Problem
.github/workflows/deploy-aws-lambda.yml (around lines 190-199) still has an unconditional failure-path state-lock release:
- name: Release state lock on failure
if: failure() || cancelled()
run: |
...
aws s3 rm "s3://${BUCKET}/${LOCK_KEY}"
This is the same state-corruption race that #438 closed for deploy-aws-fargate.yml: a run that fails because it could not acquire the lock will execute this cleanup and delete the lock held by another run that is still actively applying, enabling parallel state writes.
The Fargate workflow now relies solely on the operator-triggered clear_stale_lock input (PR #818). The Lambda workflow should adopt the same approach.
Fix
Remove the automatic Release state lock on failure step from deploy-aws-lambda.yml and add an operator-triggered clear_stale_lock workflow_dispatch boolean input (mirroring the Fargate workflow). Terraform already releases its own lock on a clean apply error; a surviving lock means the run died abnormally and needs operator confirmation before clearing. Reference runbooks/terraform-stuck-lock.md.
Out of scope for #818
PR #818 is scoped to the Fargate workflow only; this is the parallel fix for the Lambda deploy path.
Problem
.github/workflows/deploy-aws-lambda.yml(around lines 190-199) still has an unconditional failure-path state-lock release:This is the same state-corruption race that #438 closed for
deploy-aws-fargate.yml: a run that fails because it could not acquire the lock will execute this cleanup and delete the lock held by another run that is still actively applying, enabling parallel state writes.The Fargate workflow now relies solely on the operator-triggered
clear_stale_lockinput (PR #818). The Lambda workflow should adopt the same approach.Fix
Remove the automatic
Release state lock on failurestep fromdeploy-aws-lambda.ymland add an operator-triggeredclear_stale_lockworkflow_dispatchboolean input (mirroring the Fargate workflow). Terraform already releases its own lock on a clean apply error; a surviving lock means the run died abnormally and needs operator confirmation before clearing. Referencerunbooks/terraform-stuck-lock.md.Out of scope for #818
PR #818 is scoped to the Fargate workflow only; this is the parallel fix for the Lambda deploy path.