Repository navigation
Conversation
Every pull request builds the image and renders a synthetic MPEG-TS clip inside it as Lambda would run it: unprivileged, root-owned empty /tmp, the CPU and memory of the 1024 MB tier. Merging to main then runs `sam build && sam deploy` under the production environment, assuming the spectrogram-renderer-deploy role through GitHub's OIDC provider, so a deploy is a merge rather than a laptop. SAM's hello-world tests and event go; the sample event now names a real segment and writes nothing. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repo is
server/audio_vizfrom orcasite, split out with its history (orcasound/orcasite#1064 and #1065 are the last two commits). Until now the function was deployed by whoever ransam deployon their laptop, which is how production briefly ran unmerged code today.What this adds
tests/smoke.pyrenders a synthetic AAC/MPEG-TS clip inside the built image, run as an unprivileged user with a root-owned empty/tmpand the CPU and memory of the 1024 MB tier. It fails if the first render is slow enough to mean the caches were not restored. The--user/--tmpfsflags are the ones whose absence let #1065's bug through.mainfollows it withsam build && sam deployunder theproductionenvironment, assumingspectrogram-renderer-deploythrough the account's existing GitHub OIDC provider. That role's policy covers only theaudio-vizand SAM-managed stacks, the function's ECR repository, the function, and roles namedaudio-viz-*.Actions are pinned to the SHA of their latest release. The first merge to
mainwill redeploy the code that is already live, which is the pipeline's own test.Not in this PR: the contract change (presigned URLs and explicit render parameters, so the function knows nothing about S3) and deleting
server/audio_vizfrom orcasite.🤖 Generated with Claude Code