The unit, browser and terraform suites run as workflows (.github/workflows). This issue is the
Claude half that comes after: claude-code-action answering issues, turning a triaged issue into a PR, and
reviewing PRs. The design is in .github/workflows/TODO.md; the loop it closes is the self-heal
loop in modules/tasks/TODO.md and prod/platform/operator/TODO.md § the operator agent.
what the owner sets up
- a practice repo — a throwaway public repo the loop rehearses on first; its name is config in
the operator agent's SSM, so the cutover to the real repo is a value change.
- a custom GitHub App — Contents, Issues, PRs read+write; webhooks off; installed on one repo.
Repo secrets APP_ID, APP_PRIVATE_KEY; workflows get tokens from
actions/create-github-app-token.
ANTHROPIC_API_KEY — a repo secret. Everything the bot reads is public (the repo and the
board), so it runs on the Anthropic API, which carries the newest models.
the workflows
- issue triage —
claude-code-action@v1 on issues.opened and issue_comment. The prompt
labels (bug|feature, module), asks for what's missing, and links hash-distinct issues that are
one defect. It never closes an issue: closing is the operator agent's, keyed to release
annotations. claude_args sets --max-turns and --model.
Done when an escalate call from a gerp ends as a labelled issue with its placeholders intact,
and a differently worded escalation of the same defect is linked to it.
- the fix leg —
@claude on a triaged issue yields a PR (same action, same key). A merged fix
deploys with bash scripts/deploy.sh push --notes "...", whose release annotation names the
signature hashes it fixes. MCP servers mount per workflow through claude_args --mcp-config,
each tool named in --allowedTools.
- PR review — the code-review workflow on every PR, no mention needed.
open
- issues on the platform repo, or a dedicated issues repo (
modules/tasks/TODO.md).
The unit, browser and terraform suites run as workflows (
.github/workflows). This issue is theClaude half that comes after:
claude-code-actionanswering issues, turning a triaged issue into a PR, andreviewing PRs. The design is in
.github/workflows/TODO.md; the loop it closes is the self-healloop in
modules/tasks/TODO.mdandprod/platform/operator/TODO.md§ the operator agent.what the owner sets up
the operator agent's SSM, so the cutover to the real repo is a value change.
Repo secrets
APP_ID,APP_PRIVATE_KEY; workflows get tokens fromactions/create-github-app-token.ANTHROPIC_API_KEY— a repo secret. Everything the bot reads is public (the repo and theboard), so it runs on the Anthropic API, which carries the newest models.
the workflows
claude-code-action@v1onissues.openedandissue_comment. The promptlabels (
bug|feature, module), asks for what's missing, and links hash-distinct issues that areone defect. It never closes an issue: closing is the operator agent's, keyed to release
annotations.
claude_argssets--max-turnsand--model.Done when an
escalatecall from a gerp ends as a labelled issue with its placeholders intact,and a differently worded escalation of the same defect is linked to it.
@claudeon a triaged issue yields a PR (same action, same key). A merged fixdeploys with
bash scripts/deploy.sh push --notes "...", whose release annotation names thesignature hashes it fixes. MCP servers mount per workflow through
claude_args --mcp-config,each tool named in
--allowedTools.open
modules/tasks/TODO.md).