Conversation
Move lint-commits and the build matrix from ubuntu-latest to the codebuild-github-actions-runner label (CodeBuild Lambda compute in the Python testing account). The Amazon Linux runner image has no matching actions/setup-python builds, so uv provides each matrix interpreter and an activated venv; Hatch is installed with uv pip.
wangyb-A
force-pushed
the
ci/codebuild-runner
branch
from
September 30, 2026 00:07
905a5a5 to
565f641
Compare
Move cloud-tests, conformance-tests and test-parser onto the CodeBuild-hosted runner, mirroring ci.yml: setup-uv (v10.2.0) for the interpreter, uv pip install, and PIP_CONFIG_FILE/PYTHONPATH isolation. Fork-gated jobs use the plain label; test-parser uses the fork-aware runs-on expression.
added 5 commits
September 30, 2026 03:38
The CodeBuild runner image has no gh CLI, so the SAM deploy step's gh api call to resolve the latest ADOT Python layer failed with 'gh: command not found'. Replace it with curl to the GitHub REST API plus python3 to extract the release body; the awk region parse is unchanged.
The two cloud-test X-Ray span-visibility assertions failed intermittently on the runner (traces present but the durable-execution marker span not yet indexed within the ~50s window). The same tests pass on the same runner when ingestion is fast, so widen the retry budget (3x10s -> 6x15s) to absorb slower eventual-consistency instead of failing the run.
Widening the X-Ray retry budget did not resolve the two span-visibility failures (spans still not indexed after ~110s), confirming the failure is environmental X-Ray/ADOT ingestion rather than runner-caused. Revert to keep the migration change minimal.
The CodeBuild Lambda-compute runner sets AWS_LAMBDA_FUNCTION_NAME and _X_AMZN_TRACE_ID. botocore's recursion-detection handler (add_recursion_detection_header) then attaches the runner's X-Amzn-Trace-Id to every Lambda invoke, so the example functions join the runner's unsampled trace and the two X-Ray span tests cannot find their marker spans. The same tests pass on ubuntu-latest, where neither variable is set. Removing the variable in the examples conftest restores independent traces.
The CodeBuild EC2 runner executes jobs as root, so FileSystemSerDes could create /nonexistent/readonly/path and the serialization error test did not raise. Use a regular file as the parent directory, which fails for every user.
This comment has been minimized.
This comment has been minimized.
- ci.yml: lint-commits and build now route fork PRs (and Dependabot for build) to ubuntu-latest, matching test-parser and the if: gates on cloud-tests/conformance; the plain CodeBuild label let fork code run inside the testing account. - test-parser.yml: include the workflow itself in both path filters so a change to it (such as this runner migration) triggers a run; it had not executed on this branch.
wangyb-A
had a problem deploying
to
ai-pr-review-runtime
October 2, 2026 18:27 — with
GitHub Actions
Error
The first test-parser run on the runner failed in test_build_layer_excludes_adot_and_runtime_dependencies: build_lambda_layer.py runs `python -m pip install`, and the venv uv creates has no pip (setup-python's venv did). Install pip with the test dependencies.
Contributor
Codex AI reviewNo actionable findings. Residual risk is limited to external CodeBuild project and runner-image configuration not represented in the diff. Reviewed commit |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves this repo's own CI workflows onto the CodeBuild-hosted GitHub Actions runner in the Python testing account (project
github-actions-runner). The label iscodebuild-github-actions-runner-${{ github.run_id }}-${{ github.run_attempt }}, so each job gets its own ephemeral runner. The project currently runs on-demand EC2 compute (aws/codebuild/standard:7.0,BUILD_GENERAL1_MEDIUM, 60-minute timeout); the workflows here were validated on both the earlier Lambda compute and the current EC2 configuration.Scope
This PR only touches workflows that are specific to this repository. Workflows that are thin callers of shared reusable workflows are not changed here, because their
runs-onlives in the dependency repository and moving them requires a change there first:opentelemetry-conformance-tests.ymlaws/aws-durable-execution-conformance-tests(opentelemetry-orchestrator.yml)ai-pr-review.yml,notify.yml,issue-triage.yml,stale-issue-closer.ymlaws/aws-durable-execution-ciThese will be migrated in a follow-up PR once the shared workflows accept a runner label.
