gitea as itself. Every diff --git a/.gitea/workflows/scripts/agents.json b/.gitea/workflows/scripts/agents.json index 38fb05c..2c4f747 100644 --- a/.gitea/workflows/scripts/agents.json +++ b/.gitea/workflows/scripts/agents.json @@ -25,7 +25,7 @@ "desc": "Senior dev — complex, multi-file implementation (GLM-5.2 via Ollama Cloud, text-only)." }, "lead": { - "model": "anthropic/claude-opus-4-8", + "model": "xai/grok-4.5", "vision": true, "mode": "pr", "skills": [ @@ -43,7 +43,7 @@ "desc": "QA / reviewer — reviews PRs: reads the diff, drives a headless browser (Playwright) to verify behavior, posts specific recommendations on the PR and the pass/fail verdict on the issue. Never edits code, never merges." }, "ops": { - "model": "anthropic/claude-opus-4-8", + "model": "xai/grok-4.5", "vision": false, "mode": "comment", "skills": [ diff --git a/.gitea/workflows/scripts/build-activity-log.sh b/.gitea/workflows/scripts/build-activity-log.sh index a7b1381..4c92200 100755 --- a/.gitea/workflows/scripts/build-activity-log.sh +++ b/.gitea/workflows/scripts/build-activity-log.sh @@ -38,7 +38,7 @@ COST=${COST:-0}; INP=${INP:-0}; OUT=${OUT:-0}; CR=${CR:-0}; CW=${CW:-0}; RE=${RE IN_TOTAL=$(( INP + CR + CW )) # total input context processed # Cost label: ollama / ollama-cloud models are SUBSCRIPTION-billed (GPU-time against the plan, no # $/token price exists), so a "$0.0000" there would be misleading — label it a subscription instead. -# Metered providers (anthropic/…) get the real dollar cost opencode computed. +# Metered providers (xai/…) get the real dollar cost opencode computed. case "${MODEL:-}" in ollama*|*"/ollama"*) COSTF="subscription" ;; *) COSTF=$(awk -v c="$COST" 'BEGIN{printf "$%.4f", c+0}') ;; diff --git a/.gitea/workflows/scripts/install-opencode.sh b/.gitea/workflows/scripts/install-opencode.sh index 761d57a..0c1f7df 100755 --- a/.gitea/workflows/scripts/install-opencode.sh +++ b/.gitea/workflows/scripts/install-opencode.sh @@ -42,7 +42,7 @@ PERM=$(jq -nc --argjson s "$SKILLS" ' # The provider `models:` maps are DERIVED from agents.json (the single source of truth, shared with # route.sh) so every model an agent is routed to is always declared in the provider config. # `ollama-cloud/` prefix models go to the cloud provider; `ollama/` prefix models go to the local -# provider. Built-in providers (e.g. `anthropic/claude-opus-4-8` for @lead) are not derived here. +# provider. Built-in providers (e.g. `xai/grok-4.5` for @lead/@ops) are not derived here. # See issue #31. AGENTS_JSON="${SCRIPTS:-$(dirname -- "$0")}/agents.json" CLOUD_MODELS=$(jq -r '[.[] | .model | select(startswith("ollama-cloud/")) | sub("^ollama-cloud/";"")] | map({(.):{}}) | add // {}' "$AGENTS_JSON") diff --git a/.gitea/workflows/scripts/run-agent.sh b/.gitea/workflows/scripts/run-agent.sh index 9aaa924..c5a7c9b 100755 --- a/.gitea/workflows/scripts/run-agent.sh +++ b/.gitea/workflows/scripts/run-agent.sh @@ -3,7 +3,7 @@ # plain-text reply (/tmp/agent_out.md) plus the raw event stream (/tmp/events.jsonl). # # Required env (provided by the workflow step): -# ANTHROPIC_API_KEY SELF_TOKEN NAME MODEL VISION MODE HAS_IMAGES BRANCH AUTOPILOT NUM TITLE +# XAI_API_KEY SELF_TOKEN NAME MODEL VISION MODE HAS_IMAGES BRANCH AUTOPILOT NUM TITLE # IBODY CMT # FILES (the opencode -f image flags, from the imgs step output) # AUTOPILOT is 'true' when the issue carries the `autopilot` label (label-gated autopilot mode). diff --git a/.gitea/workflows/scripts/skill-gitea-admin.sh b/.gitea/workflows/scripts/skill-gitea-admin.sh index 1fff4bf..e48fecc 100644 --- a/.gitea/workflows/scripts/skill-gitea-admin.sh +++ b/.gitea/workflows/scripts/skill-gitea-admin.sh @@ -107,7 +107,7 @@ curl -sS -X POST -H "Authorization: token $SELF_TOKEN" "$API/orgs/{org}/labels" 3. Commit the standard caller so it gets the agents — `PUT /repos/{owner}/{repo}/contents/.gitea/workflows/ai-agent.yml` with base64 `content`, `message`, `branch:"main"` (copy the exact caller from the `agents` repo README). 