name: Build Lambda Layer # Build verification only. Terraform owns Lambda packaging: terraform/artifacts.tf # runs terraform/build_packages.sh during plan and carries the resulting zips into # the plan as content_base64, so there is no artifact for this workflow to upload # and no job here holds AWS credentials. # # What it does check is that the layer still builds for the Lambda target # (python3.12 / arm64) and stays small enough to travel inside a plan. boto3 and # friends are stripped by build_packages.sh because the runtime provides them; if # that strip ever stops working, the size guard below fails the PR rather than # letting a multi-hundred-megabyte plan payload reach HCP Terraform. on: pull_request: branches: [main] paths: - "src/shared/**" - "functions/**" - "terraform/build_packages.sh" - "terraform/build_packages_external.sh" - ".github/workflows/build-layer.yml" push: branches: [main] paths: - "src/shared/**" - "functions/**" - "terraform/build_packages.sh" - "terraform/build_packages_external.sh" - ".github/workflows/build-layer.yml" workflow_dispatch: permissions: contents: read concurrency: group: build-layer-${{ github.ref }} cancel-in-progress: false jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0 with: python-version: "3.12" - name: Build packages run: bash terraform/build_packages.sh - name: Check layer size run: | set -euo pipefail cd terraform/build/layer zip -qrX ../packages/layer-check.zip python BYTES=$(wc -c < ../packages/layer-check.zip) LIMIT=$((40 * 1024 * 1024)) echo "Layer zip: $BYTES bytes (limit $LIMIT)" if [ "$BYTES" -gt "$LIMIT" ]; then echo "Layer exceeds the plan-payload budget. Check that build_packages.sh still strips the runtime-provided packages." >&2 exit 1 fi if [ -d python/boto3 ]; then echo "boto3 is present in the layer; the runtime already provides it." >&2 exit 1 fi