Skip to content

diag: probe container dev on CodeBuild runner (do not merge) - #2415

Closed
notgitika wants to merge 2 commits into
refactorfrom
diag/codebuild-container-dev
Closed

notgitika wants to merge 2 commits into
refactorfrom
diag/codebuild-container-dev

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Temporary diagnostic for the always-failing e2e case 'py_strands_container' runs locally on the CodeBuild Linux runner (see #2413). Runs a throwaway workflow on the e2e-linux CodeBuild runner to check Docker output streaming, host port publishing, and whether the strands container template starts. No secrets; fake AWS keys only. Will be closed and the branch deleted once the results are read.

@github-actions github-actions Bot added the size/s PR size: S label Sep 25, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Sep 25, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

This PR adds a single throwaway workflow file (.github/workflows/diag-codebuild-container.yml) whose purpose is purely diagnostic — probing container dev behaviour on the CodeBuild runner for #2413. Both the PR title and the first line of the workflow say "TEMPORARY diagnostic — do not merge", so the "do not merge" gate is on the author.

Things I checked and are fine:

  • Trigger is scoped to pull_request on the refactor branch only, so it won't run against main.
  • permissions: contents: read and persist-credentials: false on checkout — minimal blast radius.
  • The AWS env values (AKIADIAGNOSTICONLY / diagnostic-only) are obvious placeholder strings, not real credentials.
  • actions/checkout@v7 is a real release (v7.0.1).
  • AGENTCORE_TELEMETRY_DISABLED: "1" is set for the CLI invocation, which is right for a diagnostic run.

No changes required from a review standpoint. Just make sure to delete the workflow (and not merge this PR to main) once the diagnostic data has been collected.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Sep 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 25, 2026
@github-actions github-actions Bot added size/s PR size: S and removed size/s PR size: S labels Sep 25, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 25, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.25%. Comparing base (86d7c81) to head (e0e9f18).
⚠️ Report is 1 commits behind head on refactor.

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2415   +/-   ##
=========================================
  Coverage     97.25%   97.25%           
=========================================
  Files           612      612           
  Lines         41019    41019           
=========================================
  Hits          39893    39893           
  Misses         1126     1126           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
Contributor Author

Diagnostic complete. Confirmed the Linux e2e failure was CodeBuild running privilegedMode=false (no docker daemon); tkashina flipped privilegedMode=true (+ standard:8.0 / LARGE) on 2026-09-25. This probe showed docker healthy only because it ran ~2.5 min after that flip. Closing; no code to merge.

@notgitika notgitika closed this Sep 25, 2026
@notgitika
notgitika deleted the diag/codebuild-container-dev branch September 25, 2026 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/s PR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants