Skip to content

ci: bug-bash workflow — record CLI TUI to S3 on every PR - #2131

Closed
jariy17 wants to merge 2 commits into
aws:refactorfrom
jariy17:feat/bug-bash-workflow
Closed

ci: bug-bash workflow — record CLI TUI to S3 on every PR#2131
jariy17 wants to merge 2 commits into
aws:refactorfrom
jariy17:feat/bug-bash-workflow

Conversation

@jariy17

@jariy17 jariy17 commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What

Adds a Bug Bash GitHub Actions workflow that runs the AgentCore CLI bug-bash on every PR, records the CLI TUI via private-tui-harness, and uploads the MP4 to S3.

Files

  • .github/workflows/bug-bash.yml — caller workflow (pull_request on main/refactor + workflow_dispatch)
  • .github/harness/bug-bash/record.mjs — TUI recorder driver

How it's wired (Moab reusable-workflow convention)

  • fetch-secrets (pinned to devtools SHA) assumes the repo reader role via OIDC → reads E2E_AWS_ROLE_ARN + BUGBASH_RECORDING_BUCKET from the central DevX Secrets Manager (631957124172).
  • Assumes the shared E2E role (685197708687, us-east-1) — same account as the harness reviewers.
  • Recording lands in s3://agentcore-bugbash-recordings-685197708687-us-east-1/bug-bash/<repo>/pr-<n>/; the run Summary prints an S3-console deep link.

Safety

  • Credentialed job is gated to same-repo PRs (if: on head repo) — fork PRs are skipped, so this draft from a fork will not run the job.

AWS setup (already done)

Bucket, BUGBASH_RECORDING_BUCKET secret, and reader-role grant are provisioned; reader + E2E roles already trust the pull_request OIDC subject.

Draft until reviewed.

Adds .github/workflows/bug-bash.yml + .github/harness/bug-bash/record.mjs.
Runs on pull_request (same-repo) + workflow_dispatch: builds the CLI, records
the TUI via private-tui-harness, uploads the MP4 to S3 keyed by repo/pr-number.
Assumes the shared E2E role via the devx-devtools fetch-secrets action, per the
Moab reusable-workflow convention.
@github-actions github-actions Bot added the size/m PR size: M label Aug 27, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

A few things need attention before this can land safely.

1. Unpinned clone of a personal GitHub repo executed with AWS credentials — .github/workflows/bug-bash.yml lines 83–86

git clone --depth 1 https://github.com/jariy17/private-tui-harness.git "$RUNNER_TEMP/tui-harness"
(cd "$RUNNER_TEMP/tui-harness" && npm ci && npm run build)

This clones the default branch of a personal user repo (jariy17/private-tui-harness) on every run, then runs npm ci (executes install scripts) and node dist/index.js after the E2E AWS role has been assumed. Whoever controls that personal account can push code that exfiltrates the shared E2E_AWS_ROLE_ARN credentials or writes anywhere the role can reach. The header comment in the workflow specifically calls out pinning the composite action to a full SHA "per the guide" — the same rule needs to apply here.

Options:

  • Move private-tui-harness under the aws/ org and pin the checkout to a full commit SHA.
  • Publish it as a private npm package fetched via CodeArtifact / a scoped token, and pin the version.
  • At the very least, pin to a full commit SHA (git -C … checkout <sha>) and add SHA verification, but org-owned is strongly preferred given this runs with production-adjacent AWS creds.

2. Bun is used but the repo has no bun.lockb.github/workflows/bug-bash.yml lines 78–80

- uses: oven-sh/setup-bun@v2
- run: bun install --frozen-lockfile
- run: bun run build

The repo ships package-lock.json and every other workflow uses npm ci / npm run build. bun install --frozen-lockfile requires a bun.lockb and will fail on main today. Please either switch this job to npm ci / npm run build for consistency with the rest of the workflows, or commit a bun lockfile and justify introducing a second package manager to CI.

3. Runner label appears not to be provisioned — .github/workflows/bug-bash.yml line 43

runs-on: codebuild-agentcore-e2e-${{ github.run_id }}-${{ github.run_attempt }}

No other workflow in this repo (or in agentcore-l3-cdk-constructs) targets a codebuild-agentcore-… self-hosted runner — the existing E2E workflows all use ubuntu-latest. If this CodeBuild runner project hasn't actually been created, every run will queue forever. Please confirm the runner is provisioned, or switch to ubuntu-latest to match the existing E2E jobs.

4. Authorization on same-repo PRs — .github/workflows/bug-bash.yml lines 40–42

The gate only excludes forks. Compare with e2e-tests.yml, which additionally checks AUTHORIZED_USERS before assuming the E2E role. Because this workflow runs pull_request (not pull_request_target) it executes PR-head code (including a modifiable record.mjs and BUGBASH_* env vars) with the shared runtime role. That's the same trust model as E2E, so it should carry the same authorize gate — otherwise any collaborator with push access can drive arbitrary behavior under those credentials.

Minor (please address if easy)

  • record.mjs defaults BUGBASH_CMD=bun and BUGBASH_ARGS='run src/index.ts', which runs source rather than the artifact you just built with bun run build. Consider defaulting to the built CLI so the recording reflects what users actually get.
  • No telemetry hook is added, but this is CI-only tooling so that's fine.

Once #1#3 are resolved (and #4 acknowledged one way or the other) this should be good to go.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@codecov-commenter

codecov-commenter commented Aug 27, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.24%. Comparing base (acfbd73) to head (6d0c1dc).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2131   +/-   ##
=========================================
  Coverage     97.24%   97.24%           
=========================================
  Files           465      465           
  Lines         28417    28417           
=========================================
  Hits          27635    27635           
  Misses          782      782           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Aug 27, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026
@jariy17 jariy17 closed this Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants