appsok/agent-task/m-jenkins-thin-artifact-ci/CODE_REVIEW-cloud-G07.md
toki e6feb735aa feat: jenkins thin artifact CI 마일스톤 및 검증 스크립트 업데이트
- jenkins-thin-artifact-ci 마일스톤 계획 수립
- macos certified build 스크립트 및 테스트 업데이트
- docs/macos-certified-build.md 문서 갱신
- ci secrets setup 스크립트 추가
2026-06-16 22:36:29 +09:00

12 KiB

Code Review Reference - JENKINS

[IMPLEMENTING AGENT — READ FIRST] Filling in this file is the mandatory final step of implementation. The task is NOT complete until every implementation-owned section below is filled in. Complete the 구현 체크리스트; the final checklist item is mandatory before saving. Fill implementation-owned sections, then stop with active files in place and report ready for review. If implementation is blocked by a user-only decision, user-owned external environment prerequisite, or scope conflict, fill 사용자 리뷰 요청 with evidence and stop with active files in place; code-review decides whether to write USER_REVIEW.md. Evidence gaps that a follow-up agent can close by rerunning commands or collecting artifacts are normal follow-up issues, not user-review blockers by themselves. Do not ask the user directly, present choices in chat, or call request_user_input during implementation; record the needed decision in 사용자 리뷰 요청 and stop for code-review. Finalization (코드리뷰 결과, log rename, complete.log, archive moves, 코드리뷰 전용 체크리스트) is review-agent-only, even after compaction/resume. Follow the ownership table at the bottom of this file for which sections you own.

개요

date=2026-06-16 task=m-jenkins-thin-artifact-ci, plan=0, tag=JENKINS

Roadmap Targets

  • Milestone: agent-roadmap/phase/security-distribution/milestones/jenkins-thin-artifact-ci.md
  • Task ids:
    • job-config: macbook-ultra node, AppSok SCM, main branch, shell build step을 포함한 Jenkins job config를 만든다.
    • script-call: job build step이 ./scripts/build-certified-macos.sh를 호출하고 secret 원문을 job config나 repository에 남기지 않는다.
    • archive: Jenkins archived artifact 설정으로 ZIP과 checksum을 보관한다.
    • retention: build log와 artifact 보관 정책을 최근 10개 build 기준에 맞춘다.
  • Completion mode: check-on-pass

이 파일을 읽는 리뷰 에이전트에게

[REVIEW AGENT ONLY] 아래 종결 절차는 코드리뷰 에이전트 전용이다. 구현 에이전트는 이 섹션을 실행하지 않는다.

각 항목의 구현을 실제 소스 파일과 대조하고, 검증 결과 섹션의 출력이 코드와 일치하는지 확인하세요. 리뷰 완료는 아래 순서까지 끝난 상태를 의미합니다.

  1. 판정을 append한다.
  2. CODE_REVIEW-cloud-G07.md -> code_review_cloud_G07_N.log, PLAN-cloud-G07.md -> plan_cloud_G07_M.log로 아카이브한다.
  3. PASS이면 complete.log 작성 후 active task 디렉터리를 agent-task/archive/YYYY/MM/m-jenkins-thin-artifact-ci/로 이동한다. WARN/FAIL이면 user-review gate를 확인한 뒤 다음 active plan/review 파일 또는 USER_REVIEW.md를 작성한다. USER_REVIEW.md가 사용자 결정으로 완료/PASS 해소되면 code-review가 USER_REVIEW.md를 해소 상태로 갱신하고 complete.log 작성 후 archive 이동한다.
  4. PASS이고 task group이 m-<milestone-slug>이면 완료 이벤트 메타데이터를 보고한다. roadmap 상태 체크와 update-roadmap 호출은 런타임 책임이다.
  5. 적용 가능한 코드리뷰 전용 체크리스트 항목을 최종 .log 위치에서 체크한 뒤 보고한다.

구현 항목별 완료 여부

항목 완료 여부
[JENKINS-1] Jenkins job upsert script를 추가하고 dry-run XML로 검증 [ ]
[JENKINS-2] 문서/테스트 갱신 및 remote Jenkins API apply evidence [ ]

구현 체크리스트

  • [JENKINS-1] Jenkins job upsert script를 추가하고 macbook-ultra, main, ./scripts/build-certified-macos.sh, ZIP/sha256 archive, 최근 10개 보관 정책을 dry-run XML로 검증한다.
  • [JENKINS-2] 문서와 테스트를 갱신하고 remote runner에서 Jenkins API apply 및 config 조회 evidence를 남긴다.
  • CODE_REVIEW-*-G??.md의 구현 에이전트 소유 섹션을 실제 구현 내용과 검증 출력으로 채운다. 이 항목이 완료되기 전에는 구현이 완료된 것이 아니다.

