From 52a9bf07ec41f46d529910c3698df3ce1723f219 Mon Sep 17 00:00:00 2001 From: Hweinstock Date: Mon, 5 Oct 2026 13:29:20 +0000 Subject: [PATCH 1/4] ci: port refactor E2E reusable workflow to main --- .github/workflows/refactor-e2e.yml | 136 +++++++++++++++++++++++++++++ 1 file changed, 136 insertions(+) create mode 100644 .github/workflows/refactor-e2e.yml diff --git a/.github/workflows/refactor-e2e.yml b/.github/workflows/refactor-e2e.yml new file mode 100644 index 0000000000..94d56ba1d6 --- /dev/null +++ b/.github/workflows/refactor-e2e.yml @@ -0,0 +1,136 @@ +name: e2e-test(refactor) +on: + workflow_call: + inputs: + ref: + description: git reference (commit, branch, or tag) to build and test + required: false + type: string + default: '' + tags: + description: Vitest tag expression, for example runtime || canary + required: false + type: string + default: '' + linuxOnly: + description: Run E2E tests only on Linux + required: false + type: boolean + default: false + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: + required: true + workflow_dispatch: + inputs: + ref: + description: git reference (commit, branch, or tag) to build and test + type: string + default: refactor + tags: + description: Vitest tag expression, for example runtime || canary + type: string + default: '' + linuxOnly: + description: Run E2E tests only on Linux + type: boolean + default: false + +concurrency: + group: + e2e-test-${{ inputs.ref || 'refactor' }}-${{ inputs.tags || 'all' }}-${{ inputs.linuxOnly && 'linux-only' || + 'all-os' }} + cancel-in-progress: false + +env: + AGENTCORE_TELEMETRY_DISABLED: '1' + +jobs: + authorize: + runs-on: ubuntu-latest + permissions: + id-token: write + contents: read + outputs: + is-authorized: ${{ github.workflow == 'canary(refactor)' || steps.check.outputs.is_authorized == 'true' }} + steps: + - name: Fetch secrets from Secrets Manager + uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 + with: + role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} + repo: AUTHORIZED_USERS + - name: Check authorization + id: authz + uses: aws/agentcore-devx-devtools/.github/actions/check-authorized-user@31aa3b031a86664e29861d68956e44b07cf21a74 + with: + subject: ${{ github.actor }} + authorized-users: ${{ env.AUTHORIZED_USERS }} + - name: Determine authorization + id: check + env: + IS_AUTHORIZED: ${{ steps.authz.outputs.is-authorized }} + ACTOR: ${{ github.actor }} + run: | + if [[ "$IS_AUTHORIZED" == "true" ]]; then + echo "Actor ${ACTOR} is authorized" + echo "is_authorized=true" >> "$GITHUB_OUTPUT" + else + echo "Actor ${ACTOR} is not in AUTHORIZED_USERS, skipping" + echo "is_authorized=false" >> "$GITHUB_OUTPUT" + fi + + e2e: + name: test (${{ matrix.name }}) + needs: authorize + if: needs.authorize.outputs.is-authorized == 'true' + runs-on: >- + ${{ fromJSON( + matrix.name == 'Linux' && + format('["codebuild-agentcore-e2e-{0}-{1}","e2e-linux"]', github.run_id, github.run_attempt) + || matrix.name == 'Windows' && + format('["codebuild-agentcore-e2e-{0}-{1}","image:windows-1.0","e2e-windows"]', github.run_id, + github.run_attempt) + || matrix.name == 'macOS' && '["macos-latest"]' + ) }} + permissions: + id-token: write + contents: read + strategy: + fail-fast: false + matrix: + name: ${{ fromJSON(inputs.linuxOnly && '["Linux"]' || '["Linux","Windows","macOS"]') }} + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ inputs.ref || 'refactor' }} + persist-credentials: false + - uses: oven-sh/setup-bun@v2 + - uses: actions/setup-node@v4 + with: + node-version: '24' + - uses: astral-sh/setup-uv@v6 + - run: bun install --frozen-lockfile + - name: Fetch E2E role from Secrets Manager + uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 + with: + role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} + repo: E2E_AWS_ROLE_ARN + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v6 + with: + role-to-assume: ${{ env.E2E_AWS_ROLE_ARN }} + aws-region: ${{ vars.E2E_REGION || 'us-east-1' }} + unset-current-credentials: true + - name: Build CLI + run: bun run build + - name: Run all E2E tests + if: inputs.tags == '' + env: + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/dist/index.js + AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} + run: bun run test:e2e + - name: Run tagged E2E tests + if: inputs.tags != '' + env: + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/dist/index.js + AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} + run: bun run test:e2e -- --tagsFilter="${{ inputs.tags }}" From bad542caf0cb1e33c79ec12b38731055023ec86e Mon Sep 17 00:00:00 2001 From: Hweinstock Date: Mon, 5 Oct 2026 13:29:37 +0000 Subject: [PATCH 2/4] ci: add canary(refactor) scheduled workflow --- .github/workflows/canary-refactor.yml | 50 +++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 .github/workflows/canary-refactor.yml diff --git a/.github/workflows/canary-refactor.yml b/.github/workflows/canary-refactor.yml new file mode 100644 index 0000000000..0edd7b9906 --- /dev/null +++ b/.github/workflows/canary-refactor.yml @@ -0,0 +1,50 @@ +name: canary(refactor) +on: + schedule: + - cron: '*/20 * * * *' + workflow_dispatch: + +concurrency: + group: canary-refactor + cancel-in-progress: false + +permissions: + id-token: write + contents: read + +jobs: + # Resolve the commit hash for the latest published @rc version. + resolve_release: + runs-on: ubuntu-latest + outputs: + ref: ${{ steps.resolve.outputs.ref }} + steps: + - uses: actions/setup-node@v4 + with: + node-version: '24' + - name: Resolve latest RC release commit + id: resolve + run: | + version="$(npm view @aws/agentcore@rc version)" + tag_ref="refs/tags/v${version}" + # Resolve annotated tags to their commit hash when needed. + ref="$(git ls-remote https://github.com/aws/agentcore-cli.git "${tag_ref}" "${tag_ref}^{}" | awk -v tag_ref="${tag_ref}" ' + $2 == tag_ref "^{}" { print $1; found = 1; exit } + $2 == tag_ref { tag_sha = $1 } + END { if (!found && tag_sha != "") print tag_sha } + ')" + if [[ -z "${ref}" ]]; then + echo "::error::No upstream tag found for @aws/agentcore@rc version ${version}" + exit 1 + fi + echo "ref=${ref}" >> "$GITHUB_OUTPUT" + + e2e: + needs: resolve_release + uses: ./.github/workflows/refactor-e2e.yml + with: + ref: ${{ needs.resolve_release.outputs.ref }} + tags: canary + linuxOnly: true + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} From c5d2794db8bfc66578423fefc2016b32718000e4 Mon Sep 17 00:00:00 2001 From: Hweinstock Date: Mon, 5 Oct 2026 13:29:44 +0000 Subject: [PATCH 3/4] ci: emit metrics for canary(refactor) --- .github/workflows/workflow-metrics.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 .github/workflows/workflow-metrics.yml diff --git a/.github/workflows/workflow-metrics.yml b/.github/workflows/workflow-metrics.yml new file mode 100644 index 0000000000..19b1e257f4 --- /dev/null +++ b/.github/workflows/workflow-metrics.yml @@ -0,0 +1,18 @@ +name: Workflow Metrics +on: + workflow_run: + workflows: ['canary(refactor)'] + types: [completed] + +permissions: + id-token: write + +jobs: + metrics: + uses: aws/agentcore-devx-devtools/.github/workflows/workflow-metrics.yml@d145deb62f1adc8be63fa4879a488499e1128a46 + with: + namespace: AgentCoreCLI/Workflows + os: Linux + role-secret-name: E2E_AWS_ROLE_ARN + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} From d6f07690fa658efc26a44dea81d5c4fdb3fb359d Mon Sep 17 00:00:00 2001 From: Hweinstock Date: Mon, 5 Oct 2026 15:05:53 +0000 Subject: [PATCH 4/4] ci: test rc artifact with latest refactor E2E tests --- .github/workflows/canary-refactor.yml | 3 ++- .github/workflows/refactor-e2e.yml | 35 ++++++++++++++++++++------- 2 files changed, 28 insertions(+), 10 deletions(-) diff --git a/.github/workflows/canary-refactor.yml b/.github/workflows/canary-refactor.yml index 0edd7b9906..45fab14d0e 100644 --- a/.github/workflows/canary-refactor.yml +++ b/.github/workflows/canary-refactor.yml @@ -43,7 +43,8 @@ jobs: needs: resolve_release uses: ./.github/workflows/refactor-e2e.yml with: - ref: ${{ needs.resolve_release.outputs.ref }} + artifactRef: ${{ needs.resolve_release.outputs.ref }} + testRef: refactor tags: canary linuxOnly: true secrets: diff --git a/.github/workflows/refactor-e2e.yml b/.github/workflows/refactor-e2e.yml index 94d56ba1d6..e5fd40148d 100644 --- a/.github/workflows/refactor-e2e.yml +++ b/.github/workflows/refactor-e2e.yml @@ -2,8 +2,13 @@ name: e2e-test(refactor) on: workflow_call: inputs: - ref: - description: git reference (commit, branch, or tag) to build and test + artifactRef: + description: git reference (commit, branch, or tag) to build the CLI from + required: false + type: string + default: '' + testRef: + description: git reference (commit, branch, or tag) to run E2E tests from, defaults to artifactRef required: false type: string default: '' @@ -22,10 +27,14 @@ on: required: true workflow_dispatch: inputs: - ref: - description: git reference (commit, branch, or tag) to build and test + artifactRef: + description: git reference (commit, branch, or tag) to build the CLI from type: string default: refactor + testRef: + description: git reference (commit, branch, or tag) to run E2E tests from, defaults to artifactRef + type: string + default: '' tags: description: Vitest tag expression, for example runtime || canary type: string @@ -37,8 +46,8 @@ on: concurrency: group: - e2e-test-${{ inputs.ref || 'refactor' }}-${{ inputs.tags || 'all' }}-${{ inputs.linuxOnly && 'linux-only' || - 'all-os' }} + e2e-test-${{ inputs.artifactRef || 'refactor' }}-${{ inputs.testRef || inputs.artifactRef || 'refactor' }}-${{ + inputs.tags || 'all' }}-${{ inputs.linuxOnly && 'linux-only' || 'all-os' }} cancel-in-progress: false env: @@ -101,7 +110,12 @@ jobs: steps: - uses: actions/checkout@v7 with: - ref: ${{ inputs.ref || 'refactor' }} + ref: ${{ inputs.testRef || inputs.artifactRef || 'refactor' }} + persist-credentials: false + - uses: actions/checkout@v7 + with: + ref: ${{ inputs.artifactRef || 'refactor' }} + path: artifact persist-credentials: false - uses: oven-sh/setup-bun@v2 - uses: actions/setup-node@v4 @@ -109,6 +123,8 @@ jobs: node-version: '24' - uses: astral-sh/setup-uv@v6 - run: bun install --frozen-lockfile + - run: bun install --frozen-lockfile + working-directory: artifact - name: Fetch E2E role from Secrets Manager uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 with: @@ -121,16 +137,17 @@ jobs: aws-region: ${{ vars.E2E_REGION || 'us-east-1' }} unset-current-credentials: true - name: Build CLI + working-directory: artifact run: bun run build - name: Run all E2E tests if: inputs.tags == '' env: - AGENTCORE_CLI_PATH: node ${{ github.workspace }}/dist/index.js + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/artifact/dist/index.js AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} run: bun run test:e2e - name: Run tagged E2E tests if: inputs.tags != '' env: - AGENTCORE_CLI_PATH: node ${{ github.workspace }}/dist/index.js + AGENTCORE_CLI_PATH: node ${{ github.workspace }}/artifact/dist/index.js AWS_REGION: ${{ vars.E2E_REGION || 'us-east-1' }} run: bun run test:e2e -- --tagsFilter="${{ inputs.tags }}"