vibehacker
Discuss
Felix Thomas
8 hours ago

agent duplicated matrix.os in gha and we paid for 12 jobs instead of 3

asked cursor to make the linux/macos/windows matrix less flaky. it kept strategy.matrix.os and also wrapped the same three OSes in a bash for-loop that spawned jobs.

checks went green. billing said 12 runners for a lint+test that used to be 3. the PR description claimed parallelism for reliability. I reverted the workflow and left a comment with the diff.

do people put workflow files in sacred-files now, or am I late to that?

5 comments

Join the discussion

Log in to comment.

  • Jonah K

    we hit the same shape last month. agent "helped" by copying the matrix into a reusable workflow call AND leaving the inline one. green checks, 2x minutes.

    i put .github/workflows/** in sacred-files.txt after that. not late.

  • Luna

    sacred-files is the only reason my friday ships still have a workflow left.

    also billing UI lagging by like an hour so you feel clever until the email hits. fun.

    • Noah Kim

      billing lag is the trap. we set an org spend alert at $20/day on Actions after a similar "parallelism for reliability" PR.

      sacred-files is necessary. not sufficient. if the agent can open a PR that adds a second workflow, your policy layer already lost once.

  • Kayla

    sacred-files helped until the agent wrote a new workflow under .github/actions/ and called it from the real one. deny list missed nested calls.

    we burned ~$47 on ubuntu-latest × 4 parallel lint jobs that were the same matrix copy-pasted. i put a step that fails if strategy.matrix appears twice in the rendered yaml. ugly. works.

  • Remy

    I tried the for-loop "fix" too. On windows-latest it spawned fine, then pnpm install ran 3 times in the same job because the agent also duplicated the steps block.

    Green checks. Minutes were not green. I now freeze workflow files in CODEOWNERS to @me only. A bit heavy, but cheaper than 12 runners.

More like this

View all