Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
78 changes: 78 additions & 0 deletions .github/workflows/workflow-metrics.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
name: Workflow Metrics

on:
workflow_call:
inputs:
namespace:
description: CloudWatch metric namespace
required: true
type: string
os:
description: Operating system dimension for the completed workflow run
required: true
type: string
role-secret-name:
description: Repository secret name containing the CloudWatch writer role ARN
required: true
type: string
aws-region:
description: AWS region for CloudWatch
required: false
type: string
default: us-east-1
secrets:
WORKFLOW_SECRETS_READER_ROLE_ARN:
required: true

permissions:
id-token: write

jobs:
emit-metric:
runs-on: codebuild-agentcore-e2e-${{ github.run_id }}-${{ github.run_attempt }}
timeout-minutes: 5
steps:
- name: Fetch CloudWatch writer role from Secrets Manager
uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2
with:
role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }}
repo: ${{ inputs['role-secret-name'] }}
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ env[inputs['role-secret-name']] }}
aws-region: ${{ inputs['aws-region'] }}
unset-current-credentials: true
- name: Emit workflow run duration
env:
METRIC_NAMESPACE: ${{ inputs.namespace }}
OS: ${{ inputs.os }}
WORKFLOW_NAME: ${{ github.event.workflow_run.name }}
RESULT: ${{ github.event.workflow_run.conclusion }}
RUN_STARTED_AT: ${{ github.event.workflow_run.run_started_at }}
RUN_COMPLETED_AT: ${{ github.event.workflow_run.updated_at }}
run: |
duration_seconds=0
if [[ -n "$RUN_STARTED_AT" ]]; then
duration_seconds=$(( $(date -d "$RUN_COMPLETED_AT" +%s) - $(date -d "$RUN_STARTED_AT" +%s) ))
fi
metric_data=$(jq -nc \
--arg workflow "$WORKFLOW_NAME" \
--arg result "${RESULT:-Unknown}" \
--arg os "$OS" \
--arg timestamp "$RUN_COMPLETED_AT" \
--argjson duration "$duration_seconds" \
'[{
MetricName: "WorkflowRunDuration",
Dimensions: [
{Name: "WorkflowName", Value: $workflow},
{Name: "Result", Value: $result},
{Name: "OS", Value: $os}
],
Timestamp: $timestamp,
Unit: "Seconds",
Value: $duration
}]')
aws cloudwatch put-metric-data \
--namespace "$METRIC_NAMESPACE" \
--metric-data "$metric_data"
25 changes: 25 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,31 @@ The `.github/workflows/` directory contains reusable workflows. Each is invoked
`reusable-pr-ai-review.yml` centralizes AgentCore Harness review mechanics while
callers retain their event triggers and repository-specific prompts.

`workflow-metrics.yml` emits `WorkflowRunDuration` for a completed
`workflow_run`. Callers provide the namespace, OS, and writer-role secret name,
grant `id-token: write`, and pass `WORKFLOW_SECRETS_READER_ROLE_ARN`. Pin the
workflow to a full commit SHA. The writer role needs `cloudwatch:PutMetricData`.

```yaml
on:
workflow_run:
workflows: [canary]
types: [completed]

permissions:
id-token: write

jobs:
metrics:
uses: aws/agentcore-devx-devtools/.github/workflows/workflow-metrics.yml@<ref>
with:
namespace: AgentCoreCLI/Workflows
os: Linux
role-secret-name: E2E_AWS_ROLE_ARN
secrets:
WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }}
```

## Security

See [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.
Expand Down