Skip to content

fix(scale-set): implement review followups - #5472

Closed
edersonbrilhante wants to merge 30 commits into
mainfrom
fix/scale-set-review-followups
Closed

edersonbrilhante wants to merge 30 commits into
mainfrom
fix/scale-set-review-followups

Conversation

@edersonbrilhante

Copy link
Copy Markdown
Contributor

Description

This PR addresses the review feedback from PR #5299 and documents the experimental scale-set provider.

Changes include:

  • Remove SSM write-back from the read-only controller task role.
  • Require an explicit controller image and recommend immutable digests.
  • Scope private ECR permissions to the repository and enable them only for private ECR images.
  • Align scale-set CloudWatch log retention with the repository default of 180 days.
  • Rename scale-set logging input from kms_key_arn to kms_key_id.
  • Preserve logger error redaction by passing raw Error objects.
  • Remove duplicate startup logging.
  • Document HTTPS egress trade-offs and GitHub Meta API ranges.
  • Update the pinned harden-runner version.
  • Add the scale-set architecture, lifecycle, security boundaries, configuration defaults, migration guidance, and example navigation.
  • Document that the TypeScript controller owns GitHub scale-set API operations; Terraform provisions only the AWS controller infrastructure.
  • Add an ADR describing scale-set runtime ownership and lifecycle behavior.

Related Issues

Fix #5470 #5471

edersonbrilhante and others added 29 commits September 17, 2026 20:20
## Description

Wire scale-set orchestration through the provider-aware Terraform
composition.

- Resolve global and per-lane scale-set settings into the canonical
runner configuration.
- Route scale-set lanes through `runner-config` and the scale-set
orchestration provider.
- Extend the EC2 provider contract with the scale-set runtime
configuration, IAM fragments, and outputs consumed by the controller.
- Gate webhook resources by the selected orchestration provider.
- Add scale-set validation and Terraform coverage across the affected
modules.

This PR provides the Terraform wiring used by the scale-set example and
the later MiniStack integration PRs.

## Test Plan

- Terraform formatting, validation/TFLint, and merge-conflict checks
passed through the repository hooks.
- Scale-set routing and configuration-resolution tests passed.
- Multi-runner and runner-config scale-set Terraform tests passed.
- Native provider tests remain subject to the local macOS arm64
plugin-handshake limitation.

## Related Issues

Depends on #5299.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Description

Restore the multi-runner scale-set orchestration example removed by
revert PR #5403, replacing merged PR #5378.

The example provides the Terraform configuration, provider locks,
outputs, and documentation needed to deploy an ECS scale-set controller
with the EC2 runner compute provider. It is intentionally limited to the
example and its generated/provider metadata; the reusable MiniStack
fixture support and ECS/MockServer lifecycle smoke test are provided by
the follow-up PRs.

## Test Plan

- Terraform formatting passed through the repository hooks.
- Merge-conflict checks passed.
- Parent-branch Terraform checks passed after the idle-configuration
correction.
- No live AWS deployment was performed for this example-only PR; CI
validation remains the authoritative deployment check.

## Related Issues

Depends on #5350. Replaces #5378.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## Description

Adds the TypeScript implementation of the GitHub Actions runner
scale-set control plane on top of the Terraform orchestration introduced
by #5299.

This PR includes:

- A reusable GitHub Actions scale-set client that supports GitHub.com,
GHES, and data-residency endpoints; GitHub App access tokens;
runner-group and scale-set discovery/registration; JIT runner
configuration; runner removal; and message-session polling,
acknowledgement, job acquisition, refresh, and close.
- A long-running scale-set controller service for ECS. It loads
versioned runner configuration from SSM Parameter Store, runs
independent reconcilers for each runner configuration, exposes
liveness/readiness endpoints, and performs bounded shutdown and session
recovery.
- A scale-set compute-provider contract and EC2 implementation. The
provider reconciles capacity from `totalAssignedJobs`, generates JIT
configurations for launches, tracks provider-owned instances with tags,
preserves busy or unknown runners during scale-down, and supports
task-role or assumed-role credentials.
- Configuration, authentication, transport, retry, cancellation,
ownership, lifecycle, health, and reconciliation safeguards. Sensitive
tokens, message bodies, and JIT configurations are excluded from
manifests and logs; disabling TLS verification is scoped to the relevant
client instead of changing global Node.js state.
- Unit-test coverage for the scale-set client and HTTP/session behavior,
service configuration and credentials, controller lifecycle and health,
and EC2 provider configuration, inventory, reconciliation, scale-up, and
scale-down.

The Terraform documentation and workflow changes are tracked separately
in #5347.

## Test Plan

- Added focused TypeScript tests alongside the client, service,
controller, and compute-provider implementations.
- The scale-set service package provides `typecheck`, `build`,
`format-check`, `lint`, and `test` targets for CI validation.
- End-to-end ECS deployment is not part of this PR; the service consumes
the scale-set configuration and IAM contracts supplied by the Terraform
stack.

## Related Issues

- Stacked on #5299.
- Builds on the EC2 orchestration boundary from #5312.
- Follow-up documentation and workflow changes: #5347.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Guilherme Caulada <guilherme.caulada@gmail.com>
@edersonbrilhante
edersonbrilhante requested a review from a team as a code owner September 23, 2026 22:12
@edersonbrilhante
edersonbrilhante requested a review from a team as a code owner September 23, 2026 22:12
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

  • .github/workflows/lambda.yml

@edersonbrilhante edersonbrilhante changed the title Fix/scale set review followups fix(scale-set): implement review followups Sep 23, 2026
Comment thread modules/orchestration-providers/scale-set/validations.tf Outdated
guicaulada
guicaulada previously approved these changes Sep 24, 2026
@edersonbrilhante
edersonbrilhante requested a review from a team as a code owner September 25, 2026 12:33
@edersonbrilhante
edersonbrilhante force-pushed the feat-scale-set-terraform branch 2 times, most recently from 1ca4eb6 to 828b6d9 Compare September 25, 2026 13:05
Base automatically changed from feat-scale-set-terraform to main September 25, 2026 13:07
@edersonbrilhante
edersonbrilhante dismissed guicaulada’s stale review September 25, 2026 13:07

The base branch was changed.

@edersonbrilhante

Copy link
Copy Markdown
Contributor Author

Superseded by #5477

@edersonbrilhante
edersonbrilhante deleted the fix/scale-set-review-followups branch September 25, 2026 16:14
edersonbrilhante added a commit that referenced this pull request Sep 25, 2026
## Description

This PR addresses the review feedback from PR #5299 and documents the
experimental scale-set provider.
Replaces PR #5472

Changes include:

- Remove SSM write-back from the read-only controller task role.
- Require an explicit controller image and recommend immutable digests.
- Scope private ECR permissions to the repository and enable them only
for private ECR images.
- Align scale-set CloudWatch log retention with the repository default
of 180 days.
- Rename scale-set logging input from `kms_key_arn` to `kms_key_id`.
- Preserve logger error redaction by passing raw `Error` objects.
- Remove duplicate startup logging.
- Document HTTPS egress trade-offs and GitHub Meta API ranges.
- Update the pinned `harden-runner` version.
- Add the scale-set architecture, lifecycle, security boundaries,
configuration defaults, migration guidance, and example navigation.
- Document that the TypeScript controller owns GitHub scale-set API
operations; Terraform provisions only the AWS controller infrastructure.
- Add an ADR describing scale-set runtime ownership and lifecycle
behavior.

## Related Issues

Fix #5470 #5471
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(scale-set): document architecture and configuration options

2 participants