Skip to content

fix(scale-set): implement review followups - #5477

Merged
edersonbrilhante merged 2 commits into
mainfrom
scale-set-review-followups
Sep 25, 2026
Merged

edersonbrilhante merged 2 commits into
mainfrom
scale-set-review-followups

Conversation

@edersonbrilhante

@edersonbrilhante edersonbrilhante commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR addresses the review feedback from PR #5299 and documents the experimental scale-set provider.
Replaces PR #5472

Changes include:

  • Remove SSM write-back from the read-only controller task role.
  • Require an explicit controller image and recommend immutable digests.
  • Scope private ECR permissions to the repository and enable them only for private ECR images.
  • Align scale-set CloudWatch log retention with the repository default of 180 days.
  • Rename scale-set logging input from kms_key_arn to kms_key_id.
  • Preserve logger error redaction by passing raw Error objects.
  • Remove duplicate startup logging.
  • Document HTTPS egress trade-offs and GitHub Meta API ranges.
  • Update the pinned harden-runner version.
  • Add the scale-set architecture, lifecycle, security boundaries, configuration defaults, migration guidance, and example navigation.
  • Document that the TypeScript controller owns GitHub scale-set API operations; Terraform provisions only the AWS controller infrastructure.
  • Add an ADR describing scale-set runtime ownership and lifecycle behavior.

Related Issues

Fix #5470 #5471

@edersonbrilhante
edersonbrilhante requested review from a team as code owners September 25, 2026 13:35
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/docker/build-push-action 53b7df96c91f9c12dcc8a07bcb9ccacbed38856a 🟢 7.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 9security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
SAST🟢 9SAST tool detected but not run on all commits
actions/docker/setup-buildx-action 37fe631027851001ddb9b187196cc803df7f5f0e 🟢 8.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 9security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
actions/docker/setup-qemu-action 96fe6ef7f33517b61c61be40b68a1882f3264fb8 🟢 8.4
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 9security policy file detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
SAST🟢 10SAST tool is run on all commits

Scanned Files

  • .github/workflows/lambda.yml

@edersonbrilhante
edersonbrilhante merged commit 445269c into main Sep 25, 2026
96 of 97 checks passed
@edersonbrilhante
edersonbrilhante deleted the scale-set-review-followups branch September 25, 2026 17:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(scale-set): document architecture and configuration options

2 participants