Skip to content

feat(terraform): default-off EventBridge ticks for ladder_run + fire_scheduled_purchases (L12) - #1369

Merged
cristim merged 2 commits into
mainfrom
feat/ladder-eventbridge-ticks
Jul 16, 2026
Merged

cristim merged 2 commits into
mainfrom
feat/ladder-eventbridge-ticks

Conversation

@cristim

@cristim cristim commented Jul 16, 2026 •

Copy link
Copy Markdown
Member

What

Work item L12 of the auto-laddering full-automation plan (closes gap G9). Adds two default-off EventBridge scheduled ticks, for both the Lambda and Fargate compute platforms:

  1. ladder_run (daily) — drives the scheduled laddering task added in feat(ladder): add ladder_run scheduled task (plan-only milestone) #1362.
  2. fire_scheduled_purchases (every 15 min) — the gap analysis found this action had no EventBridge rule anywhere, yet the auto-approve delayed-fire path reuses it verbatim; without a tick, delayed/scheduled purchases would never fire.

Both are cloned exactly from the existing ri_exchange / reap_stuck_purchases scheduled-rule pattern.

Safety

  • Default-off: every new resource (rules, targets, Lambda permissions, Fargate roles+policies) is count = var.enable_* ? 1 : 0, and both enable vars default false in every module and in environments/aws. Enabling is an explicit operator step.
  • No IAM broadening: the Fargate per-rule role+policy is identical in scope to the existing eventbridge_ri_exchange block (ecs:RunTask on the one task definition, iam:PassRole on exactly the two task roles, no wildcards); the Lambda permission grants only events.amazonaws.com invoke scoped to the specific rule ARN. The deploy SA already holds the events:*/iam:CreateRole bootstrap perms for the cudly-* prefixed names, so no bootstrap-permission change is required.
  • Fails loud, not silent: ladder_run isn't in the Go dispatcher until feat(ladder): add ladder_run scheduled task (plan-only milestone) #1362 merges, but a disabled rule creates zero resources, and premature enablement would error loudly (dispatchTask rejects unknown task types), never silently no-op.

Variables (all default-off)

  • enable_ladder_run_schedule (bool, false), ladder_run_schedule (rate(1 day))
  • enable_fire_scheduled_purchases_schedule (bool, false), fire_scheduled_purchases_schedule (rate(15 minutes))

Threaded through modules/compute/aws/{lambda,fargate} and environments/aws. Azure/GCP are intentionally untouched (no EventBridge; their ladder scheduling is Phase-4, L19-21).

Verification (exit 0)

  • terraform fmt -check -recursive clean on all touched modules.
  • terraform init -backend=false && terraform validate in the lambda and fargate modules: valid.
  • Pre-commit Terraform validate + tflint pass (no unused/undeclared vars).
  • Action strings verified against internal/server/handler.go scheduledEventActions / dispatch map.

Part of LeanerCloud/cloud-commitments-platform#70. Tracker LeanerCloud/cloud-commitments-go#27.

Summary by CodeRabbit

  • New Features
    • Added optional scheduled commitment-ladder planning runs with configurable frequency (disabled by default).
    • Added optional scheduled fire-scheduled-purchases sweeps with configurable intervals (disabled by default).
    • Implemented support for both Lambda- and Fargate-based deployments.
    • Updated Lambda Function URL security so it uses IAM authentication when CDN access is enabled.

…purchases (G9)

Add two default-off EventBridge rules cloned from the ri_exchange pattern:

- aws_cloudwatch_event_rule.ladder_run / target / permission, gated
  count = var.enable_ladder_run_schedule ? 1 : 0, fires action "ladder_run"
  on var.ladder_run_schedule (default rate(1 day)).
- aws_cloudwatch_event_rule.fire_scheduled_purchases / target / permission,
  gated count = var.enable_fire_scheduled_purchases_schedule ? 1 : 0, fires
  action "fire_scheduled_purchases" on var.fire_scheduled_purchases_schedule
  (default rate(15 minutes)).

Four new module vars (enable_ladder_run_schedule, ladder_run_schedule,
enable_fire_scheduled_purchases_schedule, fire_scheduled_purchases_schedule)
threaded through environments/aws, azure, gcp (variables.tf + compute.tf).
All four default to off/false; no existing resource is modified.

No new IAM: each block reuses the EventBridge->Lambda invoke-permission
pattern already used by ri_exchange, reap_stuck_purchases, and
analytics_collect. No bootstrap PR needed.

Verified action strings against internal/server/handler.go
scheduledEventActions map: "fire_scheduled_purchases" maps to
TaskFireScheduledPurchases (line 71). "ladder_run" is not yet in the
map (pending PR #1362); the rule is default-off and safe to add ahead
of the dispatcher wiring.

Gates: terraform fmt -check -recursive (exit 0), terraform validate in
terraform/modules/compute/aws/lambda with -backend=false init (exit 0).
@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/low Minor harm urgency/this-quarter Within the quarter impact/few Limited audience effort/s Hours type/feat New capability labels Jul 16, 2026
@cristim

cristim commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Important

Review skipped

No new commits to review since the last review.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 109eebf8-40a6-4100-b028-fb8dd33d4cdf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Terraform adds optional EventBridge schedules for commitment-ladder planning and scheduled-purchase sweeps in both Lambda and Fargate compute paths, with configurable enablement and rate expressions. Lambda Function URL authorization is derived from CDN enablement.

