Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| ## Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. | |
| ## SPDX-License-Identifier: Apache-2.0 | |
| # This is a reusable workflow for running the Enablement test for App Signals. | |
| # It is meant to be called from another workflow. | |
| # Read more about reusable workflows: https://docs.github.com/en/actions/using-workflows/reusing-workflows#overview | |
| # This test case validates ADOT used on its own to send traces to the X-Ray OTLP endpoint with SigV4 authentication | |
| name: Java EC2 ADOT SigV4 (Stand-Alone ADOT) Use Case | |
| on: | |
| push: | |
| branches: | |
| - Java_SigV4_Test | |
| workflow_call: | |
| inputs: | |
| caller-workflow-name: | |
| required: true | |
| type: string | |
| java-version: | |
| description: "Currently support version 8, 11, 17, 21, 22" | |
| required: false | |
| type: string | |
| default: '11' | |
| cpu-architecture: | |
| description: "Permitted values: x86_64 or arm64" | |
| required: false | |
| type: string | |
| default: "x86_64" | |
| outputs: | |
| job-started: | |
| value: ${{ jobs.java-ec2-adot-sigv4.outputs.job-started }} | |
| validation-result: | |
| value: ${{ jobs.java-ec2-adot-sigv4.outputs.validation-result }} | |
| permissions: | |
| id-token: write | |
| contents: read | |
| env: | |
| E2E_TEST_AWS_REGION: 'us-west-2' # Test uses us-west-2 in the us-east-1 accoun | |
| CALLER_WORKFLOW_NAME: ${{ inputs.caller-workflow-name }} | |
| METRIC_NAMESPACE: ApplicationSignals | |
| JAVA_VERSION: ${{ inputs.java-version || '11' }} | |
| CPU_ARCHITECTURE: ${{ inputs.cpu-architecture || 'x86_64' }} | |
| E2E_TEST_ACCOUNT_ID: ${{ secrets.APPLICATION_SIGNALS_E2E_TEST_ACCOUNT_ID }} # us-east-1 test account | |
| E2E_TEST_ROLE_NAME: ${{ secrets.APPLICATION_SIGNALS_E2E_TEST_ROLE_NAME }} | |
| LOG_GROUP_NAME: aws/spans | |
| TEST_RESOURCES_FOLDER: ${GITHUB_WORKSPACE} | |
| jobs: | |
| java-ec2-adot-sigv4: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| job-started: ${{ steps.job-started.outputs.job-started }} | |
| validation-result: ${{ steps.validation-result.outputs.validation-result }} | |
| steps: | |
| - name: Check if the job started | |
| id: job-started | |
| run: echo "job-started=true" >> $GITHUB_OUTPUT | |
| - name: Print all environment variables | |
| run: env | |
| - name: Generate testing id | |
| run: echo TESTING_ID="${{ github.run_id }}-${{ github.run_number }}-${RANDOM}" >> $GITHUB_ENV | |
| - uses: actions/checkout@v4 | |
| with: | |
| repository: 'aws-observability/aws-application-signals-test-framework' | |
| ref: ${{ env.CALLER_WORKFLOW_NAME == 'main-build' && 'main' || github.ref }} | |
| fetch-depth: 0 | |
| # We initialize Gradlew Daemon early on during the workflow because sometimes initialization | |
| # fails due to transient issues. If it fails here, then we will try again later before the validators | |
| - name: Initiate Gradlew Daemon | |
| id: initiate-gradlew | |
| uses: ./.github/workflows/actions/execute_and_retry | |
| continue-on-error: true | |
| with: | |
| command: "./gradlew :validator:build" | |
| cleanup: "./gradlew clean" | |
| max_retry: 3 | |
| sleep_time: 60 | |
| # We use the us-east-1 account, but use us-west-2 for the test | |
| # This is because transaction search is a regional setting, which would affect all other tests if run in the same region | |
| - name: Configure AWS Credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| role-to-assume: arn:aws:iam::${{ env.E2E_TEST_ACCOUNT_ID }}:role/${{ env.E2E_TEST_ROLE_NAME }} | |
| aws-region: ${{ env.E2E_TEST_AWS_REGION }} | |
| - name: Set ADOT getter command environment variable | |
| run: | | |
