Skip to content

Add /dashboard API for the dashboard's rerun GitHub writes - #151

Merged
tarekziade merged 1 commit into
mainfrom
dashboard/rerun-endpoints
Oct 8, 2026
Merged

tarekziade merged 1 commit into
mainfrom
dashboard/rerun-endpoints

Conversation

@tarekziade

Copy link
Copy Markdown
Collaborator

Adds a small, non-task API that lets the transformers-ci dashboard request GitHub writes for its "Re-run failed tests" button. The writes use serge's existing GitHub App, so the dashboard never holds an App key.

Endpoints (reviewbot/dashboard_api.py). They return 404 unless DASHBOARD_API_TOKEN is set:

  • POST /dashboard/permission {repository, actor} → {role, can_write}, read with the App and cached briefly.
  • POST /dashboard/runs/cancel {repository, actor, run_id}: only runs whose workflow is in DASHBOARD_CANCEL_WORKFLOWS (default pr-ci-caller.yml, self-comment-ci.yml).
  • POST /dashboard/workflows/dispatch {repository, actor, workflow, inputs}: only workflows in DASHBOARD_DISPATCH_WORKFLOWS (default rerun-failed-cpu.yml, rerun-failed-gpu.yml), always on the default branch, with string inputs of bounded size.

Every call needs Authorization: Bearer <DASHBOARD_API_TOKEN> (compared in constant time). The repository must be in DASHBOARD_REPOSITORIES (default huggingface/transformers), and the acting user must have write access, which serge checks itself.

/tasks is unchanged. A test checks that the dashboard token is refused there and that OIDC is still required.

Deploy: the token reaches the pod through the existing envFrom of serge-secrets, so the only new piece is a DASHBOARD_API_TOKEN key in Infisical. The chart doesn't change. The dashboard side is transformers-ci tarek/rerun-failed-preview.

🤖 Generated with Claude Code

@tarekziade
tarekziade merged commit 12d10a8 into main Oct 8, 2026
3 checks passed
@tarekziade
tarekziade deleted the dashboard/rerun-endpoints branch October 8, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant