Repository navigation
ci: enable Claude PR reviews on this repo - #113
Merged
crowecawcaw merged 1 commit intoOct 8, 2026
Merged
Conversation
Add the same two thin callers deadline-cloud uses: a no-op collect workflow on pull_request, and the review workflow on workflow_run, both calling this repo's reusable workflows at @mainline. Signed-off-by: Stephen Crowe <6042774+crowecawcaw@users.noreply.github.com>
crowecawcaw
marked this pull request as ready for review
October 7, 2026 23:08
larrygao001
approved these changes
Oct 7, 2026
larrygao001
left a comment
There was a problem hiding this comment.
Before merging, a repo admin needs to add the AWS_CLAUDE_PR_REVIEW_ROLE repository secret
Will you follow up on this and confirm it works as it was not tested end to end?
andychoquette
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was the problem/requirement? (What/Why)
This repo hosts the Claude PR-review workflows, but its own PRs aren't reviewed by them. Changes to the review tooling are exactly the ones where an extra reviewer helps.
What was the solution? (How)
Add the same two thin callers
aws-deadline/deadline-clouduses, copied unchanged except for header comments:claude_pr_review_collect.yml: a no-op stage onpull_request(permissions: {}) whose completion firesworkflow_run.claude_pr_review.yml: the review stage onworkflow_run. It forwards the trusted head repo and head SHA from the event payload, plus theAWS_CLAUDE_PR_REVIEW_ROLEsecret.Both call this repo's reusable workflows by
@mainline, like every other caller.workflow_runalso runs from the default branch. So a PR that changes the review workflow is reviewed by the version already on mainline, never by its own copy.What is the impact of this change?
PRs to this repo get Claude reviews.
Before merging, a repo admin needs to add the
AWS_CLAUDE_PR_REVIEW_ROLErepository secret (the same role ARN deadline-cloud uses). Without it, every review run fails at the credentials step. The role's OIDC trust is documented asrepo:aws-deadline/*:*withjob_workflow_refpinned to this repo's reusable workflow, which already covers this repo; it's worth confirming.How was this change tested?
dangerous-triggersignore is the same as deadline-cloud's). actionlint: clean.Was this change documented?
In the workflow header comments.
Is this a breaking change?
No.
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.