코드리뷰 전용 체크리스트

[REVIEW AGENT ONLY] 이 체크리스트는 코드리뷰 에이전트만 사용한다. 구현 에이전트는 이 섹션을 수정하거나 체크하지 않는다.

  • 코드리뷰 결과PASS, WARN, FAIL 중 하나의 판정을 append한다.
  • 판정과 차원별 평가, Required/Suggested/Nit 분류가 서로 일치한다.
  • active CODE_REVIEW-*-G??.mdcode_review_{review_lane}_GNN_N.log로 아카이브한다.
  • active PLAN-*-G??.mdplan_{build_lane}_GNN_M.log로 아카이브한다.
  • .gitignore의 Agent-Ops 관리 block이 agent-task/**/*.mdagent-task/**/*.log를 unignore하고 agent-roadmap/current.md를 ignore하는지 확인한다.
  • PASS이면 agent-ops/skills/common/code-review/templates/complete-log-template.md 기준으로 complete.log를 작성하고 active .md 파일을 남기지 않는다.
  • PASS이면 active task 디렉터리 agent-task/m-jenkins-thin-artifact-ci/agent-task/archive/YYYY/MM/m-jenkins-thin-artifact-ci/로 이동하고 최종 archive 경로에서 이 체크리스트를 갱신한다.
  • PASS이고 task group이 m-<milestone-slug>이면 런타임이 읽을 완료 이벤트 메타데이터를 보고하고, roadmap 수정이나 update-roadmap 직접 호출을 하지 않는다.
  • PASS split 작업이면 이동 후 빈 active parent agent-task/{task_group}/를 제거하거나, 남은 sibling/file이 있어 유지했다고 확인한다.
  • WARN/FAIL이고 user-review gate가 트리거되지 않았으면 다음 active PLAN-{build_lane}-GNN.mdCODE_REVIEW-{review_lane}-GNN.md를 작성하고 complete.log를 작성하지 않는다.
  • USER_REVIEW이면 agent-ops/skills/common/code-review/templates/user-review-template.md 기준으로 USER_REVIEW.md를 작성하고 active PLAN-*.md, CODE_REVIEW-*.md, complete.log를 남기지 않는다.
  • USER_REVIEW가 사용자 결정으로 완료/PASS 해소되면 USER_REVIEW.md를 해소 상태로 갱신하고 complete.log를 작성한 뒤 task directory를 archive로 이동한다.

계획 대비 변경 사항

구현 에이전트가 계획과 다르게 구현한 부분을 이유와 함께 기록한다.

주요 설계 결정

구현 에이전트가 주요 설계 결정 사항을 기록한다.

사용자 리뷰 요청

기본값은 없음이다. 구현 중 사용자 결정, 사용자 소유 외부 환경/secret/서비스 준비, 또는 계획 범위 변경 없이는 안전하게 진행할 수 없으면 아래 항목을 실제 내용으로 교체하고, 구현을 중단한 뒤 active 파일을 그대로 둔 채 리뷰를 요청한다. 구현 에이전트는 사용자에게 직접 질문하거나 선택지를 제시하거나 request_user_input을 호출하지 않는다. 후속 에이전트가 명령 재실행이나 산출물 수집으로 해소할 수 있는 검증 증거 공백만으로는 사용자 리뷰 요청을 작성하지 않는다.

  • 상태: 없음
  • 사유 유형: 없음
  • 결정 필요: 없음
  • 차단 근거: 없음
  • 실행한 검증/명령: 없음
  • 자동 후속 불가 이유: 없음
  • 재개 조건: 없음

리뷰어를 위한 체크포인트

  • scripts/upsert-jenkins-certified-job.sh가 secret 원문을 출력하거나 XML에 넣지 않는지 확인한다.
  • Jenkins job XML이 macbook-ultra, */main, ./scripts/build-certified-macos.sh, ZIP/sha256 archive, retention 10을 모두 포함하는지 확인한다.
  • Jenkins apply evidence가 endpoint/token 원문 없이 job 존재와 config 반영을 증명하는지 확인한다.
  • Roadmap Targets의 네 Task만 PASS 완료 후보로 삼고, access Epic Task를 임의로 체크하지 않는다.

