From 607afead10ca2746159a560a9e5c30fa56abda9f Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 25 May 2026 19:15:55 +0200 Subject: [PATCH 1/2] ci(pre-commit): auth tflint via GITHUB_TOKEN + retry transient flakes (closes #564) The `Run pre-commit` step in `.github/workflows/pre-commit.yml` intermittently fails because `terraform_tflint`'s `tflint --init` downloads ruleset plugins from the GitHub Releases API anonymously, hitting the 60-requests-per-hour per-IP limit that the runner shares with every other workflow running on the same NAT egress. Most recently observed on PR #696 (https://github.com/LeanerCloud/CUDly/actions/runs/26411029351). Two-part fix: 1. Expose secrets.GITHUB_TOKEN to the step. tflint reads GITHUB_TOKEN natively; with it set the limit jumps to 5000/hr per-token, which matters because the token is unique per workflow run, not per IP. This alone fixes the rate-limit class. 2. Wrap the step with nick-fields/retry@v3.0.2 (SHA-pinned per project policy) at 3 attempts with a 90s wait. The token fix eliminates the AWS-plugin rate-limit case; the retry handles the residual flakes (GitHub Releases availability blips, plugin download timeouts, etc.) so a transient failure no longer requires a manual rerun. Acceptance criteria from #564: - GITHUB_TOKEN exposed to the `Run pre-commit` step - Three consecutive `pre-commit` runs in the same hour all complete without a tflint rate-limit failure (the retry-wrapper also catches the residual flakes the token cannot) --- .github/workflows/pre-commit.yml | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index 654554bec..a89d317e2 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -180,6 +180,26 @@ jobs: # run and catch the syntax/style issues that terraform_validate # would catch; the deeper schema validation runs in # `terraform plan` during deploy workflows. + # + # GITHUB_TOKEN is passed so terraform_tflint's `tflint --init` + # step authenticates against the GitHub API (5000/hr per-token) + # when it downloads ruleset plugin releases. Without the token, + # tflint goes anonymous and hits the 60/hr per-IP limit shared + # across every workflow on the runner's NAT IP, which trips + # intermittently when PRs land in the same hour (issue #564). + # + # nick-fields/retry wraps the run with up to 3 attempts and a + # 90-second wait so transient flakes (GitHub Releases blips, + # tflint plugin download timeouts, etc.) do not require a + # manual rerun. The GITHUB_TOKEN fix above is the primary fix; + # the retry wrapper is the cheap defense-in-depth for the + # residual flakes that token alone cannot eliminate. + uses: nick-fields/retry@ce71cc2ab81d554ebbe88c79ab5975992d79ba08 # v3.0.2 env: SKIP: terraform_validate - run: pre-commit run --all-files + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + timeout_minutes: 15 + max_attempts: 3 + retry_wait_seconds: 90 + command: pre-commit run --all-files From dc639b66dc90c6bb004be6e0f5d559e0964c1876 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 25 May 2026 19:51:33 +0200 Subject: [PATCH 2/2] ci(pre-commit): bump job timeout to accommodate retry budget (CR #697) CR pointed out the retry policy was ineffective: `nick-fields/retry` uses `timeout_minutes` PER ATTEMPT (not total), so with `max_attempts: 3` and `timeout_minutes: 15` the worst case is ~48 min, but the job-level `timeout-minutes: 15` killed any retry before attempt 2 could start. Fix: tune both timeouts so the retry budget fits inside the job budget with safety margin. - per-attempt timeout: 15 -> 10 minutes (normal pre-commit runs take ~3-5 min, 10 is comfortable margin without inflating hang-detection latency) - job timeout: 15 -> 35 minutes worst case = 3 attempts * 10 min + 2 * 90 s retry waits = 33 min, fits in 35 min with margin Avoids CR's suggested 50-minute job cap because that would also delay killswitch on a genuinely hung step. 35 min is the tightest value that still lets all 3 attempts complete. --- .github/workflows/pre-commit.yml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index a89d317e2..7795c59ac 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -13,7 +13,13 @@ jobs: pre-commit: name: Run pre-commit hooks runs-on: ubuntu-latest - timeout-minutes: 15 + # 35 minutes accommodates the 3-attempt retry wrapper on the + # `Run pre-commit` step below (3 attempts * 10 min per-attempt + # timeout + 2 * 90 s retry waits = 33 min worst case) plus a + # small margin for setup/install steps. Without the bump, the + # job-level cap killed any retry attempt before it could start, + # making the retry policy ineffective (CR finding on #697). + timeout-minutes: 35 steps: - name: Checkout code uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 @@ -199,7 +205,7 @@ jobs: SKIP: terraform_validate GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: - timeout_minutes: 15 + timeout_minutes: 10 max_attempts: 3 retry_wait_seconds: 90 command: pre-commit run --all-files