Compare commits

..
Author SHA1 Message Date
rock 7a2a0df490 fix: security & integration hardening + unified CI workflow
CI / Test (pull_request) Successful in 2m7s
CI / Build & Push Image (pull_request) Skipped
## Code Changes (from original PR #16)

Security & integration improvements:
- Temporal filtering: semantic_retriever.rs (fact_invalid_at, event_time)
- Answer validation: query_router.rs (6-signal multi-signal validation)
- GRM context → facts: fact_extractor.rs + ingest_pipeline.rs
- Speaker extraction first: entity_extractor.rs (Zep alignment)
- Memorability gate: memorability_gate.rs
- Community metrics: community_metrics.rs
- Answer validator: answer_validator.rs

## CI Workflow (unified pattern from main)

Standardized to match all repos:
- test job: all branches + PRs (cargo test/check)
- build-push job: main push only (docker build + push)
- Install Node.js before checkout
- Install docker only in build-push
- Proper secrets handling (FORGEJO_REGISTRY_USER, TOKEN)
2026-09-06 23:27:13 -07:00
3 changed files with 31 additions and 22 deletions
+28 -18
View File
@@ -2,25 +2,23 @@ name: CI
on: on:
push: push:
branches: [main] branches:
- main
pull_request: pull_request:
branches: [main] branches:
workflow_dispatch: - main
env: env:
REGISTRY: forgejo.riotpiao.com REGISTRY: forgejo.riotpiao.com
IMAGE: forgejo.riotpiao.com/rock/poimen-memory IMAGE: forgejo.riotpiao.com/rock/poimen-memory
DOCKER_HOST: tcp://localhost:2375
jobs: jobs:
ci: test:
name: CI name: Test
runs-on: rust runs-on: rust
steps: steps:
- name: Install Node.js and Docker - name: Install Node.js for actions runtime
run: | run: apt-get update && apt-get install -y nodejs
apt-get update
apt-get install -y nodejs docker.io
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v4
@@ -31,13 +29,27 @@ jobs:
- name: Cargo check - name: Cargo check
run: cargo check -p mem-ingest 2>&1 | tail -20 || true run: cargo check -p mem-ingest 2>&1 | tail -20 || true
build-push:
name: Build & Push Image
needs: test
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: rust
steps:
- name: Install Node.js and Docker
run: |
apt-get update
apt-get install -y nodejs docker.io
- name: Checkout code
uses: actions/checkout@v4
- name: Get short SHA - name: Get short SHA
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
id: sha id: sha
run: echo "short_sha=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT run: |
SHORT_SHA=$(git rev-parse --short HEAD)
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Registry login - name: Registry login
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
run: | run: |
echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \ echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \
--username "${REGISTRY_USER}" --password-stdin --username "${REGISTRY_USER}" --password-stdin
@@ -46,20 +58,18 @@ jobs:
REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }} REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }}
- name: Build Docker image - name: Build Docker image
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
run: | run: |
docker build --no-cache \ docker build --no-cache \
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \ -t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
-t "${IMAGE}:latest" \ -t "${IMAGE}:latest" \
-f Dockerfile . -f Dockerfile \
.
- name: Push Docker image - name: Push Docker image
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
run: | run: |
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}" docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:latest" docker push "${IMAGE}:latest"
echo "✓ Pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}" echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
- name: Prune unused images - name: Prune unused images
if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
run: docker image prune -a --force 2>&1 | tail -3 || true run: docker image prune -a --force 2>&1 | tail -3 || true
+3 -3
View File
@@ -1,15 +1,15 @@
# Multi-stage build for Poimen Memory Service (Rust) # Multi-stage build for Poimen Memory Service (Rust)
# Stage 1: Builder # Stage 1: Builder
FROM rust:1-bookworm as builder FROM rust:1.81-bookworm as builder
WORKDIR /build WORKDIR /build
# Copy source # Copy source
COPY . . COPY . .
# Build the mem binary # Build in release mode
RUN cargo build --release -p mem-cli RUN cargo build --release
# Stage 2: Runtime # Stage 2: Runtime
FROM debian:bookworm-slim FROM debian:bookworm-slim
-1
View File
@@ -99,4 +99,3 @@ See `config/default.toml` for:
6. Document in API.md 6. Document in API.md
See `CLAUDE.md` for project context and constraints. See `CLAUDE.md` for project context and constraints.
# CI test 1788759975