검증 결과

구현 에이전트가 각 중간 검증 및 최종 검증 명령 실행 후 출력을 여기에 붙여 넣는다.

필수 규칙:

  • 검증 명령은 고정된 계약이다. 임의로 대체하지 않는다.
  • 대체가 필요하면 계획 대비 변경 사항에 이유와 대체 명령을 기록한다.
  • 검증 결과에는 실제 stdout/stderr를 붙여 넣는다.
  • 사용자 리뷰 요청으로 명령을 끝까지 실행하지 못했다면 사용자 리뷰 요청에 실행한 명령, 실제 출력, 미실행 명령의 사유를 기록한다.
  • mobile/UI hang, timeout, 또는 2분 무진행은 blind retry를 중단하고 focused rerun 명령과 screenshot/window/UI-tree evidence path를 남기며, 불가능하면 정확한 사유를 남긴다.

JENKINS-1 중간 검증

$ git diff --check -- scripts/upsert-jenkins-certified-job.sh test/certified_macos_scripts_test.dart docs/macos-certified-build.md
(output)

$ flutter test test/certified_macos_scripts_test.dart
(output)

JENKINS-2 중간 검증

$ ssh -o BatchMode=yes -o ConnectTimeout=10 toki@toki-labs.com 'zsh -lc '\''cd "$HOME/docker/services/code-server/data/volume/workspace/appsok" && export PATH="$HOME/SDK/flutter/bin:/opt/homebrew/bin:/usr/local/bin:$PATH" && ./scripts/upsert-jenkins-certified-job.sh --dry-run >/tmp/appsok-macos-certified-config.xml && for marker in "appsok-macos-certified" "macbook-ultra" "*/main" "AppSok-certified.zip.sha256" "<numToKeep>10</numToKeep>" "<artifactNumToKeep>10</artifactNumToKeep>"; do grep -F "$marker" /tmp/appsok-macos-certified-config.xml >/dev/null && printf "%s=present\n" "$marker"; done'\'''
(output)

최종 검증

$ git diff --check -- scripts/upsert-jenkins-certified-job.sh test/certified_macos_scripts_test.dart docs/macos-certified-build.md
(output)

$ flutter test test/certified_macos_scripts_test.dart
(output)

$ ssh -o BatchMode=yes -o ConnectTimeout=10 toki@toki-labs.com 'zsh -lc '\''cd "$HOME/docker/services/code-server/data/volume/workspace/appsok" && export PATH="$HOME/SDK/flutter/bin:/opt/homebrew/bin:/usr/local/bin:$PATH" && ./scripts/upsert-jenkins-certified-job.sh --dry-run >/tmp/appsok-macos-certified-config.xml && for marker in "appsok-macos-certified" "macbook-ultra" "*/main" "AppSok-certified.zip.sha256" "<numToKeep>10</numToKeep>" "<artifactNumToKeep>10</artifactNumToKeep>"; do grep -F "$marker" /tmp/appsok-macos-certified-config.xml >/dev/null && printf "%s=present\n" "$marker"; done'\'''
(output)

$ ssh -o BatchMode=yes -o ConnectTimeout=10 toki@toki-labs.com 'zsh -lc '\''cd "$HOME/docker/services/code-server/data/volume/workspace/appsok" && export PATH="$HOME/SDK/flutter/bin:/opt/homebrew/bin:/usr/local/bin:$PATH" && ./scripts/upsert-jenkins-certified-job.sh --apply'\'''
(output)

[IMPLEMENTING AGENT — BEFORE SAVING] Have you filled in every implementation-owned section: completion table, implementation checklist, changes from plan, design decisions, and verification output? If anything is blank, go back and fill it in before saving this file. Leave review-agent-only sections unchanged.

Sections and Ownership

Section Owner Note
Header comment, 개요, 리뷰 에이전트 지시 Fixed at stub creation Implementing agent must not modify or execute these
Roadmap Targets Fixed at stub creation from plan Implementing agent must not modify; code-review copies it into complete.log as Roadmap Completion only on PASS
구현 항목별 완료 여부 Implementing agent Check [ ] to [x] only
구현 체크리스트 Implementing agent Check [ ] to [x] only
코드리뷰 전용 체크리스트 Review agent only Implementing agent must not modify or check this section
계획 대비 변경 사항, 주요 설계 결정 Implementing agent Replace placeholder text with actual content
사용자 리뷰 요청 Implementing agent Keep 상태: 없음 unless user input is required to proceed
리뷰어를 위한 체크포인트 Fixed at stub creation Review focus list
검증 결과 Implementing agent Fill command output only