Building a Fast, Secure, and Cost-Efficient Repository Orchestration System : Maintaining automation across many software projects becomes difficult surprisingly quickly. Workflows drift, credentials multiply, model usage becomes expensive, and each repository develops slightly different behavior. We recently replaced that fragmented setup with one standardized, repository-scoped orchestration system. The result is a shared foundation that can understand requests, triage work, inspect code, update issues and pull requests, implement focused changes, and leave an auditable record—all while using a small set of organization-level secrets.
One event-driven agent for issues and pull requests : The system runs through GitHub Actions and listens for explicit requests. The same agent can operate from either an issue or a pull request, but its authority remains limited to the repository and conversation where it was invoked. Before acting, the workflow classifies the request:
- answer a technical question; - investigate a failure; - update issue or pull-request metadata; - review an existing change; - implement a scoped fix; or - decline an unsafe or unrelated request. This intent-first design avoids launching a full coding session for simple questions. Expensive tools are enabled only when the task actually needs them.
A separate automatic triage layer:
Interactive work and background organization are handled independently. A lightweight triage workflow classifies new issues and pull requests, applies labels, identifies task type and priority, and fills the appropriate project fields. Separating triage from implementation keeps both paths fast. Routine categorization does not need the larger context window or broader tool access required for code changes. Free-model routing with a single inference key : Model access is provided through Pollinations and a routing harness. Instead of sending every task to one large model, requests are split by workload: - a capable reasoning model handles planning and repository changes; - a fast model handles summaries, classification, and background work; - a search-oriented model is used only when current external information is required. Only free model routes are enabled. Token ceilings, bounded tool turns, and context limits prevent a small request from becoming an open-ended session. One organization-level Pollinations key powers the complete inference layer, which makes the setup easier to distribute and rotate. Smaller context through RTK : Rust Token Killer, or RTK, reduces the amount of terminal output returned to the agent. Commands, diffs, searches, and test logs are filtered into the portions that matter to the current task. This improves the system in two ways: it lowers token usage and reduces distraction. The agent sees the relevant failure or changed lines instead of repeatedly consuming entire logs and files. Repository context is also loaded progressively. Configuration, recent changes, and task-specific files are gathered first; the rest of the codebase is inspected only when needed. Shared historical context can be stored in a Gist, allowing workflows to retain useful knowledge without placing a large changelog into every prompt. Three secrets with distinct responsibilities: The orchestration layer uses three organization-level secrets:
- one repository token for issues, pull requests, branches, comments, and workflow operations; - one Gist token for shared context and changelog storage; and - one Pollinations key for model routing. Keeping repository and Gist access separate follows least-privilege principles. A workflow that needs repository access does not automatically receive unrelated Gist authority, and each token can be rotated or revoked independently. Legacy repository-specific credentials are being retired after the standardized workflows reach their default branches. This reduces secret sprawl and removes the need to maintain several names for the same capability. Portable workflows, repository-specific identity:
The shared workflows, routing adapters, acknowledgement jobs, retry behavior, assignment rules, and pull-request description tools are identical everywhere. Only repository identity and project metadata remain configurable. Portability required more than copying YAML. Different projects enforce different formatter versions and line-width rules, so the shared JavaScript adapters were refactored into a formatter-neutral form that passes both older and current tooling. This is an important property of shared automation: the baseline must survive the strictest consumer without creating per-project forks.
Safety and observability :
Every operation remains auditable through workflow logs, commits, comments, and pull-request history. The agent receives bounded repository permissions rather than unrestricted infrastructure access. Explicit invocation prevents ordinary discussion from accidentally starting an automation run, while concurrency controls stop duplicate requests from racing against each other. Failures are handled conservatively. If description generation or a model request fails, existing human-written content is preserved. Retrying a workflow does not silently overwrite issue or pull-request data. What this architecture gives us : The standardized system now provides: - consistent behavior across projects; - one command surface for issues and pull requests; - automatic labels, priorities, and project categorization; - lower token usage through routing, bounded context, and RTK; - reduced credential sprawl; - portable, formatter-compatible workflow tooling; and - an auditable path from request to code change. The larger lesson is that useful repository automation is not created by adding the biggest model to a workflow. It comes from careful orchestration: classify first, load only the necessary context, grant only the required permissions, use the smallest suitable model, and preserve a clear record of every action.
Check for the GitHub Organisation Elixpo GitHub Organisation
Technically speaking, one of the most wanted wishes of creating an agentic service via this platform ❤️