Changes

Scheduled automation

Layer / File(s) Summary
Schedule inputs and compute wiring
terraform/environments/aws/variables.tf, terraform/environments/aws/compute.tf, terraform/modules/compute/aws/lambda/variables.tf, terraform/modules/compute/aws/fargate/variables.tf
Adds enable flags and schedule expressions for both workflows, wires them into Lambda and Fargate modules, and derives Lambda Function URL authorization from CDN enablement.
Lambda EventBridge schedules
terraform/modules/compute/aws/lambda/main.tf
Adds optional EventBridge rules, Lambda targets, and invocation permissions for ladder_run and fire_scheduled_purchases.
Fargate EventBridge schedules
terraform/modules/compute/aws/fargate/main.tf
Adds optional EventBridge ECS targets and dedicated IAM permissions to run Fargate tasks for ladder_run and fire_scheduled_purchases.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant EventBridge
  participant ComputeTarget
  participant CUDly
  EventBridge->>ComputeTarget: Trigger configured schedule
  ComputeTarget->>CUDly: Run ladder_run or fire_scheduled_purchases
  CUDly-->>ComputeTarget: Complete scheduled workflow
Loading

Possibly related issues

  • LeanerCloud/CUDly#1336 — The PR adds the flag-gated Terraform EventBridge schedules and configuration for the ladder_run task described by the issue.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: adding default-off EventBridge schedules for ladder_run and fire_scheduled_purchases.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/ladder-eventbridge-ticks

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@terraform/modules/compute/aws/fargate/main.tf`:
- Around line 1054-1074: The EventBridge IAM policies are overly broad. In both
policy blocks at terraform/modules/compute/aws/fargate/main.tf lines 1054-1074
and 1153-1173, constrain each ecs:RunTask statement with an ecs:cluster
condition referencing aws_ecs_cluster.main.arn, and each iam:PassRole statement
with a StringEquals iam:PassedToService condition set to
ecs-tasks.amazonaws.com.

In `@terraform/modules/compute/aws/lambda/main.tf`:
- Around line 673-675: Update the scheduled-action dispatch configuration by
adding "ladder_run" to the scheduledEventActions collection used by the handler,
while preserving the existing jsonencoded action payload and other registered
actions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: eb3eff2c-57f9-4144-b5bd-3b5e64eb091e

📥 Commits

Reviewing files that changed from the base of the PR and between 79642c4 and 062cfa0.

📒 Files selected for processing (6)
  • terraform/environments/aws/compute.tf
  • terraform/environments/aws/variables.tf
  • terraform/modules/compute/aws/fargate/main.tf
  • terraform/modules/compute/aws/fargate/variables.tf
  • terraform/modules/compute/aws/lambda/main.tf
  • terraform/modules/compute/aws/lambda/variables.tf

Comment thread terraform/modules/compute/aws/fargate/main.tf
Comment thread terraform/modules/compute/aws/lambda/main.tf
…on ladder ticks

Address CodeRabbit findings on the L12 EventBridge ticks:

- Tighten the two new Fargate EventBridge->ECS roles (ladder_run,
  fire_scheduled_purchases). Add ArnEquals ecs:cluster =
  aws_ecs_cluster.main.arn on the ecs:RunTask statement and StringEquals
  iam:PassedToService = "ecs-tasks.amazonaws.com" on the iam:PassRole
  statement, matching AWS best practice for EventBridge-triggered ECS
  tasks. Only the two new blocks are touched; the existing ri_exchange
  block is unchanged.
- Document the intentional dispatch state above the ladder_run rule in
  both lambda/main.tf and fargate/main.tf: the "ladder_run" scheduled
  action is registered by the ladder_run task (PR #1362); the rule is
  default-off (count-gated) and enabling it before that task ships causes
  a loud dispatch error, never a silent no-op. No handler.go change here
  (that is #1362 scope; this PR stays terraform-only + default-off).
@cristim

cristim commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit ba49537 into main Jul 16, 2026
14 of 17 checks passed
@cristim
cristim deleted the feat/ladder-eventbridge-ticks branch July 16, 2026 13:58
@cristim

cristim commented Jul 16, 2026

Copy link
Copy Markdown
Member Author

Merged to main after: Fable review (SHIP - IAM verified byte-identical scope to the existing ri_exchange pattern), CodeRabbit IAM hardening applied (ecs:cluster ArnEquals on RunTask + iam:PassedToService on PassRole for both new roles), and the ladder_run dispatch-registration thread resolved by #1362 landing on main (the action is now registered; the rule stays default-off). Both EventBridge ticks (ladder_run daily, fire_scheduled_purchases 15-min) exist for Lambda and Fargate, count-gated off. Enabling is an explicit operator step via enable_*_schedule vars.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/few Limited audience priority/p2 Backlog-worthy severity/low Minor harm triaged Item has been triaged type/feat New capability urgency/this-quarter Within the quarter

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant