Files
Stefan Broenner b7a01a1ccd Fix usage analytics interpretation validation (#860)
Co-authored-by: Stefan Broenner <stbrnner@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
2026-09-08 17:26:10 -07:00

162 lines
4.8 KiB
YAML

name: Weekly Usage Analytics
on:
schedule:
- cron: "17 4 * * 1"
pull_request:
paths:
- '.github/workflows/usage-analytics.yml'
- 'scripts/*UsageAnalytics*.ps1'
- 'gh-pages/**'
- '.github/usage-analytics.json'
workflow_dispatch:
inputs:
publish:
description: Persist the validated report to analytics-data
required: true
type: boolean
default: false
concurrency:
group: usage-analytics
cancel-in-progress: false
permissions:
contents: read
jobs:
test:
name: Test analytics privacy gates
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Test analytics scripts
shell: pwsh
run: ./scripts/Test-UsageAnalytics.ps1
collect:
name: Collect sanitized aggregates
if: github.event_name != 'pull_request'
needs: test
permissions:
contents: read
id-token: write
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Authenticate to Azure
uses: azure/login@v3
with:
client-id: ${{ vars.AZURE_CLIENT_ID }}
tenant-id: ${{ vars.AZURE_TENANT_ID }}
subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }}
- name: Query sanitized aggregate telemetry
shell: pwsh
run: |
$workspaceId = az monitor log-analytics workspace show `
--resource-group excelmcp-observability `
--workspace-name excelmcp-logs `
--query customerId `
--output tsv `
--only-show-errors
if ($LASTEXITCODE -ne 0 -or [string]::IsNullOrWhiteSpace($workspaceId)) {
throw "Unable to resolve the Log Analytics workspace."
}
$agentDirectory = Join-Path $env:RUNNER_TEMP "usage-analytics-agent"
New-Item -ItemType Directory -Path $agentDirectory | Out-Null
./scripts/Update-UsageAnalytics.ps1 `
-WorkspaceId $workspaceId `
-OutputPath (Join-Path $agentDirectory "analytics.json")
- name: End Azure session
if: always()
run: az logout
- name: Upload sanitized aggregates
uses: actions/upload-artifact@v7
with:
name: usage-analytics-input
path: ${{ runner.temp }}/usage-analytics-agent/analytics.json
if-no-files-found: error
retention-days: 1
interpret:
name: Interpret and validate report
needs: collect
permissions:
contents: read
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Download sanitized aggregates
uses: actions/download-artifact@v8
with:
name: usage-analytics-input
path: ${{ runner.temp }}/usage-analytics-agent
- name: Setup Node.js
uses: actions/setup-node@v7
- name: Install Copilot CLI
run: npm install --global @github/copilot@1.0.80
- name: Interpret and validate sanitized aggregates
shell: pwsh
env:
COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
run: |
if ([string]::IsNullOrWhiteSpace($env:COPILOT_GITHUB_TOKEN)) {
throw "COPILOT_GITHUB_TOKEN is not configured."
}
$agentDirectory = Join-Path $env:RUNNER_TEMP "usage-analytics-agent"
./scripts/Invoke-UsageAnalyticsReport.ps1 `
-AnalyticsPath (Join-Path $agentDirectory "analytics.json") `
-InterpretationPath (Join-Path $agentDirectory "interpretation.md") `
-OutputPath (Join-Path $agentDirectory "usage-analytics.json")
- name: Upload validated report
uses: actions/upload-artifact@v7
with:
name: usage-analytics-report
path: ${{ runner.temp }}/usage-analytics-agent/usage-analytics.json
if-no-files-found: error
retention-days: 7
publish:
name: Publish validated report
if: github.event_name == 'schedule' || inputs.publish == true
needs: interpret
permissions:
contents: write
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Download validated report
uses: actions/download-artifact@v8
with:
name: usage-analytics-report
path: ${{ runner.temp }}/usage-analytics-report
- name: Persist to analytics-data branch
shell: pwsh
env:
GH_TOKEN: ${{ github.token }}
run: |
./scripts/Persist-UsageAnalytics.ps1 `
-Repository '${{ github.repository }}' `
-Branch 'analytics-data' `
-ReportPath (Join-Path $env:RUNNER_TEMP 'usage-analytics-report/usage-analytics.json') `
-RemotePath '.github/usage-analytics.json' `
-CommitSha '${{ github.sha }}' `
-TempPath $env:RUNNER_TEMP