4. Add the agent bot users as collaborators: `PUT /repos/{owner}/{repo}/collaborators/{username}` (`{"permission":"write"}`). -5. Ensure the repo can run agents — the org must hold the runtime secrets (ANTHROPIC_API_KEY, SELF_TOKEN, +5. Ensure the repo can run agents — the org must hold the runtime secrets (XAI_API_KEY, SELF_TOKEN, TOKEN_* , OLLAMA_URL, OLLAMA_CLOUD_API_KEY); set any missing via the secrets calls above. ## Packages / container registry diff --git a/README.md b/README.md index 89f2d1c..4d7f9de 100644 --- a/README.md +++ b/README.md @@ -10,9 +10,9 @@ Shared **AI dev-team** workflow for Gitea Actions, reusable across repos. It giv | `@pm` | `ollama-cloud/minimax-m3:cloud` | yes | comment | `gitea-api` | Product manager & orchestrator — plans, picks the dev, hands finished PRs to `@qa`, reports back to the issue creator (autopilot: merges approved PRs itself). Issue thread only; never edits files, never reads the PR diff. | | `@junior` | `ollama-cloud/kimi-k2.7-code:cloud` | no | pr | — | Junior dev — small, low-risk changes (mostly YAML/compose/config). Text-only, cannot read images. Defers complex or image tasks to `@senior` or `@lead`. | | `@senior` | `ollama-cloud/glm-5.2:cloud` | no | pr | `gitea-api` | Senior dev — complex, multi-file implementation (GLM-5.2 via Ollama Cloud, text-only). | -| `@lead` | `anthropic/claude-opus-4-8` | yes | pr | `gitea-api` | Tech lead — the hardest problems, architecture, and final calls. | +| `@lead` | `xai/grok-4.5` | yes | pr | `gitea-api` | Tech lead — the hardest problems, architecture, and final calls. | | `@qa` | `ollama-cloud/minimax-m3:cloud` | yes | comment | `gitea-api` | QA / reviewer — reads the PR diff, drives a headless browser (Playwright) to verify behavior; recommendations on the PR, pass/fail verdict on the issue. Never edits code, never merges. | -| `@ops` | `anthropic/claude-opus-4-8` | no | comment | `gitea-admin` | Gitea operator — administers the instance itself (create orgs/users/repos, labels, secrets, scoped per-user tokens, bootstrap repos). Comments only; never edits code. Confirms before destructive actions. | +| `@ops` | `xai/grok-4.5` | no | comment | `gitea-admin` | Gitea operator — administers the instance itself (create orgs/users/repos, labels, secrets, scoped per-user tokens, bootstrap repos). Comments only; never edits code. Confirms before destructive actions. | | `@intern` | `ollama/ornith:35b` | no | pr | — | Intern — very basic tasks only, routed to the local Ollama model (`ornith:35b`). Text-only, cannot read images. Escalates anything non-trivial to `@junior`, `@senior` or `@lead`. | The registry `.gitea/workflows/scripts/agents.json` is the source of truth for this mapping — if you @@ -111,7 +111,7 @@ points `$SCRIPTS` at it. Keep the workflow and its scripts moving together on `m | Secret | For | |--------|-----| -| `ANTHROPIC_API_KEY` | `@lead` (and `@pm`/`@senior`/`@qa` if on Claude) | +| `XAI_API_KEY` | `@lead`, `@ops` (and any other agent switched to a `xai/…` model) | | `OLLAMA_URL`, `OLLAMA_CLOUD_API_KEY` | local ornith / Ollama Cloud (gemma4, kimi-k2.7-code, glm-5.2, minimax-m3) | | `TOKEN_PM`,`TOKEN_SENIOR`,`TOKEN_JUNIOR`,`TOKEN_LEAD`,`TOKEN_QA` | **primary** — each agent's own Gitea-user PAT. The running agent gets *only its own* token (as `SELF_TOKEN`) so it posts, commits and comments as itself, and its `gitea-api` skill acts with its own scopes. Scopes: devs + `TOKEN_PM` carry `write:repository` (`@pm` is the only agent that merges, autopilot only); `TOKEN_QA` is `read:repository` + `write:issue` (reviews, never merges). | | `TOKEN_OPS` | `@ops` only — the admin PAT behind the `gitea-admin` skill (create orgs/users/repos, manage labels & secrets, mint scoped tokens). Injected into the agent process only when the agent is `@ops`. | -- 2.54.0