mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 16:13:15 +00:00
* fix(infra): grant instance role BatchGetSecretValue + ListSecrets for .env materialization fetch-config.sh materializes the box's .env via `secretsmanager batch-get-secret-value --filters Key=name,Values=open-swe-<env>/`, but the instance role only granted GetSecretValue/DescribeSecret. BatchGetSecretValue is a distinct IAM action, so the call was AccessDenied and open-swe.service crash-looped (no .env written -> ExecStartPre exit 1). - Add secretsmanager:BatchGetSecretValue to the prefix-scoped ReadSecrets statement. - Add secretsmanager:ListSecrets on * (required by the name-prefix filtered batch call; the API has no resource-level scoping for the list action — fits the role's stated exception). Secret VALUES stay prefix-scoped; only names are enumerable. Reviews: GPT-4.1 IAM cross-review BLOCK=none; /sh-security-review iac-iam one LOW metadata residual (no critical/high), recorded as OSWE-IAC-SECRETS-LIST-01. Refs T7/T19 dev bring-up. * ci: lift Node heap cap for Playwright E2E build (vite OOM) The E2E job's Playwright globalSetup runs the real `bun run build`, whose vite bundle exceeds Node's default ~2 GB heap and OOMs (JavaScript heap out of memory) — the same failure fixed for build-artifacts.yml in #19. Set NODE_OPTIONS=--max-old-space-size=8192 on the Run E2E step.
86 lines
2.5 KiB
YAML
86 lines
2.5 KiB
YAML
name: Agent CI
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches: ["main"]
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
lint:
|
|
name: Agent lint
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run lint
|
|
run: make lint
|
|
|
|
format:
|
|
name: Agent format check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run format check
|
|
run: make format-check
|
|
|
|
unit-tests:
|
|
name: Agent unit tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
|
|
- name: Install dependencies
|
|
run: uv sync --locked --extra dev
|
|
- name: Run unit tests
|
|
run: make test
|
|
|
|
e2e:
|
|
name: Playwright E2E
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
- uses: oven-sh/setup-bun@v2
|
|
- name: Install Python deps (langgraph dev runtime)
|
|
run: uv sync --locked
|
|
- name: Install Playwright + Chromium
|
|
working-directory: tests/e2e
|
|
run: |
|
|
npm ci
|
|
npx playwright install --with-deps chromium
|
|
# Playwright's webServer boots `langgraph dev`; globalSetup builds the real
|
|
# ui/ SPA. The fake LLM/GitHub/Slack boundaries need no secrets.
|
|
- name: Run E2E
|
|
working-directory: tests/e2e
|
|
# Playwright's globalSetup runs the real `bun run build`, whose vite bundle
|
|
# exceeds Node's default ~2 GB heap (same OOM fixed in build-artifacts.yml).
|
|
# The runner has ~16 GB, so lift the heap cap.
|
|
env:
|
|
NODE_OPTIONS: "--max-old-space-size=8192"
|
|
run: npx playwright test
|
|
- name: Upload Playwright report
|
|
if: ${{ !cancelled() }}
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: playwright-report
|
|
path: |
|
|
tests/e2e/playwright-report
|
|
tests/e2e/test-results
|
|
retention-days: 7
|