feat(cloudformation): stack policies, async stacks, CancelUpdateStack and RollbackStack (CFN-6) - #1380
Draft
NitinKumar004 wants to merge 1 commit into
Draft
feat(cloudformation): stack policies, async stacks, CancelUpdateStack and RollbackStack (CFN-6)#1380NitinKumar004 wants to merge 1 commit into
NitinKumar004 wants to merge 1 commit into
Conversation
… and RollbackStack (CFN-6)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
CFN-6: stack policies, asynchronous stack operations under
--async-settle,CancelUpdateStack, and theRollbackStack/TokenAlreadyExistsExceptionpart of CFN-X9. Closes the rest of CFN-06 and CFN-17.Stack policy
SetStackPolicy/GetStackPolicy, plusStackPolicyBody/StackPolicyURLon CreateStack and UpdateStack. URLs are read from the emulated S3, like TemplateURL.Update:Modify|Replace|Delete|*, Principal"*", Resource or NotResource as*orLogicalResourceId/<glob>, and ConditionStringEquals/StringLikeonResourceType. Bad JSON or a bad grammar is aValidationError, and the 16384 length limit is checked.Update:Modify), replacement (Update:Replace) and dropped resource (Update:Delete) before touching it. A denied resource endsUPDATE_FAILEDwithAction denied by stack policy: Statement [#N] does not allow [Update:Replace] for resource [LogicalResourceId/X], and the stack rolls back. Nothing is created or deleted for it.StackPolicyDuringUpdateBody/URLoverrides the policy for that one update only. A policy can be replaced but not removed: SetStackPolicy needs a body or a URL.Async stacks (config.AsyncSettle /
serve --async-settle)*_IN_PROGRESSfor the settle window. The resource work is done at once, but the last phase waits: completion, rollback, and the update's cleanup phase, where old resources of replacements are deleted. It completes lazily on the next API call or on the serve ticker (CloudFormation is now a registered Tickable).CancelUpdateStackworks only inUPDATE_IN_PROGRESS. Otherwise it returnsValidationError: CancelUpdateStack cannot be called from current stack status. It drops the events that had not arrived yet, fails the resources caught in progress, and goesUPDATE_ROLLBACK_IN_PROGRESS("Stack update cancelled") thenUPDATE_ROLLBACK_COMPLETE. The cleanup phase had not run yet, so the rollback puts the old resources of replacements back and deletes the new ones. No data is lost.RollbackStack and client request tokens
RollbackStackrolls aCREATE_FAILEDstack back toROLLBACK_COMPLETE, deleting what it made. It takes anUPDATE_FAILEDstack back to the template, parameters and resources it had before the first failed update, and puts back the old resources of replacements that update kept. It endsUPDATE_ROLLBACK_COMPLETE. Any other status is a ValidationError.ClientRequestTokenon CreateStack, UpdateStack, DeleteStack, ContinueUpdateRollback, CancelUpdateStack, RollbackStack and ExecuteChangeSet. A retry with the same token of the same action returns without running again, so a retried CreateStack returns the stack instead of AlreadyExists. A token used by another action isTokenAlreadyExistsException. Stack events carry the operation's token.Persistence
The stack policy, the pending async phase, the tokens and the last stable state are all in the snapshot. A restore mid-update can still settle it or cancel it.
Coverage docs
coveragegen dropped every
Set*method of a native mock as a wiring setter, soSetStackPolicywas missing. ASet*method whose first parameter is acontext.Contextis now counted as an operation, andTickis excluded like Snapshot/Restore. This also brings back ten real GKESet*operations that were hidden.Notes
Action denied by stack policy: No statement allows [...]), the RollbackStack bad-status text and the TokenAlreadyExists message are close guesses. I could not find the exact AWS strings in the docs or the botocore model.Testing
origin/development. Compat suite: SetStackPolicy, GetStackPolicy, CancelUpdateStack and RollbackStack are green, and compatgen exits 0.go build ./..., vet, andgo test -raceon cloudformation (provider, service, server), providers/aws, serverkit, settle, persist, coveragegen and compat/aws.golangci-lint --new-from-rev=origin/developmentreports 0 issues.cloudemu serveon :61166 with the aws CLI, with and without--async-settle. A policy deniesUpdate:Replaceon a table. The denied rename rolls back with the item intact and no new table. The override update replaces the table and the stored policy is unchanged. Bad JSON gets a ValidationError. Mid-updatecancel-update-stackgoes UPDATE_ROLLBACK_IN_PROGRESS and then COMPLETE, keeps the old table and its item, deletes the new one and reverts the template. Without settle, cancel returns the ValidationError.aws_cloudformation_stackwithpolicy_bodythrough apply, a clean plan, an update of both the template and the policy, another clean plan, and destroy, in both modes.