Repository navigation
feat(disruption): executor invocation router — inject vs revert (ADR-031) [#1419] - #1643
susumutomita wants to merge 1 commit into
Conversation
The last piece of executor *logic*: routeDisruptionInvocation distinguishes the
two ways the executor Lambda is invoked and dispatches each:
- EventBridge *DisruptionFired envelope → parse detail → executeDisruptionAction (inject)
- aws-scheduler one-shot { mode:"revert", dispatch, target } → reuse the sendDispatch
dep directly (the wired dep re-AssumeRoles from target; inject-time creds aren't kept)
- malformed envelope → invalid_event (handler logs/metrics, no crash)
parseDisruptionFiredDetail narrows the EventBridge detail (required strings;
parameters defaults to {}). Pure module, DI — index.ts wires real clients +
AssumeRole (deploy step). 9 new tests (parse 3 + route 4 + ...); infra suite green.
With this, the executor's full logic is built and tested: builders, orchestration,
DDB store, sendDispatch, scheduleRevert, and routing — across #1640/#1641/#1642 and
this PR. Only the real-deps index.ts wiring + the CDK construct (Lambda + EventBridge
rule + scoped sts:AssumeRole + scheduler role IAM) remain — they deploy real fault
injection, owner review/deploy.
Relates #1419
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## feat/1419-executor-schedule-revert #1643 +/- ##
======================================================================
+ Coverage 93.37% 93.39% +0.01%
======================================================================
Files 396 397 +1
Lines 10844 10867 +23
Branches 3327 3335 +8
======================================================================
+ Hits 10126 10149 +23
Misses 222 222
Partials 496 496 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
Summary
The last piece of executor logic:
routeDisruptionInvocationdistinguishes the two ways the single executor Lambda is invoked and dispatches each.*DisruptionFiredenvelope →parseDisruptionFiredDetail→executeDisruptionAction(inject path).{ mode:"revert", dispatch, target }→ reuse thesendDispatchdep directly (the wired dep re-AssumeRoles fromtarget, so inject-time credentials are never persisted; the pre-built revert dispatch just gets sent).invalid_event(the handler logs/metrics; no crash).parseDisruptionFiredDetailnarrows the EventBridgedetail(all required strings present;parametersdefaults to{}for absent/non-object). Pure module with DI —index.ts(the real-client + AssumeRole wiring) is the deploy step.Test plan
disruption-route.test.ts): parse (valid / default-params / missing-field), route (inject → execute, revert → sendDispatch only, malformed → invalid_event, revert-missing-fields → invalid_event).tsc --noEmit, biome,make harness(no findings),check-no-conflicts: clean. Infra suite green.Executor logic — now complete
With this PR the executor's entire logic is built + tested (≈39 tests), all pure / DI, no deploy:
executeDisruptionAction)claimExecution/resolveDeployment)sendDispatch(SSM/Lambda/CFn)scheduleRevert(aws-scheduler)Regression analysis
Net-new, zero production call sites (the
index.tsreal-deps wiring + CDK construct are the owner-reviewed deploy step). No Lambda/IAM/event/existing-file change. Pure functions over injected deps; theinvalid_event/ not-called branches are asserted.Physical impact
NO-OP on CloudFormation / deployed artifacts. A TypeScript module + tests. Nothing invocable until
index.ts+ the construct land.Remaining for #1419 (deploy boundary, owner)
index.ts— construct the real clients +assumeCompetitorRole(describe-stack pattern) + wiresendDispatch/scheduleRevert/store deps, export the Lambda handler overrouteDisruptionInvocation.*DisruptionFired) + scopedsts:AssumeRoleIAM + the scheduler execution role + env (table names, catalog, scheduler role ARN, self ARN).These deploy real fault injection into competitor accounts on the AdministratorAccess role — your review/deploy decision.
Relates #1419