feat(aws-ssm): Run Command lifecycle, parameter checks, list and cancel ops (SSM-2) - #1382
Draft
NitinKumar004 wants to merge 1 commit into
Draft
NitinKumar004 wants to merge 1 commit into
NitinKumar004 wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Run Command now behaves like real SSM instead of recording an instant success. This is SSM-2 from the build-out plan, and it also covers tracker row SSM-X3 plus the SendCommand version and parameter checks deferred from #1367.
SendCommand
DocumentVersionaccepts$DEFAULT,$LATESTor a number. A bad pattern returnsValidationExceptionand a missing version returnsInvalidDocumentVersion. The response echoes the requested version ($DEFAULTwhen none is given).allowedValues,allowedPattern(full match),minItems/maxItemsandminChars/maxChars. Failures returnInvalidParameters. AWS-owned names that are not in the catalog are still accepted without checks.MaxConcurrency/MaxErrorspatterns,TimeoutSeconds30..2592000,Commentup to 100 characters, at most 50 instance ids and 5 targets, and the instance id pattern.InvalidInstanceId, and so is a stopped one ("not in a valid state"). Tag targets skip terminated instances. A stopped instance picked by a tag staysDelayedand ends asDeliveryTimedOutafterTimeoutSeconds.Pending, echoes every request field and includesTargetCount,RequestedDateTimeandExpiresAfter.OutputS3BucketNamegets the output object under<prefix>/<command>/<instance>/<plugin>/<step>/stdoutonce the invocation finishes. Without S3 the bucket is only echoed back. The output URLs are reported on the plugins, and on the invocation when the document has a single plugin.Lifecycle
--async-settle, invocations go Pending (1s), then InProgress (5s), then Success. They run inMaxConcurrencybatches. AnexecutionTimeoutshorter than the run ends asTimedOut/ExecutionTimedOut.MaxErrors, TimedOut, Incomplete and NoInstancesInTag.CompletedCount,ErrorCountandDeliveryTimedOutCountare filled in.New ops
ListCommands:CommandId,InstanceId, the five filter keys (InvokedAfter/InvokedBefore/Status/ExecutionStage/DocumentName), newest first, paging. An unknown key isInvalidFilterKeyand a bad token isInvalidNextToken.ListCommandInvocations: the same filters (exceptExecutionStage, which isInvalidFilterKeyhere) and--details, which returnsCommandPlugins(one per runtimeConfig plugin or mainSteps step).CancelCommand: cancels unfinished invocations on all targets or on the listed instances. An unknown command isInvalidCommandIdand an instance that is not a target isInvalidInstanceId. Finished invocations keep their result.DescribeInstanceInformation: every EC2 instance that is not terminated is listed as a managed node. Running instances are Online and the rest ConnectionLost. It supports both filter lists and paging (5..50).GetCommandInvocationreads from the same state. It takesPluginName(an unknown one isInvalidPluginName) and reports ResponseCode -1 until the run finishes, along with ExecutionStart/End/Elapsed.Persistence
Command history is saved in the snapshot under
commandHistory, which includes cancels and output-written flags. A restored command keeps settling from its send time. Snapshots in the older per-invocationcommandsform are converted on restore.Testing
server/aws/ssm/run_command_lifecycle_test.go) all failed on the old code. The provider tests cover MaxConcurrency staggering, delivery timeout on a stopped tag target, the snapshot round trip and legacy restore.commandsparameter, and instance ids that don't match the id pattern.go build ./....go vetandgo test -raceon internal/settle, providers/aws, providers/aws/ssm, server/aws/ssm and persist.golangci-lint --new-from-rev=origin/developmentis clean.coveragegenregenerated.cloudemu serve, with and without--async-settle:--details; get-command-invocation with--plugin-name; cancel-command while the command was InProgress (it ended Cancelled) and with an unknown id; the S3 output objects listed.aws_ssm_document: apply, no-drift plan, update to version 2, no-drift plan, send-command against the TF document, destroy.aws_ssm_associationwas skipped because Associations are not implemented yet (SSM-3).