-
Notifications
You must be signed in to change notification settings - Fork 105
Fix AWS Deployment Failures #312
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
6991120
f6e8c14
cab8078
682f95f
6ba391b
31a6985
9668ae6
7667f7e
6495eb3
40871e6
dd8581b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,9 +1,11 @@ | ||
| # 503.graph-bfs - Graph BFS | ||
|
|
||
| **Type:** Scientific | ||
| **Languages:** Python | ||
| **Languages:** Python, C++ | ||
| **Architecture:** x64, arm64 | ||
|
|
||
| ## Description | ||
|
|
||
| The benchmark represents scientific computations offloaded to serverless functions. It uses the `python-igraph` library to generate an input graph and process it with the Breadth-First Search (BFS) algorithm. | ||
|
|
||
| Python 3.9 uses `python-igraph` 0.9, which reports the BFS root as its own parent. Newer igraph versions report `-1`. Output validation canonicalizes these equivalent root sentinels before checking the deterministic result checksum. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| # Copyright 2020-2025 ETH Zurich and the SeBS authors. All rights reserved. | ||
| squiggle==0.3.1 | ||
| # Lambda images use glibc 2.26, for which there are no wheels on new packages | ||
| # we have to fix version to prevent compilation from source | ||
| numpy==2.2.6 | ||
| contourpy==1.3.2 | ||
| pillow==10.3.0 | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,6 +16,7 @@ | |
| import base64 | ||
| import json | ||
| import os | ||
| import re | ||
| import time | ||
| from enum import Enum | ||
| from typing import TYPE_CHECKING, cast, Dict, List, Optional, Tuple | ||
|
|
@@ -472,9 +473,9 @@ def function_url_auth_type(self, value: FunctionURLAuthType): | |
| def lambda_role(self, boto3_session: boto3.session.Session) -> str: | ||
| """Get or create IAM role for Lambda execution. | ||
|
|
||
| Creates a Lambda execution role with S3 and basic execution permissions | ||
| if it doesn't already exist. The role allows Lambda functions to access | ||
| S3 and write CloudWatch logs. | ||
| Creates a Lambda execution role with S3, DynamoDB, and basic execution | ||
| permissions if it doesn't already exist. The role allows Lambda functions | ||
| to access SeBS resources and write CloudWatch logs. | ||
|
|
||
| Args: | ||
| boto3_session: Boto3 session for AWS API calls | ||
|
|
@@ -498,10 +499,6 @@ def lambda_role(self, boto3_session: boto3.session.Session) -> str: | |
| ], | ||
| } | ||
| role_name = "sebs-lambda-role" | ||
| attached_policies = [ | ||
| "arn:aws:iam::aws:policy/AmazonS3FullAccess", | ||
| "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole", | ||
| ] | ||
| try: | ||
| out = iam_client.get_role(RoleName=role_name) | ||
| self._lambda_role = out["Role"]["Arn"] | ||
|
|
@@ -517,9 +514,36 @@ def lambda_role(self, boto3_session: boto3.session.Session) -> str: | |
| "Sleep 10 seconds to avoid problems when using role immediately." | ||
| ) | ||
| time.sleep(10) | ||
| # Attach basic AWS Lambda and S3 policies. | ||
| for policy in attached_policies: | ||
|
|
||
| arn_match = re.fullmatch(r"arn:([^:]+):iam::([^:]+):role/.+", self._lambda_role) | ||
| if arn_match is None: | ||
| raise RuntimeError(f"Invalid Lambda execution role ARN: {self._lambda_role}") | ||
| partition, account_id = arn_match.groups() | ||
|
|
||
| for policy in ( | ||
| "arn:aws:iam::aws:policy/AmazonS3FullAccess", | ||
| "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole", | ||
| ): | ||
| iam_client.attach_role_policy(RoleName=role_name, PolicyArn=policy) | ||
|
|
||
| dynamodb_policy = { | ||
| "Version": "2012-10-17", | ||
| "Statement": [ | ||
| { | ||
| "Effect": "Allow", | ||
| "Action": ["dynamodb:GetItem", "dynamodb:PutItem", "dynamodb:Query"], | ||
| "Resource": ( | ||
| f"arn:{partition}:dynamodb:{self.region}:{account_id}:" | ||
| "table/sebs-benchmarks-*" | ||
| ), | ||
| } | ||
| ], | ||
| } | ||
| iam_client.put_role_policy( | ||
| RoleName=role_name, | ||
| PolicyName="sebs-dynamodb-access", | ||
| PolicyDocument=json.dumps(dynamodb_policy), | ||
| ) | ||
| return self._lambda_role | ||
|
|
||
| def http_api( | ||
|
|
@@ -1132,6 +1156,12 @@ def deserialize(config: dict, cache: Cache, handlers: LoggingHandlers) -> Resour | |
| ret.logging_handlers = handlers | ||
| ret.logging.info("No resources for AWS found, initialize!") | ||
|
|
||
| configured_lambda_role = config.get("lambda-role") or config.get("resources", {}).get( | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why do we need that? Shouldn't this be set in
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I added this because the role set in the config could be ignored when a cached role exists. It also picks up You're right about the placement. I'd move it into initialize() and make sure the user's role takes priority over the cached one. I also noticed that the examples/docs and the code use different places for The follow jsonc block shows the two fields I mean, and user setting one of them should be sufficient: {
"deployment": {
"aws": {
// Used in the examples/docs
"lambda-role": "arn:aws:iam::123456789012:role/my-role",
"resources": {
// Read by AWSResources.initialize()
"lambda-role": "arn:aws:iam::123456789012:role/my-role"
}
}
}
} |
||
| "lambda-role" | ||
| ) | ||
| if configured_lambda_role: | ||
| ret._lambda_role = configured_lambda_role | ||
|
|
||
| return ret | ||
|
|
||
|
|
||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.