Repository navigation
fix(tests): stabilize shared CI fixtures and timing - #3235
Erik Osterman (Cloud Posse) (osterman) wants to merge 9 commits into
Conversation
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
|
CodeRabbit (@coderabbitai) review |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
Note Repository guideline files applied to this review (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cloudposse/atmos/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (14)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe changes update tests for authentication, toolchain releases, YAML includes, command output, scheduler timing, planfile generation, and Terraform source command state. They add local and loopback fixtures, reset shared test state, adjust output assertions and timeout values, and extend CI workflow egress allowlists. ChangesAuthentication test execution
Toolchain test fixtures
YAML include test fixtures
Command output capture
Scheduler test timeouts
Terraform source command state
Terraform planfile test fixtures
CI workflow egress
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The changes improve test determinism and allow required CI downloads without changing production behavior. No actionable merge-blocking issue is established; merge after normal checks pass. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to CI jobs gain access to additional download hosts, including jobs with cloud credentials. Existing blocking policies, action pins, and permission boundaries remain. No introduced exploit or authority escalation was established, but download verification and effective cloud-role restrictions were not fully verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 56.10% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 41 functions across 14 files. (12 skipped: 12 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3235 +/- ##
==========================================
- Coverage 84.56% 84.51% -0.05%
==========================================
Files 2095 2095
Lines 205082 205082
==========================================
- Hits 173429 173327 -102
- Misses 23406 23517 +111
+ Partials 8247 8238 -9
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
CI timing summaryLatest completed GitHub Actions runs for
Wall-clock time spans the earliest included workflow creation through the latest completion. Aggregate runner time adds each job's execution time, so concurrent jobs are counted separately.
Longest jobs (top 10)
Updated automatically when a PR workflow finishes. |
|
CodeRabbit (@coderabbitai) full review |
✅ Action performedFull review finished. |
24f2051 to
2c7984a
Compare
|
CodeRabbit (@coderabbitai) review |
|
|
CodeRabbit (@coderabbitai) review |
|
|
Important Cloud Posse Engineering Team Review RequiredThis pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes. To expedite this process, reach out to us on Slack in the |
|
Warning SHA Pin Verification Passed — with documented exceptionsAll 236 third-party action reference(s) are covered, but 2 rely on a documented allowlist entry in
See the action run for full details. |
|
CodeRabbit (@coderabbitai) review |
|
Resource Changes Found for
|
|
CodeRabbit (@coderabbitai) review |
✅ Action performedReview finished.
|
what
Stabilize shared test failures exposed by the CloudFormation stack without changing production behavior.
terraform@latestinstallation and YAML tool metadata with fixed local releases.why
Live GitHub requests exhausted shared API quotas, auth logging setup raced parallel command logging, raw terminal captures retained cleared frames, and a loaded Windows runner exceeded the scheduler test's one-second startup allowance. The suite also leaked Cobra dry-run flags across invocations and blocked while writing large debug logs to an unread pipe. Concurrent Windows test binaries also locked the same shared Terraform state file. These tests now isolate command state and fixtures, drain output while commands run, and distinguish scheduling delays from behavior failures. CI shard counts and suite-wide parallelism stay the same.
Go setup also failed on cold runners when installation API quotas were exhausted: hardened jobs blocked the fallback metadata and download hosts. The allowlists now include those required hosts, with network blocking still enabled. A recursive audit covers all 24 Go setup jobs, including local composite-action callers. Shard counts and parallelism remain unchanged.
Validation passed:
latestinstallation and three shuffled race runs of the YAML toolchain-info snapshot.This PR changes only tests, fixtures, and the CI network allowlist; production Go patch coverage is not applicable.
references
Summary by CodeRabbit