ci: bug-bash workflow — record CLI TUI to S3 on every PR - #2131
Conversation
Adds .github/workflows/bug-bash.yml + .github/harness/bug-bash/record.mjs. Runs on pull_request (same-repo) + workflow_dispatch: builds the CLI, records the TUI via private-tui-harness, uploads the MP4 to S3 keyed by repo/pr-number. Assumes the shared E2E role via the devx-devtools fetch-secrets action, per the Moab reusable-workflow convention.
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Changes requested
A few things need attention before this can land safely.
1. Unpinned clone of a personal GitHub repo executed with AWS credentials — .github/workflows/bug-bash.yml lines 83–86
git clone --depth 1 https://github.com/jariy17/private-tui-harness.git "$RUNNER_TEMP/tui-harness"
(cd "$RUNNER_TEMP/tui-harness" && npm ci && npm run build)This clones the default branch of a personal user repo (jariy17/private-tui-harness) on every run, then runs npm ci (executes install scripts) and node dist/index.js after the E2E AWS role has been assumed. Whoever controls that personal account can push code that exfiltrates the shared E2E_AWS_ROLE_ARN credentials or writes anywhere the role can reach. The header comment in the workflow specifically calls out pinning the composite action to a full SHA "per the guide" — the same rule needs to apply here.
Options:
- Move
private-tui-harnessunder theaws/org and pin the checkout to a full commit SHA. - Publish it as a private npm package fetched via CodeArtifact / a scoped token, and pin the version.
- At the very least, pin to a full commit SHA (
git -C … checkout <sha>) and add SHA verification, but org-owned is strongly preferred given this runs with production-adjacent AWS creds.
2. Bun is used but the repo has no bun.lockb — .github/workflows/bug-bash.yml lines 78–80
- uses: oven-sh/setup-bun@v2
- run: bun install --frozen-lockfile
- run: bun run buildThe repo ships package-lock.json and every other workflow uses npm ci / npm run build. bun install --frozen-lockfile requires a bun.lockb and will fail on main today. Please either switch this job to npm ci / npm run build for consistency with the rest of the workflows, or commit a bun lockfile and justify introducing a second package manager to CI.
3. Runner label appears not to be provisioned — .github/workflows/bug-bash.yml line 43
runs-on: codebuild-agentcore-e2e-${{ github.run_id }}-${{ github.run_attempt }}No other workflow in this repo (or in agentcore-l3-cdk-constructs) targets a codebuild-agentcore-… self-hosted runner — the existing E2E workflows all use ubuntu-latest. If this CodeBuild runner project hasn't actually been created, every run will queue forever. Please confirm the runner is provisioned, or switch to ubuntu-latest to match the existing E2E jobs.
4. Authorization on same-repo PRs — .github/workflows/bug-bash.yml lines 40–42
The gate only excludes forks. Compare with e2e-tests.yml, which additionally checks AUTHORIZED_USERS before assuming the E2E role. Because this workflow runs pull_request (not pull_request_target) it executes PR-head code (including a modifiable record.mjs and BUGBASH_* env vars) with the shared runtime role. That's the same trust model as E2E, so it should carry the same authorize gate — otherwise any collaborator with push access can drive arbitrary behavior under those credentials.
Minor (please address if easy)
record.mjsdefaultsBUGBASH_CMD=bunandBUGBASH_ARGS='run src/index.ts', which runs source rather than the artifact you just built withbun run build. Consider defaulting to the built CLI so the recording reflects what users actually get.- No telemetry hook is added, but this is CI-only tooling so that's fine.
Once #1–#3 are resolved (and #4 acknowledged one way or the other) this should be good to go.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## refactor #2131 +/- ##
=========================================
Coverage 97.24% 97.24%
=========================================
Files 465 465
Lines 28417 28417
=========================================
Hits 27635 27635
Misses 782 782 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Claude Security Review: no high-confidence findings. (run) |
|
Claude Security Review: no high-confidence findings. (run) |
What
Adds a
Bug BashGitHub Actions workflow that runs the AgentCore CLI bug-bash on every PR, records the CLI TUI via private-tui-harness, and uploads the MP4 to S3.Files
.github/workflows/bug-bash.yml— caller workflow (pull_requeston main/refactor +workflow_dispatch).github/harness/bug-bash/record.mjs— TUI recorder driverHow it's wired (Moab reusable-workflow convention)
fetch-secrets(pinned to devtools SHA) assumes the repo reader role via OIDC → readsE2E_AWS_ROLE_ARN+BUGBASH_RECORDING_BUCKETfrom the central DevX Secrets Manager (631957124172).685197708687, us-east-1) — same account as the harness reviewers.s3://agentcore-bugbash-recordings-685197708687-us-east-1/bug-bash/<repo>/pr-<n>/; the run Summary prints an S3-console deep link.Safety
if:on head repo) — fork PRs are skipped, so this draft from a fork will not run the job.AWS setup (already done)
Bucket,
BUGBASH_RECORDING_BUCKETsecret, and reader-role grant are provisioned; reader + E2E roles already trust thepull_requestOIDC subject.Draft until reviewed.