Migrated
ci.ymlsetup-uvv10.2.0 +uv pip install hatch, pip isolation envconformance-tests.ymlsetup-uv; runner installed withuv pip installcloud-tests.ymlsetup-uvfor the matrix interpreter,uv pip install hatch==1.16.5test-parser.yml.github/scripts;setup-uv(3.13)All migrated jobs get
PIP_CONFIG_FILE=/dev/nullandPYTHONPATH=""so a runner image's shared/etc/pip.conftarget cannot leak into the build. The Python interpreter comes fromastral-sh/setup-uvSHA-pinned toc18668ad3cf93ea998bef934396af7bb5c839dc7(v10.2.0), which keeps the workflow independent of whichever Python versions the runner image ships.Fork handling
conformance-tests.yml(discover_suites,conformance) andcloud-tests.yml(example-tests) are already gated by anif:that excludes fork PRs and Dependabot (github.event.pull_request.head.repo.full_name == github.repository), so they use the plain CodeBuild label.ci.yml(lint-commits,build) andtest-parser.yml(test-scripts) have no such gate and are reachable frompull_request, so they use a fork-awareruns-onexpression that keeps fork PRs (and, forbuild, Dependabot PRs) onubuntu-latest:Note that for
pull_requestevents the workflow definition comes from the PR head, so these expressions andif:gates prevent accidental routing but are not a trust boundary on their own: a PR can edit them. The boundary is the repository's "Approval for running fork pull request workflows" setting (a maintainer approves each fork run after seeing the diff) together with the CodeBuild project's webhook configuration.Left on GitHub-hosted runners on purpose
scorecard.ymlpypi-publish.ymllambda-layer-publish.ymlecr-release.ymldocker build/docker manifest+ QEMU, to be revisited separatelyVerification
ci.yml(build 3.11-3.14 + lint-commits): green on the runner.conformance-tests.yml: green on the runner;discover_suitesplus all 12 suite jobs pass (~1-3.5 min each).cloud-tests.yml: SAM builds natively, deploys, and the example tests run on every Python version (3.11-3.14).test-parser.yml: its path filters did not include the workflow file itself, so it had not run on this branch; the filters now include it and the run on the latest head is the first execution on the runner.The first three are green on both Lambda and EC2 compute.
Runner-caused fixes (test configuration and scripts only, no SDK code)
cloud-tests.ymlresolved the latest ADOT layer viagh apiin the SAM deploy step. The Lambda-compute runner image had noghCLI, so the step failed immediately. Replaced thegh apicall withcurlto the GitHub REST API pluspython3to extract the release body; theawkregion-parsing is unchanged.test/conftest.pyin the examples package removes_X_AMZN_TRACE_IDfrom the test process. On Lambda compute the runner itself is a Lambda and sets bothAWS_LAMBDA_FUNCTION_NAMEand_X_AMZN_TRACE_ID; botocore's recursion-detection handler then attaches the runner'sX-Amzn-Trace-Idto every Lambda invoke, the example functions joined the runner's unsampled trace, and the X-Ray span assertions (test_otel_logger_example_spans_in_xray,test_plugin_spans_in_xray_across_invocations) could not find their marker spans. Dropping the variable restores independent traces for the invoked functions.tests/filesystem_serdes_test.py::test_serialization_error_handlingrelied on/nonexistent/readonly/pathbeing unwritable. EC2 compute runs jobs as root, which simply created the path, so the expectedSerDesErrorwas never raised. The test now uses a regular file as the parent directory, which fails for every user.