Page 6 of 8~112 min topic

Eval gates in code

Instrument the CI eval release gate

Page 6 adds signals that distinguish bad input from component failure in the release eval gate in CI.

~14 min this pageTesting and observability

1Learn the idea

Read

Emit stage signals

Instrument the release eval gate in CI so a run records enough structure to debug offline: counts, latency if relevant, pass/fail of pass/fail exit code, and a stable stage name. Redact secrets and raw credentials from every event.

Read

Emit and assert

import json
print(json.dumps({'stage':'eval-gate','seed':7,'baseline':0.92,'candidate':0.81,'exit_code':1}))

Expected evidence: eval gate telemetry. Prefer JSON or structured text you can grep in CI over prose logs for eval-in-code.

Read

Lock signals with a regression test

Turn one historical failure—especially flaky eval that flips without seed control—into a test that fails if the signal disappears for the CI eval release gate. Observability without a failing test is optional decoration; observability with a test is part of the eval-in-code artifact.

Read

Lab notebook: signal schema

Draft a three-field event for the CI eval release gate: stage, ok, and one domain field derived from pass/fail exit code; metric deltas vs baseline; seed recorded. Add fixture_id or docs_version when content can change. Explicitly list fields that must never appear (tokens, passwords, raw prompts) because editing golden expected answers to greenwash a bad candidate is in scope for this lab.

Wire one assertion that fails if the CI eval release gate event is missing after a run. Observability that cannot fail a test will not survive contact with a busy eval-in-code repository.

Read

Worked judgment

Imagine a teammate opens only your event stream after a bad deploy. Could they tell whether golden JSONL + threshold.yaml was wrong, whether flaky eval that flips without seed control, or soft-fail that never blocks merge returned, or whether editing golden expected answers to greenwash a bad candidate slipped through? If not, rename fields until those three stories are distinguishable.

Read

Why this stage matters for the CI eval release gate

At the testing and observability stage for eval-in-code, the job is narrower than finishing a product demo. You are creating one progressive evidence piece about golden JSONL + threshold.yaml that later pages inherit without redefining success. Keep that fixture small enough to inspect by hand, keep outputs copy-pasteable as text, and refuse to narrate this baseline as if it were a production SLA: last known good release metrics.

For this page specifically, success looks like a structured event schema locked by a test while still centering the user decision to fail a candidate release when golden-task metrics regress past a pinned threshold. If you cannot point to a file, command, or assertion that proves that for the CI eval release gate, stay on this page instead of advancing.

How-to: ship agent with eval gate · Glossary: eval set

Previous · Next

Go deeper

Before you start

Why this matters

Write the single log line or metric event that would tell you whether a bad result came from input vs implementation for the CI eval release gate. If your line could not tell them apart, redesign it before coding.

In the wild

See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.

Check your understanding

Page assessment

Answer from memory. Completion is saved from this evidence, not from opening the next page.

1. Can input faults be distinguished from component faults in the event?
2. Are secrets redacted from logs?
3. Is there a test that fails if the signal vanishes?
4. Does the event still reference the decision: fail a candidate release when golden-task metrics regress past a pinned threshold?

All responses are required.