Skip to content

ci: run shared workflows on the CodeBuild runner - #759

Draft
wangyb-A wants to merge 1 commit into
mainfrom
ci/codebuild-runner-shared-shells
Draft

wangyb-A wants to merge 1 commit into
mainfrom
ci/codebuild-runner-shared-shells

Conversation

@wangyb-A

@wangyb-A wangyb-A commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Goal: run the shared-workflow jobs this repository calls (AI PR review, Slack notify, issue triage, stale-issue closer, OpenTelemetry conformance) on the CodeBuild-hosted runner in the Python testing account instead of the shared ubuntu-latest pool.

This completes the runner migration started in #747, which deliberately left these thin shells alone because their runs-on lives in the reusable workflows they call. Those now accept a runner input:

What changed

Shell Pin Runner
ai-pr-review.yml, issue-triage.yml, notify.yml d6b017da → d901b2f1 codebuild-github-actions-runner-${{ github.run_id }}-${{ github.run_attempt }}
stale-issue-closer.yml 48b3b434 → d901b2f1 same
opentelemetry-conformance-tests.yml a628f558 → 3542852f same, via runs_on

Every shell passes the label unconditionally. All of them run from main's workflow definition (pull_request_target, issues, release, schedule) or are already gated to same-repository PRs (opentelemetry-conformance-tests), and the AI review checks out the pull request's base revision and reads the diff as data, so no fork-authored code executes on the runner.

The pin bumps carry the intervening upstream commits: 12 on aws-durable-execution-ci (the runs-on input, the model-user scripts no longer assuming a runner account, the model environment passed as an explicit env -i allowlist, one stale-issue-closer fix, dependabot bumps) and 8 on aws-durable-execution-conformance-tests.

Draft

The CI-repo pin points at the head of aws/aws-durable-execution-ci#67's branch. When #67 merges (squash), one follow-up commit replaces it with the merge SHA; nothing else changes. Do not merge while the pin is a branch commit.

Verification

  • Every with: key each shell passes was checked against the callee's workflow_call inputs at the new pin; all resolve.
  • opentelemetry-conformance-tests is pull_request-triggered and the orchestrator change is on main, so this PR's own OTel run exercises the CodeBuild path end to end.
  • The other shells run from main's definition, so this PR cannot exercise them; the first event after merge is the live test. The reusable Codex review was run end to end on the CodeBuild runner from the Update Model to use chained invoke over invoke #67 branch in aws-durable-execution-sdk-js run 37542509461, and the model-user scripts were exercised as root in run 37539805626.
  • OTel job durations on recent PR runs are 3–8 minutes, under the project's 60-minute job limit.

no linked issue: follow-up to #747.

Bump the aws-durable-execution-ci and conformance-tests orchestrator pins to the commits that accept a runner input, and pass the CodeBuild runner label from every thin shell.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant