The group key ci-${{ github.workflow }}-${{ github.ref }} resolves
identically for every job in a caller workflow (github.workflow is the
caller's name in a reusable workflow), so repos calling two reusable CI
workflows from one ci.yaml (e.g. exec-aide python + typescript) had
their jobs cancel each other on every run.
Prefix each group with the reusable workflow's own filename and append
its distinguishing input (source-dirs / working-directory) so sibling
jobs get distinct groups while superseded runs of the same job still
cancel.
Superseded CI runs on the same ref keep consuming runners and delay
feedback on the latest push. Add a job-level concurrency group keyed
on github.workflow and github.ref so a new push cancels the in-flight
CI run for that branch.
Concurrency is set at the job level rather than the workflow level
because these are workflow_call reusable workflows: workflow-level
concurrency would resolve github.workflow against the caller's context,
collapsing unrelated callers into one group. cd-* deploy workflows are
intentionally left untouched to avoid cancelling in-flight deploys.
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.
Ref: engineering-handbook cicd.md (workflow standardization).
The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.
Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
Double backslash in single quotes makes ERE match a literal
backslash instead of a dot. No .gitignore entry could pass
this check. Affects both CDK and SAM CI workflows.
* Add QEMU support to CI CDK workflow for cross-platform Docker builds
Mirrors the enable-qemu input from cd-cdk.yaml. Required when CDK
stacks use PythonFunction or other Docker-bundled constructs targeting
arm64 Lambda on x86 CI runners.
* Increase CI timeout for QEMU CDK builds
* Bump default Node.js version to 24 across all reusable workflows
npm 11 (Node 24) generates lockfileVersion 3 which breaks npm ci
on Node 22's npm 10 for repos with aws-cdk-lib bundled deps.
* Add lightweight conventions check to CI workflows
Validates README exists, .env in .gitignore, arm64 architecture,
and log retention in synthesized templates. Runs by default,
opt-out via run-conventions-check: false.
* Add pre-flight stack status checks to CD workflows
Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE,
FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on
stacks that need manual intervention.
* Add post-deploy health checks to CD workflows
Verifies stack status after deploy, prints outputs, and runs
project-specific scripts/health-check.sh if present.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Enables Python CDK repos (po-ingest, workorder-ingest) to use the
same reusable workflow. Adds run-cdk-synth, cdk-dir, and node-version
inputs. Refactors dependency install to be shared between pytest and
cdk synth paths.
Parameterized workflows that each repo calls via a thin 3-5 line
caller. All lint, test, and validate steps are toggleable so repos
can adopt incrementally. Covers Python SAM, Python CDK, TypeScript
CDK, and Node.js SAM stacks.