In the single-account execution path, accountID := m.getAWSAccountID(ctx) (internal/purchase/execution.go:66) uses the ambient host STS (manager.go:725-742), computed BEFORE per-account creds are resolved (line 67). Consequences:
- An assume-role single-account AWS purchase records the HOST account on the
purchase_history row, not the target account.
- A direct-execute Azure/GCP purchase (PlanID=='' falls through to this path, line 65) stamps the AWS host account ID (or
"unknown") onto an Azure/GCP commitment's history row.
The fan-out path correctly uses account.ExternalID (line 126); the single-account path should too (and use the provider-appropriate account identifier for non-AWS).
Fix: resolve the target account ID per the resolved provider/account before stamping history. Test for assume-role AWS + direct Azure/GCP.
Dedup: related to #604 (scheduler tags nil instead of host UUID) but distinct code path + table (savePurchaseHistory account stamping). New. Surfaced in the purchase-workflow trace.
In the single-account execution path,
accountID := m.getAWSAccountID(ctx)(internal/purchase/execution.go:66) uses the ambient host STS (manager.go:725-742), computed BEFORE per-account creds are resolved (line 67). Consequences:purchase_historyrow, not the target account."unknown") onto an Azure/GCP commitment's history row.The fan-out path correctly uses
account.ExternalID(line 126); the single-account path should too (and use the provider-appropriate account identifier for non-AWS).Fix: resolve the target account ID per the resolved provider/account before stamping history. Test for assume-role AWS + direct Azure/GCP.
Dedup: related to #604 (scheduler tags nil instead of host UUID) but distinct code path + table (savePurchaseHistory account stamping). New. Surfaced in the purchase-workflow trace.