Skip to content

fix(auth): normalize --identity=false to disable authentication - #2412

Merged
Andriy Knysh (aknysh) merged 6 commits into
mainfrom
osterman/fix-identity-false-flag
May 16, 2026
Merged

Andriy Knysh (aknysh) merged 6 commits into
mainfrom
osterman/fix-identity-false-flag

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented May 15, 2026 •

Copy link
Copy Markdown
Member

what

  • Normalize boolean-false values (false, 0, no, off, case-insensitive) passed via --identity=<value> and --identity <value> to the disabled sentinel (cfg.IdentityFlagDisabledValue), so the auth pre-hook and CreateAndAuthenticateManager* short-circuit instead of trying to authenticate with the literal name "false".
  • Patch is in internal/exec/cli_utils.go::parseIdentityFlag — the single arg-walker that feeds info.Identity / configAndStacksInfo.Identity for every ProcessCommandLineArgs consumer (terraform, helmfile, packer, list, describe, workflow, vendor, pro, validate, atlantis, docs, generate).
  • Add parser-level unit cases in TestParseIdentityFlag for =false / =False / =FALSE / =0 / =no / =off plus space-separated form, and end-to-end cases in TestProcessArgsAndFlags_IdentityFlag{,Helmfile,Packer} asserting info.Identity == cfg.IdentityFlagDisabledValue.

why

  • Regression: ATMOS_IDENTITY=false was fixed in fix(auth): normalize ATMOS_IDENTITY=false (issue #1931) #1935 by normalizing the env-var fallback at cli_utils.go:199, but the env fallback only runs when Identity == "". When --identity=false is passed on the CLI, parseIdentityFlag populated the literal "false", the env-fallback branch was skipped, and the literal flowed through to pkg/auth/hooks.go::isAuthenticationDisabled (which only matches __DISABLED__).
  • refactor(cli_utils): DRY processArgsAndFlags with table-driven flag parsing, 100% unit test coverage #2225 extracted parseIdentityFlag into a new helper without porting the normalization from the env path, silently breaking the documented --identity=false contract. Reported by users for atmos terraform * and atmos list instances.
  • Centralizing normalization at the parse site means every command sharing ProcessCommandLineArgs is fixed in one place, and matches the behavior already implemented for the StandardParser path (pkg/flags/global_registry.go) and the cmd/identity_helpers.go / cmd/list/utils.go / cmd/list/affected.go per-command identity reads.

references

Summary by CodeRabbit

  • Bug Fixes

    • The --identity flag now recognizes common boolean-false values (false, 0, no, off, case-insensitive) to disable authentication.
  • New Features

    • Passing --identity=false (or equivalent) disables per-component auth resolution and is honored across describe, list, and state-resolution flows.
    • Describe and list commands now surface and propagate an "auth disabled" option so outputs respect disabled auth.
  • Tests

    • Expanded tests for identity parsing and auth-disabled behavior across commands, env vars, and execution paths.

Review Change Stack

`--identity=false` (and `=0`, `=no`, `=off`, case-insensitive) was reaching
auth hooks as the literal string "false" instead of the disabled sentinel,
so authentication was not skipped. The env-var path (`ATMOS_IDENTITY=false`)
already normalized correctly; the flag path regressed when
`internal/exec/cli_utils.go::parseIdentityFlag` was extracted in #2225 and
the new helper omitted the call to `cfg.NormalizeIdentityValue`.

Apply normalization to both value branches (`--identity=value` and
`--identity value`) so every `ProcessCommandLineArgs` consumer
(terraform / helmfile / packer / list / describe / workflow / …) receives
the disabled sentinel and short-circuits auth. Add parser-level and
end-to-end unit tests covering all boolean-false spellings.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@atmos-pro

atmos-pro Bot commented May 15, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More.

@github-actions github-actions Bot added the size/s Small size PR label May 15, 2026
@github-actions

github-actions Bot commented May 15, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

atmos-pro[bot]
atmos-pro Bot previously approved these changes May 15, 2026

@atmos-pro atmos-pro Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no affected stacks, therefore this is approved by Atmos Pro.

@coderabbitai

coderabbitai Bot commented May 15, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 9f352aae-adff-40ad-a144-2eb8cfc0d4ac

📥 Commits

Reviewing files that changed from the base of the PR and between adb1a68 and 161b00a.

