Skip to content

Status: v0.2.1 (2026-10-08)

v0.2.1: safety fix and hatchling

  • The RUNBOOK no longer lists custom-resource handles for deletion (the 0.2.0 list named HTTPSCert's physical ID, the live certificate ARN). Custom-domain gaps found offline are fixed (gap analysis); the real custom-domain run (issue #6) still needs a domain.

  • Builds with hatchling (ADR-0016), so Homebrew can install it without Rust.

  • Next: the App Runner milestone M5 (plan, approved).

v0.2.0: Worker Services (ADR-0014)

  • Worker Services hand off, including the backlog-per-task Lambda their queue-depth scaling depends on. The synthetic full-hand-off app now has a Worker Service: four stacks, 114–117 imports, terraform validate clean. The new Lambda, permission, Events rule and target, and SNS subscription blocks plan as pure imports against a local moto server.

  • Verified on real AWS on 2026-10-07 (report).

v0.2.0: Scheduled Jobs (ADR-0015)

  • Scheduled Jobs hand off: the Events rule and its role-assuming target, the Step Functions state machine (definition substituted exactly and checked against the live definition), and the EFS access point on the env's managed file system. The synthetic app now has a job and the env's managed EFS: five stacks, 132–135 imports, terraform validate clean.

  • Verified on real AWS on 2026-10-07 (report): 63/63 pure imports, teardown, and a successful job run from the Terraform-owned state machine.

Done

  • Plan. PLAN.md r4 was approved unanimously in council round 4 (gpt-6-astra, Claude Fable 5.1 and Claude Opus 5.5). All four rounds are kept verbatim in council/, and the decisions are in adr/.

  • Commands. All five plan commands are implemented: inventory, report, generate, check (--phase import|steady, --state, --changeset, --template-diff) and verify-retain. A sixth, verify-fresh, came out of the code review.

  • Mappers. 64 CloudFormation resource types map to Terraform, covering the network, compute, data, IAM, DNS and out-of-band families. Unsupported shapes fail closed as blocked.

  • Knowledge base. The Copilot knowledge base covers all 13 custom resources (9 of them have destructive Delete handlers), the stack layering, and the env conditions.

  • Tests. 261 tests pass offline:

    • real Copilot-rendered fixtures
    • a synthetic app
    • moto
    • golden snapshots
    • a full hand-off app (env, LBWS, and an Aurora or S3/DynamoDB addon: 63–66 imports) whose generated Terraform passes terraform validate against the real AWS provider schema

    • a runbook block run under shell stubs, which proves a failed check stops the mutation

    • Code review. Two independent reviews (gpt-6-astra and Claude Opus), then a verification review of the fixes. Every P0 and P1 finding is fixed; see council/code-review-v0.1/.
  • Checks. ruff, ruff format, mypy and CI (GitHub Actions on Python 3.11–3.13) are all green.

  • Repository. It is public at github.com/moneytool/ecsodus, and published to PyPI as ecsodus (ADR-0013). main and release tags are protected by rulesets.

AWS end-to-end: passed (2026-09-30)

A real Copilot v1.34.1 app (env + Load Balanced Web Service + DynamoDB and S3 addons, 5 stacks) went through every runbook step in the sandbox account:

  • 44/44 pure imports, then 44/44 no-op plans before and after teardown.
  • All Copilot stacks and the StackSet were deleted.
  • The service kept serving HTTP 200, and the sentinel data survived.
  • Everything was removed afterwards.

Report: e2e/2026-09-30-aws-e2e.md.

PLAN §6 questions 1–3 are answered: Retain stops custom-resource Delete handlers, policy-only change sets are applied, and nested patches produce no Dynamic entries. Question 4 (a custom domain and ACM certificate) was not covered.

Teardown gate: removed (ADR-0012)

Step 5 is always emitted now, and the runbook banner states the verified scope.

Known limitations (fail-closed, documented)

  • Unsupported: RDWS, Static Sites, NLB, CloudFront, pipelines, and Transform or Fn::ForEach templates. Each is detected, reported, and kept on Copilot. (Service Connect is imported as deployed, per ADR-0011; sidecar containers are imported with their task definition.)

  • Partial imports: some imports are generated with notes, where a sub-resource is a separate Terraform resource (S3 bucket sub-configurations, IAM managed-policy attachments, cluster capacity providers). check --phase import flags any difference.

  • JSON templates are re-serialised rather than edited as text. The semantic check still applies.

Next

  1. Launch posts and docs pages titled for the searches people make (PLAN §7, M4).
  2. v0.2: App Runner, with a rebuild-in-parallel mode.