Skip to content

ci: Reduce shared Actions pool usage with concurrency cancellation and draft-skip - #488

Open
kavmur wants to merge 1 commit into
aws-deadline:mainlinefrom
kavmur:ci/github-actions-hygiene
Open

kavmur wants to merge 1 commit into
aws-deadline:mainlinefrom
kavmur:ci/github-actions-hygiene

Conversation

@kavmur

@kavmur kavmur commented Oct 9, 2026

Copy link
Copy Markdown

What was the problem/requirement? (What/Why)

PR-triggered CI workflows had no concurrency block, so superseded runs on a branch kept running and new pushes queued extra jobs on the shared enterprise ubuntu-latest pool. With agent-driven development pushing frequently per PR, this wastes runner capacity on a pool that degrades silently under load.

What was the solution? (How)

Applied the org admins' recommended GitHub Actions hygiene practices to the PR CI workflows (code_quality.yml, codeql.yml, security_scan.yml, record_pr.yml, auto_approve.yml), purely additive:

  • Concurrency cancellation with a conditional group key: pull_request events share a per-ref group so a new push supersedes the in-progress run; all other events (push/release/workflow_call) get a unique github.run_id suffix so they never cancel each other's pending runs.
  • Draft-skip on the heavy matrix build so draft PRs don't consume the pool (via ready_for_review trigger + if: github.event.pull_request.draft != true). Not applied to codeql/security_scan so those keep reporting.
  • Explicit fail-fast on the code_quality matrix.

What is the impact of this change?

Lower consumption of the shared Actions runner pool, especially on draft PRs and rapid push bursts. No change to what the jobs do. Verified: not a required status check — mainline only requires Semantic PR and DCO, so skipping these jobs on drafts cannot stall the merge queue.

How was this change tested?

Statically validated — every edited workflow parses cleanly with yaml.safe_load and the concurrency/if guards were confirmed structurally. Runtime behavior (cancel-on-push, draft-skip) manifests only on GitHub's runners; recommend opening as a draft first to confirm the heavy jobs skip, then marking ready.

Integ test result

N/A — CI configuration only; no src/ changes.

Installer test result

N/A — no installer/ or src/ changes.

Did you run the "Job Bundle Output Tests"? If not, why not? If so, paste the test results here.

N/A — change is limited to .github/workflows/; no submitter or adaptor code touched.

Was this change documented?

No doc changes needed — workflow-config only.

Did you modify schema files?

  • Yes
  • No

Is this a breaking change?

No. Draft-skip (Yes — code_quality.yml's matrix build skips draft PRs and sets explicit fail-fast.) Additive workflow metadata only; no public contract or adaptor interface changed.

@kavmur
kavmur requested a review from a team as a code owner October 9, 2026 22:11
@github-actions github-actions Bot added the waiting-on-maintainers Waiting on the maintainers to review. label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Claude review · advisory

Reviewed 1578dda (changes since 00f6eae): 0 new, 0 resolved.

Open: 0 blocking · 0 should-fix · 0 nit. ✅ Nothing blocking.

Fix or reply to each thread; the next revision's review re-checks open threads and resolves those it agrees are handled. Resolving a thread yourself also closes it. Later revisions review only what changed.

…d draft-skip

Amazon's ubuntu-latest runners draw on a single enterprise-wide shared
concurrency pool. Apply the org-recommended CI hygiene practices to the
PR-triggered workflows, matching the fix landed on aws-deadline/deadline-cloud.

- Add a P2-correct concurrency block to code_quality, security_scan, codeql,
  record_pr, and auto_approve. The group key uses a conditional suffix so
  PR events share a per-ref group (supersede-cancel works) while non-PR
  events (push/schedule/workflow_call) get a unique run_id and are never
  cancelled by a shared pending run.
- Draft-skip the heavy code_quality Test matrix via a ready_for_review
  trigger type plus an if-guard. workflow_call has no PR context, so the
  job still runs for release/manual-release callers.
- Set explicit fail-fast: true on the code_quality matrix.
- Leave codeql and security_scan without draft-skip since they are
  required status checks.

Purely additive; no existing logic removed.

Signed-off-by: kavmur <kavmur@users.noreply.github.com>
@kavmur
kavmur force-pushed the ci/github-actions-hygiene branch from 00f6eae to 1578dda Compare October 9, 2026 22:16
@jairaws

jairaws commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Some Code Quality workflows are failing. Could you take a look?

@kavmur

kavmur commented Oct 9, 2026

Copy link
Copy Markdown
Author

Some Code Quality workflows are failing. Could you take a look?

Looks like a mypy failure

src/deadline/maya_submitter/mel_commands.py:75: error: Incompatible types in
assignment (expression has type "SubmitJobToDeadlineDialog | None", variable has
type "None")  [assignment]
    ...              DeadlineCloudSubmitterCmd.dialog = show_maya_render_subm...
                                                        ^~~~~~~~~~~~~~~~~~~~~...

unrelated to this PR. Likely caused by new mypy 2.4.0 update

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

waiting-on-maintainers Waiting on the maintainers to review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants