Codex Automation and CI/CD
Codex provides multiple automation methods that can be used in scripts, pipelines, and server-side.
Non-interactive mode (exec)
The exec command is used for scripting and automation scenarios, without needing to open the TUI.
Basic usage
exec command
codex exec "Review the code and output a report"
# Output to file
codex exec -o review.md "Review src/auth.py"
# Use a specific model
codex exec -m gpt-5.4-mini "Analyze the project structure"
# Fully automatic execution
codex exec --full-auto "Run tests and fix failures"
Common parameters
| Parameter | Description |
|---|---|
-m | Specify model |
-o | Output result to file |
--full-auto | Fully automatic execution |
--ephemeral | Do not save session files |
--json | JSON Lines output format |
--output-schema | Output according to JSON Schema format |
--sandbox | Set sandbox mode |
Read from standard input
stdin input
echo "Explain this error" | codex exec -
# Read from file
codex exec - < task.txt
# Multi-line task
cat <<EOF | codex exec -
Analyze src/directory
Find potential bugs
Output fix suggestions
EOF
Resume session
Resume execution
codex exec resume --last "Continue fixing bugs"
# Resume a specified session
codex exec resume --session abc123 "Next task"
By default, exec runs in a read-only sandbox and does not modify files.
Codex SDK
The Codex SDK provides a programming interface to invoke Agent capabilities in code.
Install SDK
Install SDK
Usage examples
SDK basic usage
// Create Codex client
const codex = new Codex({
apiKey: process.env.OPENAI_API_KEY
});
// Execute task
const thread = await codex.run({
prompt: 'Review the src/auth.py file',
model: 'gpt-5.4'
});
// Get result
console.log(thread.messages);
// Continue task
const followUp = await codex.run({
threadId: thread.id,
prompt: 'Fix the discovered bugs'
});
SDK applicable scenarios
- Integrate into CI/CD pipelines
- Create custom Agent applications
- Automate internal tools
- Batch processing tasks
GitHub Action
The official Codex GitHub Action allows triggering tasks in CI pipelines.
Basic workflow
GitHub Action example
name: Codex Review
on: [pull_request]
jobs:
codex-review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Run Codex Review
uses: openai/codex-action@v1
with:
prompt-file: '.github/codex-review.md'
model: 'gpt-5.4'
sandbox: 'workspace-write'
output-file: 'review.md'
- name: Post Review
uses: actions/github-script@v7
with:
script: |
const fs = require('fs');
const review = fs.readFileSync('review.md', 'utf8');
github.rest.pulls.createReview({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.issue.number,
body: review,
event: 'COMMENT'
});
Action parameters
| Parameters | Description |
|---|---|
prompt | Specify task description directly |
prompt-file | Specify task file path |
model | Model used |
sandbox | Sandbox mode |
output-file | Output file path |
codex-args | Additional CLI parameters |
Security configuration
Security settings
- name: Run Codex
uses: openai/codex-action@v1
with:
prompt: 'Review changes'
safety-strategy: 'drop-sudo'
unprivileged-user: 'codex-runner'
allow-users: ['maintainers']
When using GitHub Action, ensure the API Key is stored as Secrets, do not hardcode it.
App Server
App Server exposes Codex capabilities as a server-side API.
Start App Server
Start service
codex app-server
# Specify port
codex app-server --port 3000
# Remote access
codex --remote ws://server:3000
Applicable scenarios
- Team sharing of Codex capabilities
- Remote CI/CD invocation
- Integration into internal platforms
MCP Server
Provide Codex as an MCP tool for other Agents to call.
Configure Codex MCP
MCP Server configuration
[mcp_servers.codex]
command = "codex"
args = ["mcp-server"]
Best practices
Security
- Use read-only sandbox mode
- Store API Key as Secrets
- Limit trigger conditions (only specific events)
- Review output before applying changes
Reliability
- Set a reasonable timeout
- Use --ephemeral to avoid state residue
- Verify task success before continuing
- Handle rollback in case of failure
Frequently asked questions
Q: What's the difference between exec and interactive mode?
exec exits after a single execution, suitable for automation; interactive mode continues the conversation.
Q: How to authenticate in CI/CD?
Use the CODEX_API_KEY environment variable, stored as Secrets.
Q: Can GitHub Action modify files?
Yes, set sandbox: workspace-write.
Q: How to use in Docker?
Install Codex into the image, configure authentication, then call it.
Other extensions