Skip to content

ci: let the Swagger validator's browser launch - #162

Merged
sk-portkey merged 2 commits into
Portkey-AI:masterfrom
vrv-panw:ci/swagger-validator-chromium
Sep 30, 2026
Merged

sk-portkey merged 2 commits into
Portkey-AI:masterfrom
vrv-panw:ci/swagger-validator-chromium

Conversation

@vrv-panw

@vrv-panw vrv-panw commented Sep 29, 2026 •

Copy link
Copy Markdown

Summary

The Swagger Editor Validator Service check fails on every PR, including #160, before it validates anything. The cause is the CI setup, not the spec. There were two separate problems:

  1. Chromium can't start. char0n/swagger-editor-validate drives a headless Chromium through Puppeteer. ubuntu-latest is now Ubuntu 24.04, where AppArmor blocks the unprivileged user namespaces Chromium's sandbox needs. A new step sets kernel.apparmor_restrict_unprivileged_userns=0, which only affects the throwaway GitHub-hosted runner.
  2. The editor image changed. swaggerapi/swagger-editor:latest is now SwaggerEditor 5. It serves on port 80, not 8080, so the check got ERR_CONNECTION_RESET. Its UI also lacks the v4 .errors-wrapper panel the action reads errors from. The service is now pinned to v4.14.8, the last v4 release.

It also bumps actions/checkout from v2 to v4, since v2 runs on a deprecated Node runtime.

With both fixes the check runs to completion on this PR. The log shows "Definition successfully validated by Swagger Editor" for the current openapi.yaml on master.

Test plan

  • The Swagger Editor Validator Service check on this PR launches the browser, reaches the editor and validates openapi.yaml
  • After merge, merge master into Add /v1/decisions endpoint spec #160 and confirm its check passes

🤖 Generated with Claude Code

Ubuntu 24.04 runners restrict unprivileged user namespaces via AppArmor, so the headless Chromium that char0n/swagger-editor-validate drives cannot start its sandbox and the check fails before validating anything. Lift the restriction on the ephemeral runner, and move checkout to v4.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 06:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused workflow changes correctly address the documented browser-launch failure.

Review effort: Balanced
Findings: None

What changed in this PR

Updates CI so Chromium can launch during OpenAPI validation on Ubuntu 24.04 runners.

Changes:

  • Upgrades actions/checkout from v2 to v4.
  • Enables unprivileged user namespaces before validation.
File Description
.github/​workflows/​validate-openapi.yml Updates checkout and configures AppArmor for Chromium.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

swaggerapi/swagger-editor:latest moved to SwaggerEditor 5. Its nginx listens on 80, not 8080, so the validator got ERR_CONNECTION_RESET, and its UI lacks the .errors-wrapper panel char0n/swagger-editor-validate parses. v4.14.8 is the last v4 release.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 29, 2026 06:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused workflow changes correctly address Chromium startup and Swagger Editor compatibility.

Review effort: Balanced
Findings: None

@sk-portkey
sk-portkey merged commit 54c7d35 into Portkey-AI:master Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants