diff --git a/.github/workflows/workflow-metrics.yml b/.github/workflows/workflow-metrics.yml new file mode 100644 index 0000000..bcf0e25 --- /dev/null +++ b/.github/workflows/workflow-metrics.yml @@ -0,0 +1,78 @@ +name: Workflow Metrics + +on: + workflow_call: + inputs: + namespace: + description: CloudWatch metric namespace + required: true + type: string + os: + description: Operating system dimension for the completed workflow run + required: true + type: string + role-secret-name: + description: Repository secret name containing the CloudWatch writer role ARN + required: true + type: string + aws-region: + description: AWS region for CloudWatch + required: false + type: string + default: us-east-1 + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: + required: true + +permissions: + id-token: write + +jobs: + emit-metric: + runs-on: codebuild-agentcore-e2e-${{ github.run_id }}-${{ github.run_attempt }} + timeout-minutes: 5 + steps: + - name: Fetch CloudWatch writer role from Secrets Manager + uses: aws/agentcore-devx-devtools/.github/actions/fetch-secrets@75989f65f7f193deaf83c237c36572d1a8f800b2 + with: + role-arn: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} + repo: ${{ inputs['role-secret-name'] }} + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v6 + with: + role-to-assume: ${{ env[inputs['role-secret-name']] }} + aws-region: ${{ inputs['aws-region'] }} + unset-current-credentials: true + - name: Emit workflow run duration + env: + METRIC_NAMESPACE: ${{ inputs.namespace }} + OS: ${{ inputs.os }} + WORKFLOW_NAME: ${{ github.event.workflow_run.name }} + RESULT: ${{ github.event.workflow_run.conclusion }} + RUN_STARTED_AT: ${{ github.event.workflow_run.run_started_at }} + RUN_COMPLETED_AT: ${{ github.event.workflow_run.updated_at }} + run: | + duration_seconds=0 + if [[ -n "$RUN_STARTED_AT" ]]; then + duration_seconds=$(( $(date -d "$RUN_COMPLETED_AT" +%s) - $(date -d "$RUN_STARTED_AT" +%s) )) + fi + metric_data=$(jq -nc \ + --arg workflow "$WORKFLOW_NAME" \ + --arg result "${RESULT:-Unknown}" \ + --arg os "$OS" \ + --arg timestamp "$RUN_COMPLETED_AT" \ + --argjson duration "$duration_seconds" \ + '[{ + MetricName: "WorkflowRunDuration", + Dimensions: [ + {Name: "WorkflowName", Value: $workflow}, + {Name: "Result", Value: $result}, + {Name: "OS", Value: $os} + ], + Timestamp: $timestamp, + Unit: "Seconds", + Value: $duration + }]') + aws cloudwatch put-metric-data \ + --namespace "$METRIC_NAMESPACE" \ + --metric-data "$metric_data" diff --git a/README.md b/README.md index 264dae0..d359b09 100644 --- a/README.md +++ b/README.md @@ -9,6 +9,31 @@ The `.github/workflows/` directory contains reusable workflows. Each is invoked `reusable-pr-ai-review.yml` centralizes AgentCore Harness review mechanics while callers retain their event triggers and repository-specific prompts. +`workflow-metrics.yml` emits `WorkflowRunDuration` for a completed +`workflow_run`. Callers provide the namespace, OS, and writer-role secret name, +grant `id-token: write`, and pass `WORKFLOW_SECRETS_READER_ROLE_ARN`. Pin the +workflow to a full commit SHA. The writer role needs `cloudwatch:PutMetricData`. + +```yaml +on: + workflow_run: + workflows: [canary] + types: [completed] + +permissions: + id-token: write + +jobs: + metrics: + uses: aws/agentcore-devx-devtools/.github/workflows/workflow-metrics.yml@ + with: + namespace: AgentCoreCLI/Workflows + os: Linux + role-secret-name: E2E_AWS_ROLE_ARN + secrets: + WORKFLOW_SECRETS_READER_ROLE_ARN: ${{ secrets.WORKFLOW_SECRETS_READER_ROLE_ARN }} +``` + ## Security See [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.