Skip to content

ci: port refactor canary to main - #2519

Merged
Hweinstock merged 4 commits into
aws:mainfrom
Hweinstock:fix/canary-refactor-on-main
Oct 5, 2026
Merged

Hweinstock merged 4 commits into
aws:mainfrom
Hweinstock:fix/canary-refactor-on-main

Conversation

@Hweinstock

Copy link
Copy Markdown
Contributor

Description

Problem

Scheduled and workflow_run triggers only fire on the default branch (docs), so #2503 and #2508 on refactor never run.

Solution

  • Port refactor's E2E workflow as refactor-e2e.yml, always checking out refactor code.
  • Add canary(refactor) with its own concurrency group.
  • Port metrics workflow, triggered by canary(refactor).
  • Split ref into artifactRef/testRef so the canary runs the latest refactor tests against the @rc build.

Notes

  • Filename: refactor-e2e.yml avoids main's .github/workflows/e2e* path filter, which would otherwise trigger the full E2E suite on edits.
  • Concurrency group: canary-refactor, since main's Canary already uses the canary group.
  • No environment: matches refactor. Confirm the first run gets AWS credentials.
  • Metric dimension: now WorkflowName=canary(refactor).

Related Issue

Follow-up to #2503 and #2508.

Type of Change

  • Other (please describe): CI

Testing

Triggers can't run before merge. The test was a local simulation of the job: tests at refactor HEAD, with the RC commit built in artifact/.

> npx prettier --check .github/ && actionlint .github/workflows/{refactor-e2e,canary-refactor,workflow-metrics}.yml
All matched files use Prettier code style!
> node artifact/dist/index.js --version
1.0.0-rc.5
> AGENTCORE_CLI_PATH="node $PWD/artifact/dist/index.js" bunx vitest list --config vitest.e2e.config.ts --tagsFilter=canary
48 tests (harness.test.ts: 10, templates.test.ts: 38), 0 from artifact/

Checklist

  • I have read the CONTRIBUTING document
  • My changes generate no new warnings

@github-actions github-actions Bot added the size/m PR size: M label Oct 5, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.31.1.tgz

How to install

gh release download pr-2519-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.31.1.tgz

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Only workflow YAML is added here. I checked the three new files against the existing e2e-tests.yml patterns, the refactor branch's package.json (bin/main both point at dist/index.js, matching AGENTCORE_CLI_PATH), and the vitest.e2e.config.ts on refactor (tags are declared, so --tagsFilter=canary is valid). YAML parses cleanly; action references are pinned by SHA; OIDC-based AWS auth and persist-credentials: false on both checkouts look correct.

A couple of non-blocking things worth confirming before merge, but nothing that requires code changes:

  • canary-refactor.yml runs every 20 minutes and triggers Linux CodeBuild E2E runs — just make sure that cadence is intentional given the CodeBuild cost/queue.
  • The canary intentionally pairs artifactRef = v<rc version> with testRef: refactor. That's a reasonable canary design, but it means test-suite changes on refactor that assume unreleased CLI behavior will cause the canary to flap. Something to keep in mind when triaging failures.
  • The authorization bypass github.workflow == 'canary(refactor)' relies on the caller workflow's name: string matching exactly; if that name is ever changed, the canary will silently stop running the e2e job (authz would fall through to the user check and the scheduled actor would not match). Low risk, but worth a comment near the outputs.is-authorized expression.

Looks good to merge.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Oct 5, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 5, 2026
@Hweinstock Hweinstock changed the title ci: run refactor canary from main ci: port refactor canary to main Oct 5, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Oct 5, 2026
@Hweinstock
Hweinstock marked this pull request as ready for review October 5, 2026 16:07
@Hweinstock
Hweinstock requested a review from a team October 5, 2026 16:07
@Hweinstock
Hweinstock merged commit bd0e7fa into aws:main Oct 5, 2026
37 of 42 checks passed
@Hweinstock
Hweinstock deleted the fix/canary-refactor-on-main branch October 5, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants