Skip to content

Commit d8005d2

Browse files
committed
ci: run LMI tests on PRs and main
Run the complete cloud matrix on every trusted PR update, including drafts, and every main push without labels or path filters. Preserve existing cloud credential restrictions for forks and Dependabot. Use run-owned resources without a cross-run concurrency group so newer commits cannot replace another commit's pending cloud job.
1 parent f93a3c8 commit d8005d2

2 files changed

Lines changed: 25 additions & 20 deletions

File tree

‎.github/workflows/lmi-e2e-tests.yml‎

Lines changed: 6 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ on:
44
push:
55
branches: [main]
66
pull_request:
7-
types: [opened, synchronize, reopened, labeled]
7+
types: [opened, synchronize, reopened]
88
workflow_dispatch:
99
inputs:
1010
region:
@@ -44,13 +44,12 @@ jobs:
4444

4545
cloud:
4646
needs: harness
47-
# Start with manual runs and explicit trusted PR opt-in; no scheduled cloud job.
47+
# Run on every main push and trusted PR update, including drafts.
48+
# Match the repository's cloud credential restrictions for forks/Dependabot.
4849
if: >-
49-
github.event_name == 'workflow_dispatch' ||
50-
(github.event_name == 'pull_request' &&
51-
github.actor != 'dependabot[bot]' &&
52-
github.event.pull_request.head.repo.full_name == github.repository &&
53-
contains(github.event.pull_request.labels.*.name, 'run-lmi-e2e'))
50+
github.event_name != 'pull_request' ||
51+
(github.actor != 'dependabot[bot]' &&
52+
github.event.pull_request.head.repo.full_name == github.repository)
5453
runs-on: ubuntu-latest
5554
timeout-minutes: 55
5655
permissions:
@@ -62,9 +61,6 @@ jobs:
6261
matrix:
6362
python: ['3.13', '3.14']
6463
concurrency: [1, 2]
65-
concurrency:
66-
group: python-lmi-e2e-${{ matrix.python }}-${{ matrix.concurrency }}
67-
cancel-in-progress: false
6864
env:
6965
AWS_REGION: ${{ inputs.region || 'us-west-2' }}
7066
CAPACITY_PROVIDER_ARN: ${{ secrets.CAPACITY_PROVIDER_ARN }}

‎lmi_tests/README.md‎

Lines changed: 19 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -7,9 +7,10 @@ It follows the separate cloud-suite approach in
77
[Java PR #728](https://github.com/aws/aws-durable-execution-sdk-java/pull/728).
88
It changes no production SDK code. The deadline and early-completion regressions
99
are **expected to fail on the current SDK**. They are ordinary failing assertions,
10-
with no `xfail`, swallowed failure, or expected-failure success status. Cloud tests
11-
and local red regressions require explicit opt-in; the ordinary test suite remains
12-
usable while the fix is designed.
10+
with no `xfail`, swallowed failure, or expected-failure success status. CI runs the
11+
cloud suite automatically on every trusted PR update and main push. Local cloud
12+
runs and local red regressions require explicit commands; the ordinary local test
13+
suite remains usable while the fix is designed.
1314

1415
## Run locally
1516

@@ -156,13 +157,21 @@ An unexecuted scenario is never summarized as passing.
156157

157158
## CI and resource ownership
158159

159-
The dedicated workflow runs the green harness checks on PRs and main pushes.
160-
Cloud tests initially run on `workflow_dispatch` or same-repository PRs labeled
161-
`run-lmi-e2e`, excluding Dependabot and forks. It reuses `TEST_ROLE_ARN`,
162-
`TEST_ACCOUNT_ID`, and `TEST_LAMBDA_EXECUTION_ROLE_ARN` with OIDC. Cloud checks are
163-
intentionally not required green until #741 is implemented and cloud placement /
164-
timing has been validated. Scheduled and larger stress runs can be added after
165-
this suite is stable.
160+
The dedicated workflow runs the harness and full LMI cloud matrix automatically
161+
when a same-repository PR is opened, updated, or reopened (including Draft PRs),
162+
and on every push to `main`, including merged changes. There are no path filters,
163+
label requirements, or ready-for-review requirements. `workflow_dispatch` remains
164+
available for manual reruns; there are no scheduled jobs.
165+
166+
Each workflow run has its own resources and runs its four matrix entries
167+
sequentially. Runs do not share a GitHub concurrency group, so a new PR update or
168+
main push cannot replace another commit's pending cloud job.
169+
170+
Privileged cloud jobs retain the repository's existing restrictions for forked PRs
171+
and Dependabot; the harness still runs for those PRs. Cloud jobs reuse
172+
`TEST_ROLE_ARN`, `TEST_ACCOUNT_ID`, and `TEST_LAMBDA_EXECUTION_ROLE_ARN` with OIDC.
173+
The #741 regression assertions remain visibly failing until its fix lands; they
174+
are not skipped or converted into expected-success results to keep CI green.
166175

167176
The workflow collects evidence before teardown, even after test failure or ordinary
168177
cancellation. Cleanup sends external releases, stops running durable executions,

0 commit comments

Comments
 (0)