| # if [ "${{ github.event.repository.name }}" = "aws-otel-java-instrumentation" ]; then | |
| echo GET_ADOT_JAR_COMMAND="aws s3 cp s3://adot-main-build-staging-jar/aws-opentelemetry-agent.jar ./adot.jar" >> $GITHUB_ENV | |
| # else | |
| # echo GET_ADOT_JAR_COMMAND="wget -O adot.jar https://github.com/aws-observability/aws-otel-java-instrumentation/releases/latest/download/aws-opentelemetry-agent.jar" >> $GITHUB_ENV | |
| # fi | |
| - name: Set up terraform | |
| uses: ./.github/workflows/actions/execute_and_retry | |
| with: | |
| command: "wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg" | |
| post-command: 'echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list | |
| && sudo apt update && sudo apt install terraform' | |
| sleep_time: 60 | |
| - name: Initiate Terraform | |
| uses: ./.github/workflows/actions/execute_and_retry | |
| with: | |
| command: "cd ${{ env.TEST_RESOURCES_FOLDER }}/terraform/java/ec2/adot-sigv4 && terraform init && terraform validate" | |
| cleanup: "rm -rf .terraform && rm -rf .terraform.lock.hcl" | |
| max_retry: 6 | |
| sleep_time: 60 | |
| - name: Deploy sample app via terraform and wait for endpoint to come online | |
| working-directory: terraform/java/ec2/adot-sigv4 | |
| run: | | |
| # Attempt to deploy the sample app on an EC2 instance and wait for its endpoint to come online. | |
| # There may be occasional failures due to transitivity issues, so try up to 2 times. | |
| # deployment_failed of 0 indicates that both the terraform deployment and the endpoint are running, while 1 indicates | |
| # that it failed at some point | |
| retry_counter=0 | |
| max_retry=2 | |
| while [ $retry_counter -lt $max_retry ]; do | |
| echo "Attempt $retry_counter" | |
| deployment_failed=0 | |
| terraform apply -auto-approve \ | |
| -var="aws_region=${{ env.E2E_TEST_AWS_REGION }}" \ | |
| -var="test_id=${{ env.TESTING_ID }}" \ | |
| -var="sample_app_jar=s3://aws-appsignals-sample-app-prod-us-east-1/java-main-service-v${{ env.JAVA_VERSION }}.jar" \ | |
| -var="sample_remote_app_jar=s3://aws-appsignals-sample-app-prod-us-east-1/java-remote-service-v${{ env.JAVA_VERSION }}.jar" \ | |
| -var="get_adot_jar_command=${{ env.GET_ADOT_JAR_COMMAND }}" \ | |
| -var="language_version=${{ env.JAVA_VERSION }}" \ | |
| -var="cpu_architecture=${{ env.CPU_ARCHITECTURE }}" \ | |
| || deployment_failed=$? | |
| if [ $deployment_failed -eq 1 ]; then | |
| echo "Terraform deployment was unsuccessful. Will attempt to retry deployment." | |
| fi | |
| # If the success is 1 then either the terraform deployment or the endpoint connection failed, so first destroy the | |
| # resources created from terraform and try again. | |
| if [ $deployment_failed -eq 1 ]; then | |
| echo "Destroying terraform" | |
| terraform destroy -auto-approve \ | |
| -var="test_id=${{ env.TESTING_ID }}" | |
| retry_counter=$(($retry_counter+1)) | |
| else | |
| # If deployment succeeded, then exit the loop | |
| break | |
| fi | |
| if [ $retry_counter -eq $max_retry ]; then | |
| echo "Max retry reached, failed to deploy terraform and connect to the endpoint. Exiting code" | |
| exit 1 | |
| fi | |
| done | |
| - name: Get the ec2 instance ami id | |
| working-directory: terraform/java/ec2/adot-sigv4 | |
| run: | | |
| echo "EC2_INSTANCE_AMI=$(terraform output ec2_instance_ami)" >> $GITHUB_ENV | |
| - name: Get the sample app and EC2 instance information | |
| working-directory: terraform/java/ec2/adot-sigv4 | |
| run: | | |
| echo "MAIN_SERVICE_ENDPOINT=localhost:8080" >> $GITHUB_ENV | |
| echo "REMOTE_SERVICE_IP=$(terraform output sample_app_remote_service_private_ip)" >> $GITHUB_ENV | |
| echo "MAIN_SERVICE_INSTANCE_ID=$(terraform output main_service_instance_id)" >> $GITHUB_ENV | |
| - name: Initiate Gradlew Daemon | |
| if: steps.initiate-gradlew == 'failure' | |
| uses: ./.github/workflows/actions/execute_and_retry | |
| continue-on-error: true | |
| with: | |
| command: "./gradlew :validator:build" | |
| cleanup: "./gradlew clean" | |
| max_retry: 3 | |
| sleep_time: 60 | |
| # Validation for pulse telemetry data | |
| - name: Validate generated EMF logs | |
| id: log-validation | |
| run: ./gradlew validator:run --args='-c java/ec2/adot-sigv4/log-validation.yml | |
| --testing-id ${{ env.TESTING_ID }} | |
| --endpoint http://${{ env.MAIN_SERVICE_ENDPOINT }} | |
| --remote-service-deployment-name ${{ env.REMOTE_SERVICE_IP }}:8080 | |
| --region ${{ env.E2E_TEST_AWS_REGION }} | |
| --account-id ${{ env.E2E_TEST_ACCOUNT_ID }} | |
| --metric-namespace ${{ env.METRIC_NAMESPACE }} | |
| --log-group ${{ env.LOG_GROUP_NAME }} | |
| --service-name sample-application-${{ env.TESTING_ID }} | |
| --remote-service-name sample-remote-application-${{ env.TESTING_ID }} | |
| --query-string ip=${{ env.REMOTE_SERVICE_IP }}&testingId=${{ env.TESTING_ID }} | |
| --instance-ami ${{ env.EC2_INSTANCE_AMI }} | |
| --instance-id ${{ env.MAIN_SERVICE_INSTANCE_ID }} | |
| --rollup' | |
| - name: Validate generated metrics | |
| id: metric-validation | |
| if: (success() || steps.log-validation.outcome == 'failure') && !cancelled() | |
| run: ./gradlew validator:run --args='-c java/ec2/adot-sigv4/metric-validation.yml | |
| --testing-id ${{ env.TESTING_ID }} | |
| --endpoint http://${{ env.MAIN_SERVICE_ENDPOINT }} | |
| --remote-service-deployment-name sample-remote-application-${{ env.TESTING_ID }} | |
| --region ${{ env.E2E_TEST_AWS_REGION }} | |
| --account-id ${{ env.E2E_TEST_ACCOUNT_ID }} | |
| --metric-namespace ${{ env.METRIC_NAMESPACE }} | |
| --log-group ${{ env.LOG_GROUP_NAME }} | |
| --service-name sample-application-${{ env.TESTING_ID }} | |
| --remote-service-name sample-remote-application-${{ env.TESTING_ID }} | |
| --query-string ip=${{ env.REMOTE_SERVICE_IP }}&testingId=${{ env.TESTING_ID }} | |
| --instance-ami ${{ env.EC2_INSTANCE_AMI }} | |
| --instance-id ${{ env.MAIN_SERVICE_INSTANCE_ID }} | |
| --rollup' | |
| - name: Validate generated traces | |
| id: trace-validation | |
| if: (success() || steps.log-validation.outcome == 'failure' || steps.metric-validation.outcome == 'failure') && !cancelled() | |
| run: ./gradlew validator:run --args='-c java/ec2/adot-sigv4/trace-validation.yml | |
| --testing-id ${{ env.TESTING_ID }} | |
| --endpoint http://${{ env.MAIN_SERVICE_ENDPOINT }} | |
| --remote-service-deployment-name ${{ env.REMOTE_SERVICE_IP }}:8080 | |
| --region ${{ env.E2E_TEST_AWS_REGION }} | |
| --account-id ${{ env.E2E_TEST_ACCOUNT_ID }} | |
| --metric-namespace ${{ env.METRIC_NAMESPACE }} | |
| --log-group ${{ env.LOG_GROUP_NAME }} | |
| --service-name sample-application-${{ env.TESTING_ID }} | |
| --remote-service-name sample-remote-application-${{ env.TESTING_ID }} | |
| --query-string ip=${{ env.REMOTE_SERVICE_IP }}&testingId=${{ env.TESTING_ID }} | |
| --instance-ami ${{ env.EC2_INSTANCE_AMI }} | |
| --instance-id ${{ env.MAIN_SERVICE_INSTANCE_ID }} | |
| --rollup' | |
| - name: Refresh AWS Credentials | |
| if: ${{ github.event.repository.name == 'aws-application-signals-test-framework' }} | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| role-to-assume: arn:aws:iam::${{ env.E2E_TEST_ACCOUNT_ID }}:role/${{ env.E2E_TEST_ROLE_NAME }} | |
| aws-region: ${{ env.E2E_TEST_AWS_REGION }} | |
| # Clean up Procedures | |
| - name: Terraform destroy | |
| if: always() | |
| continue-on-error: true | |
| working-directory: terraform/java/ec2/adot-sigv4 | |
| run: | | |
| terraform destroy -auto-approve \ | |
| -var="test_id=${{ env.TESTING_ID }}" |