📒 Files selected for processing (1)
  • pkg/list/list_instances_authdisabled_test.go
🚧 Files skipped from review as they are similar to previous changes (1)
  • pkg/list/list_instances_authdisabled_test.go

📝 Walkthrough

Walkthrough

The PR normalizes --identity inputs (both --identity=value and --identity value) to detect false-like values as the disabled sentinel, then threads an AuthDisabled boolean through command parsing, describe/stacks processors, Terraform state resolution, YAML terraform-state handling, and list instances execution; tests added/updated across unit and integration suites.

Changes

AuthDisabled propagation and identity normalization

Layer / File(s) Summary
Identity parsing and tests
internal/exec/cli_utils.go, internal/exec/cli_utils_helpers_test.go, internal/exec/cli_utils_identity_test.go
parseIdentityFlag now normalizes both equals and space forms via cfg.NormalizeIdentityValue. Tests extended to assert false-like inputs (false, 0, no, off, case variants) normalize to cfg.IdentityFlagDisabledValue.
Command lookup, instances options, and tests
cmd/list/utils.go, cmd/list/utils_test.go, cmd/list/instances.go
Add lookupChangedIdentityFlag and robust getIdentityFromCommand normalization; add InstancesOptions.AuthDisabled and set it when identity equals the disabled sentinel; tests cover inherited flags and ATMOS_IDENTITY env normalization.
Describe component params and schema
internal/exec/describe_component.go, pkg/schema/schema.go
Add AuthDisabled to DescribeComponentParams / execute/context params and set ConfigAndStacksInfo.AuthDisabled so downstream code observes auth-disabled state.
Describe stacks processor and wrappers
internal/exec/describe_stacks.go, internal/exec/describe_stacks_component_processor.go, internal/exec/describe_stacks_component_processor_auth_test.go, internal/exec/stacks_processor.go
Introduce ExecuteDescribeStacksWithAuthDisabled, add authDisabled to describeStacksProcessor, short-circuit per-component auth resolution when authDisabled is true, propagate info.AuthDisabled, and add tests for the auth-disabled path.
Terraform state and YAML integration
internal/exec/terraform_state_utils.go, internal/exec/yaml_func_terraform_state.go
Compute authDisabled from parent stack info and skip nested component auth resolution when disabled; pass AuthDisabled into component describe params and ensure YAML terraform-state uses an authContextWrapper when auth is disabled and authManager is nil.
List instances execution flow and tests
pkg/list/list_instances.go, internal/exec/stacks_processor_test.go, pkg/list/list_instances_authdisabled_test.go
Add AuthDisabled to InstancesCommandOptions; refactor instance processing to call auth-disabled-aware helpers and to use ExecuteDescribeStacksWithAuthDisabled when available, threading the flag through tree, matrix, and non-tree output paths; add tests verifying dispatch and fallback behavior.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

  • cloudposse/atmos#1935: Implements/consumes consistent --identity/ATMOS_IDENTITY false-value normalization and related parsing changes.
  • cloudposse/atmos#1900: Concurrent updates to identity flag parsing normalizing false-like inputs to the disabled sentinel.
  • cloudposse/atmos#2411: Related changes to per-component auth resolution which interact with authDisabled control flow.

Suggested reviewers

  • aknysh
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the main fix: normalizing --identity=false to disable authentication. It's concise, specific, and directly reflects the central change across multiple commands.
Docstring Coverage ✅ Passed Docstring coverage is 86.11% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/fix-identity-false-flag

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

coderabbitai[bot]
coderabbitai Bot previously approved these changes May 15, 2026
@codecov

codecov Bot commented May 15, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.82609% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 78.10%. Comparing base (e21a28c) to head (161b00a).

Files with missing lines Patch % Lines
internal/exec/yaml_func_terraform_state.go 66.66% 1 Missing and 1 partial ⚠️
internal/exec/describe_component.go 75.00% 1 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2412      +/-   ##
==========================================
+ Coverage   78.06%   78.10%   +0.04%     
==========================================
  Files        1110     1110              
  Lines      104673   104784     +111     
==========================================
+ Hits        81713    81842     +129     
+ Misses      18425    18399      -26     
- Partials     4535     4543       +8     
Flag Coverage Δ
unittests 78.10% <97.82%> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
cmd/list/instances.go 62.10% <100.00%> (+1.23%) ⬆️
cmd/list/utils.go 73.33% <100.00%> (+2.13%) ⬆️
internal/exec/cli_utils.go 96.01% <100.00%> (ø)
internal/exec/describe_stacks.go 98.23% <100.00%> (+0.09%) ⬆️
...ternal/exec/describe_stacks_component_processor.go 95.85% <100.00%> (+0.11%) ⬆️
internal/exec/stacks_processor.go 100.00% <100.00%> (ø)
internal/exec/terraform_state_utils.go 79.76% <100.00%> (+2.73%) ⬆️
pkg/list/list_instances.go 87.66% <100.00%> (+1.77%) ⬆️
pkg/schema/schema.go 87.70% <ø> (ø)
internal/exec/describe_component.go 67.98% <75.00%> (+0.09%) ⬆️
... and 1 more

