meal-order-manager/.github/workflows/build-layer.yml
dependabot[bot] 145b0cbac6
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
chore(deps): bump actions/setup-python from 6.0.0 to 7.0.0 (#132)
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...5fda3b95a4ea91299a34e894583c3862153e4b97)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 17:23:37 +00:00

68 lines
2.3 KiB
YAML

name: Build Lambda Layer
# Build verification only. Terraform owns Lambda packaging: terraform/artifacts.tf
# runs terraform/build_packages.sh during plan and carries the resulting zips into
# the plan as content_base64, so there is no artifact for this workflow to upload
# and no job here holds AWS credentials.
#
# What it does check is that the layer still builds for the Lambda target
# (python3.12 / arm64) and stays small enough to travel inside a plan. boto3 and
# friends are stripped by build_packages.sh because the runtime provides them; if
# that strip ever stops working, the size guard below fails the PR rather than
# letting a multi-hundred-megabyte plan payload reach HCP Terraform.
on:
pull_request:
branches: [main]
paths:
- "src/shared/**"
- "functions/**"
- "terraform/build_packages.sh"
- "terraform/build_packages_external.sh"
- ".github/workflows/build-layer.yml"
push:
branches: [main]
paths:
- "src/shared/**"
- "functions/**"
- "terraform/build_packages.sh"
- "terraform/build_packages_external.sh"
- ".github/workflows/build-layer.yml"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: build-layer-${{ github.ref }}
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Build packages
run: bash terraform/build_packages.sh
- name: Check layer size
run: |
set -euo pipefail
cd terraform/build/layer
zip -qrX ../packages/layer-check.zip python
BYTES=$(wc -c < ../packages/layer-check.zip)
LIMIT=$((40 * 1024 * 1024))
echo "Layer zip: $BYTES bytes (limit $LIMIT)"
if [ "$BYTES" -gt "$LIMIT" ]; then
echo "Layer exceeds the plan-payload budget. Check that build_packages.sh still strips the runtime-provided packages." >&2
exit 1
fi
if [ -d python/boto3 ]; then
echo "boto3 is present in the layer; the runtime already provides it." >&2
exit 1
fi