Add GitHub REST and GraphQL API point budgets - #8978
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
GraphQL mutations, pagination, and attached method shorthand can undercount usage and permit configured budgets to be exceeded.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds configurable per-run GitHub API point budgets to the protected gh CLI proxy.
Changes:
- Adds REST and GraphQL budget configuration, CLI flags, validation, and schemas.
- Enforces budgets in the CLI proxy with HTTP 429 responses and audit events.
- Adds mapping, service wiring, and limiter tests.
| File | Description |
|---|---|
src/types/cli-proxy-options.ts |
Defines point-budget options. |
src/services/cli-proxy-service.ts |
Passes budgets to the proxy. |
src/services/cli-proxy-service.test.ts |
Tests environment wiring. |
src/config-mapper.ts |
Maps file configuration. |
src/config-file.ts |
Extends configuration types. |
src/config-file-validation.test.ts |
Tests budget validation. |
src/config-file-mapping.test.ts |
Tests configuration mapping. |
src/commands/validators/infrastructure-validator.ts |
Validates limits and proxy requirement. |
src/commands/build-config.ts |
Builds numeric budget settings. |
src/cli-options.ts |
Adds CLI flags. |
src/awf-config-schema.json |
Updates runtime schema. |
docs/awf-config.schema.json |
Updates canonical schema. |
docs/awf-config-spec.md |
Documents budget behavior. |
containers/cli-proxy/server.js |
Enforces limits and logs rejections. |
containers/cli-proxy/github-api-point-limiter.test.js |
Tests classification and budgets. |
containers/cli-proxy/github-api-point-limiter.js |
Implements request classification and accounting. |
containers/cli-proxy/Dockerfile |
Includes the limiter module. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 458d7ea |
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.80% | 92.78% | 📉 -0.02% |
| Statements | 91.35% | 91.33% | 📉 -0.02% |
| Functions | 89.78% | 89.78% | ➡️ +0.00% |
| Branches | 84.63% | 84.58% | 📉 -0.05% |
📁 Per-file Coverage Changes (2 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/commands/validators/infrastructure-validator.ts |
100.0% → 90.3% (-9.73%) | 100.0% → 90.4% (-9.59%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Smoke Gemini completed. All facets verified. 💎 Warning Firewall blocked 3 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "github.com"
- "play.googleapis.com"See Network Configuration for more information.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "msfeed25.pkgs.visualstudio.com"See Network Configuration for more information.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
Smoke Test: Cloud Hypervisor + Copilot
Result: ALL PASS Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine
Overall: PASS
|
Smoke Test: Copilot BYOK (Direct) Mode
Mode: Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com Status: PASS
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com): Overall: PASS Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
Gemini Smoke Test Results
Overall Status: PASS Warning Firewall blocked 3 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "github.com"
- "play.googleapis.com"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version differs between host and chroot environment, so the
|
|
Smoke Test: GitHub Actions Services Connectivity
Overall: PASS
|
|
fix: download NVX release assets outside the agent sandbox Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "msfeed25.pkgs.visualstudio.com"See Network Configuration for more information.
|
Smoke Test: API Proxy OpenTelemetry Tracing — Results
Summary: All scenarios pass. OTEL module initialization, span creation/attribute logic, env var propagation, and token-tracker hook points all check out. Span export mechanism is functioning (workflow-level span successfully exported to Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|

Adds per-run point budgets for
gh apiREST and GraphQL calls, preventing protected CLI proxy workloads from exceeding configured GitHub API secondary-rate-limit usage.Configuration
maxGithubApiPointsRestandmaxGithubApiPointsGraphqlunderrateLimiting.--max-github-api-points-rest--max-github-api-points-graphqlEnforcement
ghCLI proxy.Auditability
github_api_points_limitedstructured audit records with API kind, configured limit, used points, and remaining budget.