Skip to content

ci(deploy): stop the weekly AWS deploy run - #30

Open
NWarila wants to merge 1 commit into
mainfrom
ci/stop-weekly-deploy
Open

NWarila wants to merge 1 commit into
mainfrom
ci/stop-weekly-deploy

Conversation

@NWarila

@NWarila NWarila commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

What

  • .github/workflows/aws-deploy.yml drops its schedule trigger (Mondays 09:17 UTC). The workflow now runs on pushes to protected main that match its path filter, and on manual dispatch.
  • The header bullet states those two triggers, in the Golden Repo's words.

Why

The Golden Repo stopped its weekly run on 2026-09-30 (nwarila-platform/pdq-deploy-inventory#94). Eleven fleet repositories still carried the identical cron (corrected from "nine": secure-wazuh and aws-workspace-builder were missed by a local-checkout grep). GitHub fires them hours late (17:40–18:33 UTC rather than 09:17) and all at once: about 72 vCPU of stacks against the account's 32-vCPU limit. On 2026-10-05, every Linux stack's scheduled run failed at RunInstances with VcpuLimitExceeded. Here, all six scheduled runs since 2026-08-31 failed.

aws-reaper.yml keeps its own quarter-hour schedule, so cleanup does not depend on this workflow's triggers.

Proof

  • The candidate equals main's file with exactly the two header lines replaced and the three schedule lines deleted (2 added, 5 removed); nothing else in the workflow changes.
  • The parsed on: keys are push and workflow_dispatch.
  • zizmor (offline) reports no findings, before or after. actionlint and yamllint run in this PR's Quality check.
  • No tracked file still mentions the weekly run or its cron expression.

Merge order

Merging this triggers a deploy (the workflow is in its own path filter), so merge the CIS image bump #29 first: a deploy on the v07 pin fails at Terraform apply. Merge the fleet's deploy-triggering PRs one at a time; the stacks share the 32-vCPU limit.

The Golden Repo dropped this schedule on 2026-09-30
(pdq-deploy-inventory#94). Nine fleet repositories still carried its
identical Monday 09:17 UTC cron, which GitHub fires hours late and all
at once: about 56 vCPU of stacks against the account's 32-vCPU limit.
On 2026-10-05 every Linux stack's scheduled run died at RunInstances
with VcpuLimitExceeded. Here, all six scheduled runs since 2026-08-31
failed.

The workflow now runs on pushes to protected main that match its path
filter, and on manual dispatch; the header states those two triggers in
the Golden Repo's words. aws-reaper.yml keeps its own quarter-hour
schedule, so cleanup does not depend on this workflow's triggers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant