Round 4 vote: Claude Opus 5.5¶
(Verbatim; read-only; 2026-09-29.)
Vote¶
APPROVE WITH NOTES. r4 fixes all three round-3 blockers from Astra and both from Fable, and folds in every round-3 note. I found no remaining P0 or P1. The problems r4 introduces all fail closed: they can stop the runbook but cannot delete anything. They are listed below as P2/P3 notes to fold in during M2.
Round-3 items status¶
| Condition (reviewer + number) | Status | Note |
|---|---|---|
| Astra B1 / Fable B1 / Opus N1: change-set acceptance rule | addressed | §2.4 now requires Modify with Replacement: False. Allowed targets are DeletionPolicy/UpdateReplacePolicy, plus TemplateURL with RequiresRecreation: Never and a SHA-256 match. The rule runs on nested change sets through --include-nested-stacks. An empty change set counts as failure, and the check is machine-run (check --changeset). The Metadata fallback, the StackSet step and output-driven dynamic entries are gaps (notes 1–3). |
| Astra B2 / Fable B2: no fate may drop destructive handles | addressed | drop-after-cutover is gone. manual-cleanup stays retained, and the patch has "no exceptions", with Custom::*/EnvControllerAction/AddonsStack named (§2.2, §2.4). |
| Astra B3: SecureString import reads values | addressed | SecureStrings are now external-reference. This is accurate: copilot secret init writes them outside CloudFormation, and AWS::SSM::Parameter cannot create SecureString. Secrets Manager is resource-only (no secret_version). ecsodus reads, Terraform reads and secret-bearing artifacts are listed separately. |
| Astra N: freshness vs step 3 | addressed | §2.5 step 3 ends with a fresh inventory and regeneration. |
| Astra N: steady gate machine-enforced | addressed | §2.6 --phase steady fails on any action other than no-op. |
| Astra N: sensitive artifacts beyond inventory | addressed | HCL, plan.json, state.txt and checkpoints are written 0600 and git-ignored. |
| Astra N: real partial-migration and domain e2e | addressed | Both are in §6 e2e scope. |
| Fable N: freshness | addressed | Same fix as Astra's. |
| Fable N: StackSet instances protected before detach | partial | Step 3 now uses update-stack-set, but StackSets have no change sets, so the §2.4 rule cannot run there (note 2). |
| Fable N: neutralizer / 2027-08-31 | addressed | §2.3, §2.4. |
| Fable N: out-of-band protection drift not reverted | addressed | §2.5 step 2. |
| Fable N: keep-CloudFormation caveat | addressed | §2.3. |
| Opus N2: freshness | addressed | Step 3 re-inventory. |
| Opus N3: artifact bucket / ARN-string closure | addressed | §2.2 closure list and ARN rule. |
| Opus N4: coexistence after partial migration | addressed | §2.5 step 7. |
| Opus N5: gate only step 5 | addressed | §6 always emits steps 6–7. |
| Opus N6: rotation fated | addressed | Rotation schedules are imported; rotation Lambdas are imported or documented as manually owned. |
| Opus N7: Terraform ≥ 1.10 | addressed | §2.4, §5. removed also needs ≥ 1.7, which the 1.10 floor covers. |
| Opus N8: imported task-definition revision | addressed | removed { lifecycle { destroy = false } } hand-off (see note 5). |
Blocking issues (only if REJECT)¶
None.
Notes (non-blocking)¶
- P2 – §2.4, the Metadata fallback breaks the acceptance rule. The fallback adds an
ecsodus:retainMetadatakey. That shows up as aMetadatascope/target, which the rule rejects, so the fallback can never passcheck --changeset. Add a--allow-metadata-key ecsodus:retainmode that also acceptsAttribute: Metadatatargets; confirm in the e2e that aMetadatachange combined with a policy change is actually applied. - P2 – §2.5 step 3, the StackSet path.
update-stack-sethas no change set. Specify instead: pre-check diff of the patched template against the StackSet's own deployed template (describe-stack-set), only policy lines may differ;UsePreviousValue, Copilot's existing--administration-role-arn/--execution-role-name, existing capabilities; wait forSUCCEEDEDand runverify-retainon every instance stack. Step 5.4's re-patch is then redundant but harmless. - P2 – §2.4, dynamic entries in the parent change set. When a nested stack's
TemplateURLchanges, parent resources that read its outputs through!GetAtt AddonsStack.Outputs.*may be listed asModifywithEvaluation: Dynamic,ChangeSource: ResourceAttributeandReplacement: Conditional(task definition, IAM policies). Add a §6 e2e question; if it occurs, allowDynamic/ResourceAttributeentries whose causing entity is a patched nested stack, provided that child's change set shows no output-affecting changes. - P3 – §2.4, re-running an already-patched stack yields "no changes", which the rule counts as failure. Skip any stack where
verify-retainalready passes. NameSyncWithActualin the reject list. - P3 – §2.4, removing the imported task definition.
aws_ecs_service.task_definitionmust stop referencingaws_ecs_task_definition.xbefore theremovedblock. Emit a literal ARN or a data source. - P3 – §2.2 wording. Add
external-referenceas an allowed closure target. - P3 – §2 command list. Add
check --changesetandverify-retain. - P3 – §2.2, Aurora
AWS::SecretsManager::SecretTargetAttachmenthas no Terraform equivalent; fate itmanual-cleanup(retained, then orphaned).
Sources: ResourceChange API, Metadata attribute.