... and 9 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@osterman Erik Osterman (Cloud Posse) (osterman) added the patch A minor, backward compatible change label May 15, 2026
@github-actions github-actions Bot added size/m Medium size PR and removed size/s Small size PR labels May 15, 2026
atmos-pro[bot]
atmos-pro Bot previously approved these changes May 15, 2026

@atmos-pro atmos-pro Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no affected stacks, therefore this is approved by Atmos Pro.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
internal/exec/describe_stacks_component_processor_auth_test.go (1)

60-61: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Run go-fumpt on this file before merge.

CI is currently failing pre-commit because this test file is not in go-fumpt format.

As per coding guidelines: “Follow standard Go coding style: use gofmt and goimports to format code, prefer short descriptive variable names, use kebab-case for command-line flags, and snake_case for environment variables.”.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/describe_stacks_component_processor_auth_test.go` around lines
60 - 61, This test file is not formatted with gofumpt; run gofumpt (or gofumpt
-w) on internal/exec/describe_stacks_component_processor_auth_test.go to
reformat it so it passes pre-commit CI (the failing line is around the test
declaration using t.Parallel()); ensure imports and spacing follow gofumpt rules
and re-run tests/commit.
🧹 Nitpick comments (1)
internal/exec/terraform_state_utils.go (1)

98-110: 💤 Low value

Redundant fallback assignment.

Line 108 re-assigns resolvedAuthMgr = parentAuthMgr, but it was already set to parentAuthMgr on line 98. The assignment in the error branch is unnecessary.

Suggested simplification
 	resolvedAuthMgr := parentAuthMgr
 	if !authDisabled {
 		var err error
 		resolvedAuthMgr, err = resolveAuthManagerForNestedComponent(atmosConfig, component, stack, parentAuthMgr)
 		if err != nil {
 			log.Debug("Auth does not exist for nested component, using parent AuthManager",
 				"component", component,
 				"stack", stack,
 				"error", err,
 			)
-			resolvedAuthMgr = parentAuthMgr
 		}
 	}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/terraform_state_utils.go` around lines 98 - 110, The code
redundantly reassigns resolvedAuthMgr to parentAuthMgr in the error branch even
though resolvedAuthMgr is already initialized to parentAuthMgr; update the error
handling inside the if !authDisabled block to simply log the error and leave
resolvedAuthMgr untouched (remove the duplicate assignment), keeping the call to
resolveAuthManagerForNestedComponent and variables atmosConfig, component,
stack, authDisabled, parentAuthMgr and resolvedAuthMgr intact so the fallback
behavior remains implicit.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@internal/exec/describe_stacks_component_processor_auth_test.go`:
- Around line 60-61: This test file is not formatted with gofumpt; run gofumpt
(or gofumpt -w) on
internal/exec/describe_stacks_component_processor_auth_test.go to reformat it so
it passes pre-commit CI (the failing line is around the test declaration using
t.Parallel()); ensure imports and spacing follow gofumpt rules and re-run
tests/commit.

---

Nitpick comments:
In `@internal/exec/terraform_state_utils.go`:
- Around line 98-110: The code redundantly reassigns resolvedAuthMgr to
parentAuthMgr in the error branch even though resolvedAuthMgr is already
initialized to parentAuthMgr; update the error handling inside the if
!authDisabled block to simply log the error and leave resolvedAuthMgr untouched
(remove the duplicate assignment), keeping the call to
resolveAuthManagerForNestedComponent and variables atmosConfig, component,
stack, authDisabled, parentAuthMgr and resolvedAuthMgr intact so the fallback
behavior remains implicit.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: e9c861b7-70ca-44ef-a8a2-377dfaff8d2e

📥 Commits

Reviewing files that changed from the base of the PR and between b45575a and 53c2231.

