ci: Cleanup AWS resources better - #2405
Merged
mmlb merged 3 commits intoOct 2, 2026
Merged
Conversation
PostgreSQL Extension Dependency Analysis: PR #2405
SummaryNo extensions had dependencies with MAJOR version updates. Full Analysis ResultsPostgreSQL 15 Extension DependenciesExtension: pg_repack
Raw Dependency TreeExtension: postgis
Raw Dependency TreePostgreSQL 17 Extension DependenciesExtension: pg_repack
Raw Dependency TreeExtension: postgis
Raw Dependency TreeOrioleDB 17 Extension Dependencies |
PostgreSQL Package Dependency Analysis: PR #2405
SummaryNo packages had MAJOR version updates. Full Analysis ResultsPostgreSQL 15 Dependency ChangesExtracting PostgreSQL 15 dependencies...
Runtime Closure Size
Raw Dependency ClosurePostgreSQL 17 Dependency ChangesExtracting PostgreSQL 17 dependencies...
Runtime Closure Size
Raw Dependency Closure |
Contributor
There was a problem hiding this comment.
Pull request overview
Centralizes AWS AMI build cleanup and expands stale-resource detection across CI workflows.
Changes:
- Adds shared scripts for execution-specific and stale-resource cleanup.
- Tags Packer resources for discovery and cleanup.
- Updates CI workflows and testinfra execution identifiers.
Reviewed changes
Copilot reviewed 10 out of 10 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
ci/cleanup-ami-build-resources.sh |
Adds shared AWS resource cleanup. |
ci/cleanup-stale-ami-build-resources.sh |
Discovers stale build executions. |
amazon-amd64-nix.pkr.hcl |
Adds cleanup tags to amd64 resources. |
amazon-arm64-nix.pkr.hcl |
Adds cleanup tags to arm64 resources. |
stage2-nix-psql.pkr.hcl |
Adds cleanup tags to stage-two resources. |
testinfra/test_ami_nix.py |
Requires explicit build and AMI identifiers. |
.github/workflows/ami-release-nix.yml |
Uses shared cleanup for releases. |
.github/workflows/testinfra-ami-build.yml |
Uses shared cleanup after testing. |
.github/workflows/cleanup-stale-ec2.yml |
Runs the stale-resource cleaner. |
.github/workflows/qemu-image-build.yml |
Simplifies, but does not centralize, cleanup. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
150
to
151
| run: | | ||
| aws ec2 describe-instances --filters "Name=tag:packerExecutionId,Values=${EXECUTION_ID}" --query "Reservations[].Instances[].InstanceId" --output text | xargs -r aws ec2 terminate-instances --instance-ids |
Collaborator
Author
There was a problem hiding this comment.
this workflow doesn't create any aws resources so no need for clean ups, will drop this in the next push.
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
from
September 30, 2026 16:51
600160d to
d7c94d6
Compare
mmlb
marked this pull request as ready for review
September 30, 2026 16:52
brainrake
requested changes
Sep 30, 2026
brainrake
reviewed
Sep 30, 2026
brainrake
requested changes
Sep 30, 2026
brainrake
approved these changes
Sep 30, 2026
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
2 times, most recently
from
September 30, 2026 19:35
bbeeab5 to
4876608
Compare
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
from
September 30, 2026 19:54
4876608 to
0c86b96
Compare
AMI_ID is obviously always required but would fail later in the test, better to do so early IMO. This test isn't really being run locally at the moment if/when it does, I want to make it easier by using the nix package instead which will set this before running.
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
from
October 1, 2026 20:31
0c86b96 to
73780e9
Compare
This comment has been minimized.
This comment has been minimized.
Our clean up has been pretty lacking. We've had left over key pairs, security groups and instances too. This new script fixes all of those. AMIs are only deleted if the --delete-ami is passed in which is not done for Release AMI Nix workflow.
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
from
October 1, 2026 22:20
73780e9 to
9d8b1dd
Compare
The stale cron job is updated to use a script that finds all the stale executionIDs and then passes that to the per-execution clean up script. AMIs deletion flag is not passed so won't be touched. Most of the resources are already discoverable, device mappings needed a timestamp for staleness discovery.
mmlb
force-pushed
the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
from
October 2, 2026 14:46
9d8b1dd to
b90bd8d
Compare
mmlb
deleted the
mannymendez/psql-1620-clean-up-packer-created-ci-resources
branch
October 2, 2026 17:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
Maintenance
What is the current behavior?
We do a pretty bad job cleaning up packer and testinfra created resources in general, especially when a job timesout/is cancelled. We have a cron job that is supposed to catch cases that are missed but it only does instances that are running.
What is the new behavior?
Moved the logic from each GHA workflow into an actual script that is used by all of them, including the stale clean up recurring job. The stale clean up job just goes through and finds executionIds or testinfra-run-ids and passes them to the execution clean up script. AMIs are not cleaned up.
Additional context
Having these in scripts is much nicer to develop than in yaml plus we can also easily run them locally for testing/one-offs too.