Skip to content

fix(scale-set): address PR #5299 review follow-ups #5471

Description

@edersonbrilhante

Context

Track the remaining findings from Npalm's review of PR #5299.

Required fixes

  • Resolve the controller task-role ssm:PutParameter mismatch. The controller writes discovered GitHub App installation IDs and runner-group IDs, but the current IAM policy grants read-only SSM access. Prefer removing write-back until both cache parameter ARNs are explicit Terraform inputs; do not introduce an unbounded write permission.
  • Replace the default scale-set controller :latest image with a verified immutable release digest and update tests/documentation.
  • Scope ECR layer-pull permissions to private-ECR deployments only; public GHCR deployments should not receive unused ECR permissions.
  • Align controller log retention with the repository baseline of 180 days, or document and justify a different default.
  • Preserve logger error redaction when normalizing Error values and add regression coverage.

Documentation and maintainability

  • Update docs/index.md and docs/configuration.md with scale-set architecture, ECS controller behavior, grouping, and experimental variables.
  • Extend the v1/v2 configuration and migration guides with scale-set selection guidance and limitations.
  • Add an ADR documenting that existing GitHub scale sets are adopted by name and are not created or deleted by Terraform.
  • Clarify the default 0.0.0.0/0 egress trade-off, GitHub Meta API ranges, and NAT/firewall/proxy alternatives in the module variables and README. Documentation issue docs(scale-set): document architecture and configuration options #5470 overlaps with this section and should be consolidated or closed as appropriate.
  • Remove duplicate controller startup log fields; keep the count at info level and names at debug level.
  • Align the step-security/harden-runner pin in .github/workflows/lambda.yml with the current repository pin.
  • Add a short comment documenting the security scope of the MiniStack Docker socket mount.

Validation

  • Run Terraform/OpenTofu formatting, validation, and scale-set tests.
  • Run focused TypeScript format, lint, build, and unit tests.
  • Regenerate Terraform documentation and run git diff --check.
  • Verify the final changed-file list and link the implementation branch/PR.

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions