fix(scale-set): implement review followups - #5472
Closed
edersonbrilhante wants to merge 30 commits into
Closed
edersonbrilhante wants to merge 30 commits into
edersonbrilhante wants to merge 30 commits into
Conversation
## Description Wire scale-set orchestration through the provider-aware Terraform composition. - Resolve global and per-lane scale-set settings into the canonical runner configuration. - Route scale-set lanes through `runner-config` and the scale-set orchestration provider. - Extend the EC2 provider contract with the scale-set runtime configuration, IAM fragments, and outputs consumed by the controller. - Gate webhook resources by the selected orchestration provider. - Add scale-set validation and Terraform coverage across the affected modules. This PR provides the Terraform wiring used by the scale-set example and the later MiniStack integration PRs. ## Test Plan - Terraform formatting, validation/TFLint, and merge-conflict checks passed through the repository hooks. - Scale-set routing and configuration-resolution tests passed. - Multi-runner and runner-config scale-set Terraform tests passed. - Native provider tests remain subject to the local macOS arm64 plugin-handshake limitation. ## Related Issues Depends on #5299. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Description Restore the multi-runner scale-set orchestration example removed by revert PR #5403, replacing merged PR #5378. The example provides the Terraform configuration, provider locks, outputs, and documentation needed to deploy an ECS scale-set controller with the EC2 runner compute provider. It is intentionally limited to the example and its generated/provider metadata; the reusable MiniStack fixture support and ECS/MockServer lifecycle smoke test are provided by the follow-up PRs. ## Test Plan - Terraform formatting passed through the repository hooks. - Merge-conflict checks passed. - Parent-branch Terraform checks passed after the idle-configuration correction. - No live AWS deployment was performed for this example-only PR; CI validation remains the authoritative deployment check. ## Related Issues Depends on #5350. Replaces #5378. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Description Adds the TypeScript implementation of the GitHub Actions runner scale-set control plane on top of the Terraform orchestration introduced by #5299. This PR includes: - A reusable GitHub Actions scale-set client that supports GitHub.com, GHES, and data-residency endpoints; GitHub App access tokens; runner-group and scale-set discovery/registration; JIT runner configuration; runner removal; and message-session polling, acknowledgement, job acquisition, refresh, and close. - A long-running scale-set controller service for ECS. It loads versioned runner configuration from SSM Parameter Store, runs independent reconcilers for each runner configuration, exposes liveness/readiness endpoints, and performs bounded shutdown and session recovery. - A scale-set compute-provider contract and EC2 implementation. The provider reconciles capacity from `totalAssignedJobs`, generates JIT configurations for launches, tracks provider-owned instances with tags, preserves busy or unknown runners during scale-down, and supports task-role or assumed-role credentials. - Configuration, authentication, transport, retry, cancellation, ownership, lifecycle, health, and reconciliation safeguards. Sensitive tokens, message bodies, and JIT configurations are excluded from manifests and logs; disabling TLS verification is scoped to the relevant client instead of changing global Node.js state. - Unit-test coverage for the scale-set client and HTTP/session behavior, service configuration and credentials, controller lifecycle and health, and EC2 provider configuration, inventory, reconciliation, scale-up, and scale-down. The Terraform documentation and workflow changes are tracked separately in #5347. ## Test Plan - Added focused TypeScript tests alongside the client, service, controller, and compute-provider implementations. - The scale-set service package provides `typecheck`, `build`, `format-check`, `lint`, and `test` targets for CI validation. - End-to-end ECS deployment is not part of this PR; the service consumes the scale-set configuration and IAM contracts supplied by the Terraform stack. ## Related Issues - Stacked on #5299. - Builds on the EC2 orchestration boundary from #5312. - Follow-up documentation and workflow changes: #5347. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned Files
|
guicaulada
reviewed
Sep 24, 2026
guicaulada
previously approved these changes
Sep 24, 2026
edersonbrilhante
force-pushed
the
feat-scale-set-terraform
branch
from
September 25, 2026 12:33
db2c3fb to
23cdda4
Compare
edersonbrilhante
force-pushed
the
feat-scale-set-terraform
branch
2 times, most recently
from
September 25, 2026 13:05
1ca4eb6 to
828b6d9
Compare
edersonbrilhante
dismissed
guicaulada’s stale review
September 25, 2026 13:07
The base branch was changed.
edersonbrilhante
force-pushed
the
fix/scale-set-review-followups
branch
from
September 25, 2026 13:17
be1cfd8 to
6a52246
Compare
Contributor
Author
|
Superseded by #5477 |
edersonbrilhante
added a commit
that referenced
this pull request
Sep 25, 2026
## Description This PR addresses the review feedback from PR #5299 and documents the experimental scale-set provider. Replaces PR #5472 Changes include: - Remove SSM write-back from the read-only controller task role. - Require an explicit controller image and recommend immutable digests. - Scope private ECR permissions to the repository and enable them only for private ECR images. - Align scale-set CloudWatch log retention with the repository default of 180 days. - Rename scale-set logging input from `kms_key_arn` to `kms_key_id`. - Preserve logger error redaction by passing raw `Error` objects. - Remove duplicate startup logging. - Document HTTPS egress trade-offs and GitHub Meta API ranges. - Update the pinned `harden-runner` version. - Add the scale-set architecture, lifecycle, security boundaries, configuration defaults, migration guidance, and example navigation. - Document that the TypeScript controller owns GitHub scale-set API operations; Terraform provisions only the AWS controller infrastructure. - Add an ADR describing scale-set runtime ownership and lifecycle behavior. ## Related Issues Fix #5470 #5471
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses the review feedback from PR #5299 and documents the experimental scale-set provider.
Changes include:
kms_key_arntokms_key_id.Errorobjects.harden-runnerversion.Related Issues
Fix #5470 #5471