diff --git a/.github/workflows/canary-refactor.yml b/.github/workflows/canary-refactor.yml new file mode 100644 index 0000000000..45fab14d0e --- /dev/null +++ b/.github/workflows/canary-refactor.yml @@ -0,0 +1,51 @@ +name: canary(refactor) +on: + schedule: + - cron: '*/20 * * * *' + workflow_dispatch: + +concurrency: + group: canary-refactor + cancel-in-progress: false + +permissions: + id-token: write + contents: read + +jobs: + # Resolve the commit hash for the latest published @rc version. + resolve_release: + runs-on: ubuntu-latest + outputs: + ref: ${{ steps.resolve.outputs.ref }} + steps: + - uses: actions/setup-node@v4 + with: + node-version: '24' + - name: Resolve latest RC release commit + id: resolve + run: | + version="$(npm view @aws/agentcore@rc version)" + tag_ref="refs/tags/v${version}" + # Resolve annotated tags to their commit hash when needed. + ref="$(git ls-remote https://github.com/aws/agentcore-cli.git "${tag_ref}" "${tag_ref}^{}" | awk -v tag_ref="${tag_ref}" ' + $2 == tag_ref "^{}" { print $1; found = 1; exit } + $2 == tag_ref { tag_sha = $1 } + END { if (!found && tag_sha != "") print tag_sha } + ')" + if [[ -z "${ref}" ]]; then + echo "::error::No upstream tag found for @aws/agentcore@rc version ${version}" + exit 1 + fi + echo "ref=${ref}" >> "$GITHUB_OUTPUT" + + e2e: + needs: resolve_release + uses: ./.github/workflows/refactor-e2e.yml + with: + artifactRef: ${{ needs.resolve_release.outputs.ref }} + testRef: refactor + tags: canary + linuxOnly: true + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} diff --git a/.github/workflows/refactor-e2e.yml b/.github/workflows/refactor-e2e.yml new file mode 100644 index 0000000000..e5fd40148d --- /dev/null +++ b/.github/workflows/refactor-e2e.yml @@ -0,0 +1,153 @@ +name: e2e-test(refactor) +on: + workflow_call: + inputs: + artifactRef: + description: git reference (commit, branch, or tag) to build the CLI from + required: false + type: string + default: '' + testRef: + description: git reference (commit, branch, or tag) to run E2E tests from, defaults to artifactRef + required: false + type: string + default: '' + tags: + description: Vitest tag expression, for example runtime || canary + required: false + type: string + default: '' + linuxOnly: + description: Run E2E tests only on Linux + required: false + type: boolean + default: false + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: + required: true + workflow_dispatch: + inputs: + artifactRef: + description: git reference (commit, branch, or tag) to build the CLI from + type: string + default: refactor + testRef: + description: git reference (commit, branch, or tag) to run E2E tests from, defaults to artifactRef + type: string + default: '' + tags: + description: Vitest tag expression, for example runtime || canary + type: string + default: '' + linuxOnly: + description: Run E2E tests only on Linux + type: boolean + default: false + +concurrency: + group: + e2e-test-${{ inputs.artifactRef || 'refactor' }}-${{ inputs.testRef || inputs.artifactRef || 'refactor' }}-${{ + inputs.tags || 'all' }}-${{ inputs.linuxOnly && 'linux-only' || 'all-os' }} + cancel-in-progress: false + +env: + AGENTCORE_TELEMETRY_DISABLED: '1' + +jobs: + authorize: + runs-on: ubuntu-latest + permissions: + id-token: write + contents: read + outputs: + is-authorized: ${{ github.workflow == 'canary(refactor)' || steps.check.outputs.is_authorized == 'true' }} + steps: + - name: Fetch secrets from Secrets Manager + uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 + with: + role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} + repo: AUTHORIZED_USERS + - name: Check authorization + id: authz + uses: aws/agentcore-devx-devtools/.github/actions/check-authorized-user@31aa3b031a86664e29861d68956e44b07cf21a74 + with: + subject: ${{ github.actor }} + authorized-users: ${{ env.AUTHORIZED_USERS }} + - name: Determine authorization + id: check + env: + IS_AUTHORIZED: ${{ steps.authz.outputs.is-authorized }} + ACTOR: ${{ github.actor }} + run: | + if [[ "$IS_AUTHORIZED" == "true" ]]; then + echo "Actor ${ACTOR} is authorized" + echo "is_authorized=true" >> "$GITHUB_OUTPUT" + else + echo "Actor ${ACTOR} is not in AUTHORIZED_USERS, skipping" + echo "is_authorized=false" >> "$GITHUB_OUTPUT" + fi + + e2e: + name: test (${{ matrix.name }}) + needs: authorize + if: needs.authorize.outputs.is-authorized == 'true' + runs-on: >- + ${{ fromJSON( + matrix.name == 'Linux' && + format('["codebuild-agentcore-e2e-{0}-{1}","e2e-linux"]', github.run_id, github.run_attempt) + || matrix.name == 'Windows' && + format('["codebuild-agentcore-e2e-{0}-{1}","image:windows-1.0","e2e-windows"]', github.run_id, + github.run_attempt) + || matrix.name == 'macOS' && '["macos-latest"]' + ) }} + permissions: + id-token: write + contents: read + strategy: + fail-fast: false + matrix: + name: ${{ fromJSON(inputs.linuxOnly && '["Linux"]' || '["Linux","Windows","macOS"]') }} + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ inputs.testRef || inputs.artifactRef || 'refactor' }} + persist-credentials: false + - uses: actions/checkout@v7 + with: + ref: ${{ inputs.artifactRef || 'refactor' }} + path: artifact + persist-credentials: false + - uses: oven-sh/setup-bun@v2 + - uses: actions/setup-node@v4 + with: + node-version: '24' + - uses: astral-sh/setup-uv@v6 + - run: bun install --frozen-lockfile + - run: bun install --frozen-lockfile + working-directory: artifact + - name: Fetch E2E role from Secrets Manager + uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 + with: + role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} + repo: E2E_AWS_ROLE_ARN + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v6 + with: + role-to-assume: ${{ env.E2E_AWS_ROLE_ARN }} + aws-region: ${{ vars.E2E_REGION || 'us-east-1' }} + unset-current-credentials: true + - name: Build CLI + working-directory: artifact + run: bun run build + - name: Run all E2E tests + if: inputs.tags == '' + env: + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/artifact/dist/index.js + AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} + run: bun run test:e2e + - name: Run tagged E2E tests + if: inputs.tags != '' + env: + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/artifact/dist/index.js + AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} + run: bun run test:e2e -- --tagsFilter="${{ inputs.tags }}" diff --git a/.github/workflows/workflow-metrics.yml b/.github/workflows/workflow-metrics.yml new file mode 100644 index 0000000000..19b1e257f4 --- /dev/null +++ b/.github/workflows/workflow-metrics.yml @@ -0,0 +1,18 @@ +name: Workflow Metrics +on: + workflow_run: + workflows: ['canary(refactor)'] + types: [completed] + +permissions: + id-token: write + +jobs: + metrics: + uses: aws/agentcore-devx-devtools/.github/workflows/workflow-metrics.yml@d145deb62f1adc8be63fa4879a488499e1128a46 + with: + namespace: AgentCoreCLI/Workflows + os: Linux + role-secret-name: E2E_AWS_ROLE_ARN + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }}