Astra r3
Vote¶
REJECT — Most round-2 conditions are addressed, but three P1 contradictions remain in retention mechanics, destructive-handler fates, and SecureString adoption.
Round-2 conditions status¶
| Condition (reviewer + number) | Status | Note |
|---|---|---|
| Astra C1 | addressed | §2.2 dependency propagation, §2.5 teardown gates, §6 mixed-app tests. |
| Astra C2 | partial | Nested publication and verification specified; blanket Modify rejection prevents it. |
| Astra C3 | addressed | Hosted-zone attribution and detached StackSet-instance sequence corrected. |
| Astra C4 | partial | Dependencies and environment reconstruction covered; SecureString no-read import is incorrect. |
| Astra C5 | addressed | Strict import/state checks; protection enabled before re-inventory is a valid alternative. |
| Astra C6 | addressed | v0.1 adoption only; rebuild prerequisites deferred explicitly. |
| Fable C1 | partial | Retain-all and dependency list added; destructive handles still qualify for dropping. |
| Fable C2 | addressed | Neutralizer fallback specified. |
| Fable C3 | addressed | Remaining consumers prevent shared-stack teardown. |
| Fable C4 | partial | Nested mechanics/parameters/capabilities present; change-set gate contradicts them. |
| Fable C5 | addressed | Informational Express predicate written down. |
| Fable C6 | addressed | Rebuild explicitly v0.2. |
| Opus C1 | addressed | Closure, IAM/network dependencies and CMK reporting specified. |
| Opus C2 | partial | External objects and fallback covered; public-release gate replaces literal no-guidance gate, consistent with maintainer decision. |
| Opus C3 | addressed | Consumer-aware truncation covers env/app/StackSet. |
| Opus C4 | partial | Import/state checks and offline partial-migration tests present; real partial-migration case absent. |
| Opus C5 | partial | Mechanics largely present; blanket Modify rejection is unworkable. |
| Opus C6 | addressed | Predicate present. |
| Astra new P1: deletion protection | addressed | Live-matching HCL after out-of-band protection. |
| Fable new P1: retain whitelist | partial | Whitelist removed; destructive-handle exception remains. |
| Opus new P1: deletion protection | addressed | Same fix. |
| Opus new P1: IAM/network omissions | addressed | §2.2 explicitly includes them. |
Blocking issues (only if REJECT)¶
-
P1 — §2.4, §2.5 step 3, §6: fix the change-set acceptance rule. Changing a nested stack’s
TemplateURLproduces a resource modification, which the plan categorically rejects. Require--include-nested-stacks, inspect descendants, and narrowly permit verified retention-policy changes and non-replacing wrapperTemplateURLchanges to verified patched children. Reject other changes. Also checkReplacement=True/Conditional;Replaceis not a CloudFormation action. AWS nested change sets, ResourceChange API. -
P1 — §2.2 versus §2.4: remove destructive custom-resource handles from
drop-after-cutover. §2.2 explicitly permits droppingEnvControllerAction-style handles, while §2.4 promises to retain every such handle. Make retention unconditional for every custom-resource handle through stack teardown; assign later manual cleanup separately. Otherwise the stated fate rule can re-enable the destructive Delete handler the design must suppress. -
P1 — §2.2–2.4: replace the SecureString “imported by name without reading values” promise with an implementable ownership contract.
aws_ssm_parameterrefresh requests decryption; ordinary value handling also stores the value in state. Import-by-name does not avoid this, and write-only configuration does not eliminate the provider read. For v0.1, retain these parameters under their existing owner and reference their identifiers, blocking affected teardown, unless a tested alternative is specified. Explicitly distinguish ecsodus’s reads from Terraform’s reads and secret-bearing artifacts. AWS provider implementation.
Notes (non-blocking)¶
- P2 — §2.1/2.5: Retain updates change
LastUpdatedTime, making the pre-patch inventory fail freshness checks. Specify re-inventory/regeneration after verified patches. - P2 — §6: Add a real partial-migration case; require a domain-enabled fixture before claiming certificate/DNS survival is validated.
- P2 — §2.6: Make the runbook’s zero-change steady gate machine-enforced; the current checker merely warns on updates.
- P2 — §2.1/2.4: Extend sensitive-file permissions and ignore rules to generated HCL, plan JSON and state checkpoints containing plaintext environment values.