mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 12:43:16 +00:00
* chore: decommission self-hosted AWS LangGraph stack Removes the now-dead self-host IaC and AWS-only CI/CD after destroying the dev + prod CloudFormation stacks (open-swe-dev, open-swe-prod, open-swe-iam, and the dev-exclusive CDKToolkit-oswedev bootstrap) in account 328440206208, us-east-1. The deployment is now managed (LangGraph Cloud + Vercel). - remove infra/ (CDK app: app + IAM stacks, constructs, aspects, tests) - remove deploy/ami (Packer AMI build) and deploy/seahaven (boot/config scripts, DEPLOYMENT/ROTATION runbooks) - remove AWS-only workflows: cd-infra, ci-infra, build-artifacts, rollback - README: rewrite the Deployment section to the managed LangGraph Cloud + Vercel view; drop dead links to infra/ and deploy/seahaven Preserved: the shared default CDKToolkit bootstrap and promote-dev-to-prod.yml. The RETAIN'd Secrets Manager shells and open-swe-<env>-assets S3 buckets survive cdk destroy by design (orphaned) and need a separate deliberate cleanup. * chore: clean up dangling references left by the AWS decommission Folds in the FIX-level items from the #64 review gates (GPT-4.1 cross-review + /sh-security-review), none of which were blockers: - delete orphaned .github/scripts/{package-artifacts,publish-and-deploy,roll-box, rollback}.sh — their only callers were the removed AWS deploy workflows - drop the deleted /infra dir from dependabot.yml npm directories (was producing a recurring Dependabot config error) - remove the stale OSWE-IAC-SECRETS-LIST-01 suppression (referenced the deleted infra/lib/constructs/instance-role.ts) - repoint the README promotion link to promote-to-main.yml (renamed in #63) The promote-dev-to-prod.yml comment in check-dev-green.sh is intentionally left to #63, which rewrites that same line.
89 lines
2.7 KiB
YAML
89 lines
2.7 KiB
YAML
name: CI
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
# dev as well as main so every dev HEAD carries the full CI signal that
|
|
# the dev->main promotion gate (check-dev-green.sh) reads. PR checks alone are
|
|
# not enough: an admin-merge can land a red PR onto dev.
|
|
branches: ["main", "dev"]
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
lint:
|
|
name: Lint
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run lint
|
|
run: make lint
|
|
|
|
format:
|
|
name: Format check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run format check
|
|
run: make format-check
|
|
|
|
unit-tests:
|
|
name: Unit tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run unit tests
|
|
run: make test
|
|
|
|
e2e:
|
|
name: Playwright E2E
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
- uses: oven-sh/setup-bun@v2
|
|
- name: Install Python deps (langgraph dev runtime)
|
|
run: uv sync --locked
|
|
- name: Install Playwright + Chromium
|
|
working-directory: tests/e2e
|
|
run: |
|
|
npm ci
|
|
npx playwright install --with-deps chromium
|
|
# Playwright's webServer boots `langgraph dev`; globalSetup builds the real
|
|
# ui/ SPA. The fake LLM/GitHub/Slack boundaries need no secrets.
|
|
- name: Run E2E
|
|
working-directory: tests/e2e
|
|
# Playwright's globalSetup runs the real `bun run build`, whose vite bundle
|
|
# exceeds Node's default ~2 GB heap.
|
|
# The runner has ~16 GB, so lift the heap cap.
|
|
env:
|
|
NODE_OPTIONS: "--max-old-space-size=8192"
|
|
run: npx playwright test
|
|
- name: Upload Playwright report
|
|
if: ${{ !cancelled() }}
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: playwright-report
|
|
path: |
|
|
tests/e2e/playwright-report
|
|
tests/e2e/test-results
|
|
retention-days: 7
|