📒 Files selected for processing (12)
  • cmd/list/instances.go
  • cmd/list/utils.go
  • cmd/list/utils_test.go
  • internal/exec/describe_component.go
  • internal/exec/describe_stacks.go
  • internal/exec/describe_stacks_component_processor.go
  • internal/exec/describe_stacks_component_processor_auth_test.go
  • internal/exec/stacks_processor.go
  • internal/exec/terraform_state_utils.go
  • internal/exec/yaml_func_terraform_state.go
  • pkg/list/list_instances.go
  • pkg/schema/schema.go

coderabbitai[bot]
coderabbitai Bot previously approved these changes May 15, 2026
atmos-pro[bot]
atmos-pro Bot previously approved these changes May 15, 2026

@atmos-pro atmos-pro Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no affected stacks, therefore this is approved by Atmos Pro.

coderabbitai[bot]
coderabbitai Bot previously approved these changes May 15, 2026
Andriy Knysh (aknysh) and others added 2 commits May 15, 2026 19:43
…-false-flag

# Conflicts:
#	internal/exec/describe_stacks_component_processor.go
Coverage report showed 30 missing lines on the PR; 26 of them were in the
auth-disabled wiring added for `--identity=false`. Pure pass-through and
test-seam code that wasn't reachable from existing test fixtures.

* internal/exec/stacks_processor_test.go:
  TestDefaultStacksProcessor_ExecuteDescribeStacksWithAuthDisabled — table
  drives authDisabled=true and authDisabled=false through the new
  pass-through method, mirroring the existing
  TestDefaultStacksProcessor_ExecuteDescribeStacks empty-fixture pattern.
  Lifts the function from 0% to 100% (15 missing lines recovered).

* pkg/list/list_instances_authdisabled_test.go (new):
  Hand-written fakes for the unexported authDisabledStacksProcessor
  interface (the gomock MockStacksProcessor only models the public
  interface; the auth-disabled method is an optional capability
  type-asserted at runtime).

  - TestExecuteDescribeStacksForInstances_AuthDisabledDispatchesToAuthDisabledMethod
    pins authDisabled=true + capable processor → auth-disabled method.
  - TestExecuteDescribeStacksForInstances_AuthDisabledFalseUsesRegularPath
    pins authDisabled=false → regular ExecuteDescribeStacks even when
    the optional interface is implemented.
  - TestExecuteDescribeStacksForInstances_FallsBackWhenInterfaceNotImplemented
    safety-net: authDisabled=true with a non-capable processor must
    fall back to ExecuteDescribeStacks rather than panic on a failed
    type assertion.
  - TestProcessInstancesWithDepsAuthDisabled_PropagatesAuthDisabledFlag
    end-to-end through the helper with a realistic stacks map.
  - TestProcessInstancesWithAuthDisabled_ConstructsDefaultProcessor
    smoke test for the production wrapper.

  Lifts processInstancesWithDepsAuthDisabled, executeDescribeStacksForInstances,
  and processInstancesWithAuthDisabled from <80% to 100% each.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
atmos-pro[bot]
atmos-pro Bot previously approved these changes May 16, 2026

@atmos-pro atmos-pro Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no affected stacks, therefore this is approved by Atmos Pro.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/list/list_instances_authdisabled_test.go`:
- Around line 219-233: The test currently constructs an empty
schema.AtmosConfiguration and calls processInstancesWithAuthDisabled, which lets
path resolution rely on ambient defaults and can make assert.Empty flaky; fix by
making the config deterministic: create a schema.AtmosConfiguration with its
stacks path(s) explicitly set to an isolated non-existent or temporary directory
(or an empty temp dir) before calling processInstancesWithAuthDisabled so
ExecuteDescribeStacksWithAuthDisabled cannot find any stacks; this ensures
instances is always empty and the test is stable.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: d1d50437-0560-4529-b41b-62e7631d4545

📥 Commits

Reviewing files that changed from the base of the PR and between 85d9f1e and adb1a68.

