ci: port refactor canary to main - #2519
Merged
Merged
Conversation
Contributor
Package TarballHow to installgh release download pr-2519-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.31.1.tgz |
Contributor
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Only workflow YAML is added here. I checked the three new files against the existing e2e-tests.yml patterns, the refactor branch's package.json (bin/main both point at dist/index.js, matching AGENTCORE_CLI_PATH), and the vitest.e2e.config.ts on refactor (tags are declared, so --tagsFilter=canary is valid). YAML parses cleanly; action references are pinned by SHA; OIDC-based AWS auth and persist-credentials: false on both checkouts look correct.
A couple of non-blocking things worth confirming before merge, but nothing that requires code changes:
canary-refactor.ymlruns every 20 minutes and triggers Linux CodeBuild E2E runs — just make sure that cadence is intentional given the CodeBuild cost/queue.- The canary intentionally pairs
artifactRef = v<rc version>withtestRef: refactor. That's a reasonable canary design, but it means test-suite changes onrefactorthat assume unreleased CLI behavior will cause the canary to flap. Something to keep in mind when triaging failures. - The authorization bypass
github.workflow == 'canary(refactor)'relies on the caller workflow'sname:string matching exactly; if that name is ever changed, the canary will silently stop running thee2ejob (authz would fall through to the user check and the scheduled actor would not match). Low risk, but worth a comment near theoutputs.is-authorizedexpression.
Looks good to merge.
Contributor
|
Claude Security Review: no high-confidence findings. (run) |
Hweinstock
marked this pull request as ready for review
October 5, 2026 16:07
nborges-aws
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Problem
Scheduled and
workflow_runtriggers only fire on the default branch (docs), so #2503 and #2508 onrefactornever run.Solution
refactor-e2e.yml, always checking out refactor code.canary(refactor)with its own concurrency group.canary(refactor).refintoartifactRef/testRefso the canary runs the latest refactor tests against the@rcbuild.Notes
refactor-e2e.ymlavoids main's.github/workflows/e2e*path filter, which would otherwise trigger the full E2E suite on edits.canary-refactor, since main'sCanaryalready uses thecanarygroup.environment: matches refactor. Confirm the first run gets AWS credentials.WorkflowName=canary(refactor).Related Issue
Follow-up to #2503 and #2508.
Type of Change
Testing
Triggers can't run before merge. The test was a local simulation of the job: tests at
refactorHEAD, with the RC commit built inartifact/.Checklist