ci: add concurrency to ci-python-app + fix sam-deploy template (INFRA-136) (#74)
Some checks failed
ci / ci / ci (push) Has been cancelled

Add job-level concurrency (cancel-in-progress) to all four ci-python-app
jobs, matching the ci-python-sam idiom. Per-job group keys include
github.job so the parallel jobs in a single run do not share a group.

Replace sam-deploy starter-template stack-name: $default-branch (which
GitHub substitutes to the literal branch name main) with a
REPLACE-ME-stack-name placeholder, and point cfn-role-arn at the real
shared github-cfn-execution-role.
This commit is contained in:
Adam Moussa 2026-07-08 16:32:40 -04:00 • committed by GitHub
parent fc75158c94
commit 9fa0a71564
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 16 additions and 2 deletions

View file

@ -50,6 +50,9 @@ jobs:
lint: lint:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 10
concurrency:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }}
cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
@ -96,6 +99,9 @@ jobs:
if: ${{ inputs.collect-only }} if: ${{ inputs.collect-only }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 10
concurrency:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }}
cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
@ -117,6 +123,9 @@ jobs:
if: ${{ inputs.subproject-dir != '' }} if: ${{ inputs.subproject-dir != '' }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 10
concurrency:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }}
cancel-in-progress: true
steps: steps:
- uses: actions/checkout@v7 - uses: actions/checkout@v7
@ -140,6 +149,9 @@ jobs:
needs: [lint, test-collect, subproject-tests] needs: [lint, test-collect, subproject-tests]
if: always() if: always()
runs-on: ubuntu-latest runs-on: ubuntu-latest
concurrency:
group: ci-python-app-${{ github.workflow }}-${{ github.ref }}-${{ inputs.source-dirs }}-${{ github.job }}
cancel-in-progress: true
steps: steps:
- name: Require all jobs to have succeeded - name: Require all jobs to have succeeded
run: | run: |

View file

@ -8,8 +8,10 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@main
with: with:
# Required: the CloudFormation stack name (kebab-case, matches repo name). # Required: the CloudFormation stack name (kebab-case, matches repo name).
stack-name: $default-branch # NOTE: this is a literal placeholder on purpose — starter-workflow variables
# like $default-branch substitute to the BRANCH name ("main"), not the repo name.
stack-name: REPLACE-ME-stack-name
# Required: the CloudFormation execution role ARN for this stack. # Required: the CloudFormation execution role ARN for this stack.
cfn-role-arn: arn:aws:iam::328440206208:role/REPLACE-ME-cfn-exec-role cfn-role-arn: arn:aws:iam::328440206208:role/github-cfn-execution-role
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}