From 71447a20a779a3151c86908f4b6b2f46be7bcf2f Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 8 Jul 2026 16:28:32 -0400 Subject: [PATCH] ci: add concurrency to ci-python-app + fix sam-deploy template (INFRA-136) Add job-level concurrency (cancel-in-progress) to all four ci-python-app jobs, matching the ci-python-sam idiom. Per-job group keys include github.job so the parallel jobs in a single run do not share a group. Replace sam-deploy starter-template stack-name: $default-branch (which GitHub substitutes to the literal branch name main) with a REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real shared github-cfn-execution-role. --- .github/workflows/ci-python-app.yaml | 12 ++++++++++++ workflow-templates/sam-deploy.yml | 6 ++++-- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci-python-app.yaml b/.github/workflows/ci-python-app.yaml index 006a7bc..b829498 100644 --- a/.github/workflows/ci-python-app.yaml +++ b/.github/workflows/ci-python-app.yaml @@ -50,6 +50,9 @@ jobs: lint: runs-on: ubuntu-latest timeout-minutes: 10 + concurrency: + group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }} + cancel-in-progress: true steps: - uses: actions/checkout@v7 @@ -96,6 +99,9 @@ jobs: if: ${{ inputs.collect-only }} runs-on: ubuntu-latest timeout-minutes: 10 + concurrency: + group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }} + cancel-in-progress: true steps: - uses: actions/checkout@v7 @@ -117,6 +123,9 @@ jobs: if: ${{ inputs.subproject-dir != '' }} runs-on: ubuntu-latest timeout-minutes: 10 + concurrency: + group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }} + cancel-in-progress: true steps: - uses: actions/checkout@v7 @@ -140,6 +149,9 @@ jobs: needs: [lint, test-collect, subproject-tests] if: always() runs-on: ubuntu-latest + concurrency: + group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }} + cancel-in-progress: true steps: - name: Require all jobs to have succeeded run: | diff --git a/workflow-templates/sam-deploy.yml b/workflow-templates/sam-deploy.yml index f24cc70..c734753 100644 --- a/workflow-templates/sam-deploy.yml +++ b/workflow-templates/sam-deploy.yml @@ -8,8 +8,10 @@ jobs: uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main with: # Required: the CloudFormation stack name (kebab-case, matches repo name). - stack-name: $default-branch + # NOTE: this is a literal placeholder on purpose — starter-workflow variables + # like $default-branch substitute to the BRANCH name ("main"), not the repo name. + stack-name: REPLACE-ME-stack-name # Required: the CloudFormation execution role ARN for this stack. - cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role + cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}