Conversation
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
This PR adds a single throwaway workflow file (.github/workflows/diag-codebuild-container.yml) whose purpose is purely diagnostic — probing container dev behaviour on the CodeBuild runner for #2413. Both the PR title and the first line of the workflow say "TEMPORARY diagnostic — do not merge", so the "do not merge" gate is on the author.
Things I checked and are fine:
- Trigger is scoped to
pull_requeston therefactorbranch only, so it won't run againstmain. permissions: contents: readandpersist-credentials: falseon checkout — minimal blast radius.- The AWS env values (
AKIADIAGNOSTICONLY/diagnostic-only) are obvious placeholder strings, not real credentials. actions/checkout@v7is a real release (v7.0.1).AGENTCORE_TELEMETRY_DISABLED: "1"is set for the CLI invocation, which is right for a diagnostic run.
No changes required from a review standpoint. Just make sure to delete the workflow (and not merge this PR to main) once the diagnostic data has been collected.
|
Claude Security Review: no high-confidence findings. (run) |
|
Claude Security Review: no high-confidence findings. (run) |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## refactor #2415 +/- ##
=========================================
Coverage 97.25% 97.25%
=========================================
Files 612 612
Lines 41019 41019
=========================================
Hits 39893 39893
Misses 1126 1126 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Diagnostic complete. Confirmed the Linux e2e failure was CodeBuild running privilegedMode=false (no docker daemon); tkashina flipped privilegedMode=true (+ standard:8.0 / LARGE) on 2026-09-25. This probe showed docker healthy only because it ran ~2.5 min after that flip. Closing; no code to merge. |
Temporary diagnostic for the always-failing e2e case
'py_strands_container' runs locallyon the CodeBuild Linux runner (see #2413). Runs a throwaway workflow on thee2e-linuxCodeBuild runner to check Docker output streaming, host port publishing, and whether the strands container template starts. No secrets; fake AWS keys only. Will be closed and the branch deleted once the results are read.