Skip to content

actual code used for latest deployment on 08/26 - #820

Open
tloubrieu-jpl wants to merge 2 commits into
mainfrom
release-candidate/1.7.3-deploy
Open

actual code used for latest deployment on 08/26#820
tloubrieu-jpl wants to merge 2 commits into
mainfrom
release-candidate/1.7.3-deploy

Conversation

@tloubrieu-jpl

Copy link
Copy Markdown
Member

🗒️ Summary

Remove non working ECR Pull Through Cache which has never worked so far.
Minor fixes so that deployment worked.

🤖 AI Assistance Disclosure

  • No AI assistance used
  • AI used for light assistance (e.g., suggestions, refactoring, documentation help, minor edits)
  • AI used for moderate content generation (AI generated some code or logic, but the developer authored or heavily revised the majority)
  • AI generated substantial portions of this code

Estimated % of code influenced by AI: ___ %

⚙️ Test Data and/or Report

♻️ Related Issues

🤓 Reviewer Checklist

Reviewers: Please verify the following before approving this pull request.

Documentation and PR Content

  • Documentation: README, Wiki, or inline documentation (Sphinx, Javadoc, Docstrings) have been updated to reflect these changes.
  • Issue Traceability: The PR is linked to a valid GitHub Issue
  • PR Title: The PR title is "user-friendly" clearly identifying what is being fixed or the new feature being added, that if you saw it in the Release Notes for a tool, you would be able to get the gist of what was done.

Security & Quality

  • SonarCloud: Confirmed no new High or Critical security findings.
  • Secrets Detection: Verified that the Secrets Detection scan passed and no sensitive information (keys, tokens, PII) is exposed.
  • Code Quality: Code follows organization style guidelines and best practices for the specific language (e.g., PEP 8, Google Java Style).

Testing & Validation

  • Test Accuracy: Verified that test data is accurate, representative of real-world PDS4 scenarios, and sufficient for the logic being tested.
  • Coverage: Automated tests cover new logic and edge cases.
  • Local Verification: (If applicable) Successfully built and ran the changes in a local or staging environment.

Maintenance

  • Backward Compatibility: Confirmed that these changes do not break existing downstream dependencies or API contracts (or that breaking changes are clearly documented).

Terraform (only if this PR touches a terraform/ directory)

  • Validator run: scripts/validate_terraform.py was run against the changed terraform/ tree and any Must-Have failures were resolved (or are tracked in a reviewed .tfvalidate-ignore entry, not silently bypassed).
  • Ownership boundary: Shared/singleton CDS resources (Cognito, CloudFront, org-wide IAM roles, shared security groups) were only added/changed in pdc-cds-infra, not duplicated in an application repo.
  • Module structure: modules/ stays flat and no new module is just a thin wrapper around a single resource.
  • SSM interface: Any new cross-component output is actually published under /pds/<component>/... and, if this PR is the consumer side, reads from the correct published parameter rather than another repo's Terraform state.
  • Naming intent: Resource and variable names are semantically meaningful, not just non-redundant (the validator only checks for repeated resource-type substrings).
  • Auth at runtime: Terraform/CI actually authenticates via OIDC or an assumed role when applied — not just "no static key found in this diff."
  • Least privilege: Any new or changed IAM policy attached to the Terraform execution role grants only what this change needs.

@tloubrieu-jpl
tloubrieu-jpl requested a review from a team as a code owner August 28, 2026 14:43
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant