From f38b21dde4a101d3b90afcadce510f862ce68072 Mon Sep 17 00:00:00 2001 From: andychoquette <78888816+andychoquette@users.noreply.github.com> Date: Wed, 23 Sep 2026 12:17:34 -0700 Subject: [PATCH] fix: let the integ credentials outlive the CodeBuild build they poll aws-codebuild-run-build polls the CodeBuild build using the credentials from configure-aws-credentials, so the session has to outlive the build rather than just start it. Neither credential step set role-duration-seconds, so both got the 1 hour default. Integ builds already exceed that. deadline-cloud-for-3ds-max release 0.4.2 failed twice this way: the GitHub job died at 1h01m and again at 1h00m with ##[error]The security token included in the request is expired while the CodeBuild build it was polling, deadline-cloud-for-3ds-max-mainline-windows-integ started 2026-09-23 09:32 PDT, SUCCEEDED at 11:06 -- 94 minutes. The tests passed; only the poller's credentials ran out, and the release was blocked on a green job it could never get. Mainline builds for that project run ~48 min, so the margin was only ~12 minutes even before anything grew. Builds against refs/tags/* take roughly twice as long as the equivalent mainline build (48 min vs 94 min on the same day, same code), so the release path is the one that goes over. 10800s is chosen because every *_IntegOIDCRole in the CI account already allows it, so no IAM change is needed. Verified by RoleId that the 3ds Max job assumes deadline_cloud_for_3ds_max_dev_IntegOIDCRole, MaxSessionDuration 10800; the other nine integ roles match. configure-aws-credentials fails fast when role-duration-seconds exceeds a role's MaxSessionDuration, so a future caller whose role allows less would break immediately and visibly rather than silently. Signed-off-by: andychoquette <78888816+andychoquette@users.noreply.github.com> --- .github/workflows/reusable_integration_test.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/reusable_integration_test.yml b/.github/workflows/reusable_integration_test.yml index ee8b141..b7f6fc5 100644 --- a/.github/workflows/reusable_integration_test.yml +++ b/.github/workflows/reusable_integration_test.yml @@ -34,6 +34,13 @@ jobs: id-token: write contents: read steps: + # aws-codebuild-run-build polls the build with these credentials, so the session has to + # outlive the build, not just start it. The default is 1 hour and integ builds already run + # ~48 min on mainline and ~94 min against a tag, so the poller was dying mid-build with + # "The security token included in the request is expired" and failing the job while the + # build itself went on to succeed. Every *_IntegOIDCRole allows 10800s, so this needs no + # IAM change -- but configure-aws-credentials fails fast if a role's MaxSessionDuration is + # lower, so any new caller's role must allow it too. - name: Configure AWS credentials for release if: ${{inputs.environment == 'release'}} uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1 @@ -41,6 +48,7 @@ jobs: role-to-assume: ${{ secrets.AWS_CODEBUILD_RELEASE_INTEG_ROLE }} aws-region: us-west-2 mask-aws-account-id: true + role-duration-seconds: 10800 - name: Configure AWS credentials for mainline if: ${{inputs.environment == 'mainline'}} @@ -49,6 +57,7 @@ jobs: role-to-assume: ${{ secrets.AWS_CODEBUILD_MAINLINE_INTEG_ROLE }} aws-region: us-west-2 mask-aws-account-id: true + role-duration-seconds: 10800 - name: Run Integration Tests uses: aws-actions/aws-codebuild-run-build@7e46c3fa1c1f217e26a73712796b1f78938b534b # v1.0.18