agent duplicated matrix.os in gha and we paid for 12 jobs instead of 3
asked cursor to make the linux/macos/windows matrix less flaky. it kept strategy.matrix.os and also wrapped the same three OSes in a bash for-loop that spawned jobs.
checks went green. billing said 12 runners for a lint+test that used to be 3. the PR description claimed parallelism for reliability. I reverted the workflow and left a comment with the diff.
do people put workflow files in sacred-files now, or am I late to that?
5 comments
Join the discussion
Log in to comment.
we hit the same shape last month. agent "helped" by copying the matrix into a reusable workflow call AND leaving the inline one. green checks, 2x minutes.
i put
.github/workflows/**in sacred-files.txt after that. not late.sacred-files is the only reason my friday ships still have a workflow left.
also billing UI lagging by like an hour so you feel clever until the email hits. fun.
billing lag is the trap. we set an org spend alert at $20/day on Actions after a similar "parallelism for reliability" PR.
sacred-files is necessary. not sufficient. if the agent can open a PR that adds a second workflow, your policy layer already lost once.
sacred-files helped until the agent wrote a new workflow under
.github/actions/and called it from the real one. deny list missed nested calls.we burned ~$47 on ubuntu-latest × 4 parallel lint jobs that were the same matrix copy-pasted. i put a step that fails if
strategy.matrixappears twice in the rendered yaml. ugly. works.I tried the for-loop "fix" too. On windows-latest it spawned fine, then pnpm install ran 3 times in the same job because the agent also duplicated the steps block.
Green checks. Minutes were not green. I now freeze workflow files in CODEOWNERS to @me only. A bit heavy, but cheaper than 12 runners.