Repository navigation
feat: harden AWS integration security and deployment evidence - #22
CoreyLeath-code merged 21 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 584962572f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| selector: | ||
| matchLabels: | ||
| app: api-gateway | ||
| app.kubernetes.io/name: api-gateway |
There was a problem hiding this comment.
Preserve the existing Deployment selector during promotion
When this manifest is applied over a Deployment created from the previous version, kubectl apply rejects the update because spec.selector is immutable and this changes it from app: api-gateway to app.kubernetes.io/name: api-gateway. The new promotion workflow applies the manifest to the same api-gateway object, so the first promotion to any existing environment cannot proceed; retain the original selector label or explicitly implement a safe replacement migration.
Useful? React with 👍 / 👎.
| ingress { | ||
| description = "IAM-authenticated Kafka traffic within the cluster security group" | ||
| from_port = 9098 | ||
| to_port = 9098 | ||
| protocol = "tcp" | ||
| self = true |
There was a problem hiding this comment.
Permit the measurement runner to reach the MSK security group
For the documented self-hosted VPC runner, this self-referencing rule only admits sources already attached to the newly created MSK security group. The workflow supplies only the VPC and subnet IDs and never attaches this generated group to the runner or adds an ingress rule for the runner's security group, so scripts/aws_msk_e2e.py cannot connect to port 9098 even when the runner has a route into the VPC. Accept a runner security-group input or otherwise authorize the producer explicitly.
Useful? React with 👍 / 👎.
| jwks_url = os.getenv("AUTH_JWKS_URL") or f"{issuer}/.well-known/jwks.json" | ||
| signing_key = _jwks_client(jwks_url).get_signing_key_from_jwt(token) | ||
|
|
||
| try: |
There was a problem hiding this comment.
Catch JWKS lookup failures as authentication errors
When an unauthenticated caller supplies a malformed JWT or an unknown kid, get_signing_key_from_jwt() can raise before entering the try block, so FastAPI returns an unhandled 500 rather than the intended 401 response. Move the signing-key lookup into the guarded verification path and translate its PyJWT/JWK errors to the same authentication failure response.
Useful? React with 👍 / 👎.
4eca332
into
feat/aws-cloudwatch-observability
Summary
Completes the next production-hardening roadmap tranche on top of the CloudWatch observability branch while preserving the repository's evidence-first/no-overclaim rule.
This is a stacked PR based on
feat/aws-cloudwatch-observability.What changed
Real development Amazon MSK integration
msk_cluster_arnor the optional development cluster as the Lambda MSK event source.scripts/aws_msk_e2e.pyto send synthetictrip.completedprobes through MSK -> Lambda -> SQS -> Lambda -> SNS -> probe SQS and record min/mean/p50/p95/p99/max latency.evidence/aws-msk-integration-results.jsonwithstatus: not_rununtil a real authorized AWS run occurs.Authentication, Secrets Manager, and PII boundaries
/drivers,/drivers/{driver_id}, and/count./healthand/readyunauthenticated for infrastructure probes.Kubernetes environments and promotion/rollback evidence
yourdockerhub/api-gateway:latestdeployment image.@sha256:images for production promotion before any apply.Coverage and validation
Documentation
docs/aws-msk-integration.md.docs/security-and-pii.md.docs/kubernetes-promotion.md..env.example, and changelog.Evidence / production boundary
No real AWS MSK latency/cost result or Kubernetes deployment/rollback result is claimed by this PR. The code, Terraform, workflows, and evidence schemas are implemented, while checked-in cloud/deployment evidence remains
not_rununtil an authorized environment actually executes those workflows.Remaining production gaps are documented explicitly: durable idempotency and DLQ replay, fine-grained authorization, distributed tracing, measured SLO/error-budget policy, secret rotation operations, capacity/failover/DR evidence, payment/trip consistency controls, and production privacy/audit policy.