📒 Files selected for processing (4)
  • internal/exec/describe_stacks_component_processor.go
  • internal/exec/describe_stacks_component_processor_auth_test.go
  • internal/exec/stacks_processor_test.go
  • pkg/list/list_instances_authdisabled_test.go
🚧 Files skipped from review as they are similar to previous changes (2)
  • internal/exec/describe_stacks_component_processor_auth_test.go
  • internal/exec/describe_stacks_component_processor.go

Comment thread pkg/list/list_instances_authdisabled_test.go Outdated
…pDir

CodeRabbit flagged the smoke test as ambient-state-dependent: with an
empty AtmosConfiguration the underlying FindStacksMap resolves CWD-relative
empty BasePath/Stacks.BasePath, so the assertion that the collector returns
zero instances depends on whatever happens to exist in the test runner's
CWD.

The fix matches the existing convention in
TestDefaultStacksProcessor_ExecuteDescribeStacks
(internal/exec/stacks_processor_test.go:14-27) and the CLAUDE.md guidance
to anchor file-discovery tests to an absolute path: set BasePath to
t.TempDir() and give the relative Stacks/Components paths explicit values.
The temp dir is empty, so the empty-instances assertion is now guaranteed
regardless of CWD or filesystem state.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

@atmos-pro atmos-pro Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There were no affected stacks, therefore this is approved by Atmos Pro.

@aknysh
Andriy Knysh (aknysh) merged commit b7084f6 into main May 16, 2026
58 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/fix-identity-false-flag branch May 16, 2026 01:53
@atmos-pro

atmos-pro Bot commented May 16, 2026

Copy link
Copy Markdown
Contributor

Note

Atmos Pro  

Waiting for your GitHub Actions workflow to upload affected stacks.
Learn More.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.218.1-rc.1.

Andriy Knysh (aknysh) added a commit that referenced this pull request May 22, 2026
…#2471)

* fix(auth): honor --identity=false in describe affected and dependents

`--identity=false` (and aliases `off`/`0`/`no`) normalized correctly at the
parser layer in 1.219 (PR #2412), but the disabled signal was only wired
through `list instances`. In `describe affected`, the top-level AuthManager
correctly became nil, but a nil AuthManager was indistinguishable from "no
identity specified" downstream — so the per-component auth resolver still
ran whenever `processTemplates` was true (its default), reintroducing the
AssumeRoleWithWebIdentity call the user tried to disable.

Thread an `AuthDisabled bool` from the cmd layer through
`executeDescribeAffectedWith*`, `executeDescribeAffected`,
`addDependentsToAffected`, and `ExecuteDescribeDependents`, routing inner
stack resolution through `ExecuteDescribeStacksWithAuthDisabled` so
`processor.authDisabled=true` short-circuits the per-component resolver.

Also propagated through `terraform_affected.go`,
`terraform_affected_graph.go`, `pkg/list/list_affected.go`,
`pkg/ai/tools/atmos/describe_affected.go`, and
`atlantis_generate_repo_config.go` call sites. Extracted
`pkg/list/list_affected.go::executeAffectedLogic` into three per-mode
helpers to stay under the 60-line function-length limit.

Tests:
- cmd/describe_affected_test.go::TestDescribeAffectedSetsAuthDisabled
  verifies `false`/`off`/`0`/`no` env values set `AuthDisabled=true` and
  `AuthManager=nil`.
- internal/exec/describe_affected_authdisabled_test.go verifies
  `Execute()` forwards `AuthDisabled` to all three helper paths and to
  `addDependentsToAffected`.
- describe_stacks_component_processor_auth_test.go adds the exact
  `(processTemplates=true, processYamlFunctions=false, authDisabled=true)`
  regression case from the infra-live CI failure.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* style: apply CI go-fumpt formatting

Address pre-commit hook failures from PR #2471 CI run. The newer gofumpt
in CI flagged formatting in four files I touched in the previous commit:

- pkg/list/list_affected.go — split `})` from inline closure into
  `},` + `)` on separate lines.
- internal/exec/describe_affected_utils.go — split the long log.Warn
  message into its own line in two greenfield-handling branches.
- internal/exec/atlantis_generate_repo_config.go — split trailing args
  in two errors.Errorf calls onto their own lines.
- internal/exec/describe_affected_utils_2.go — remove redundant parens
  from `&((*slice)[i])` → `&(*slice)[i]` in four loop bodies.

No behavior change.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(auth): propagate AuthDisabled through DescribeDependentsExecProps

Address CodeRabbit review on PR #2471. The previous commit added
`AuthDisabled` to `DescribeDependentsArgs` but missed adding it to
`DescribeDependentsExecProps`, which is the type that `describe dependents`
constructs from CLI flags and passes to `describeDependentsExec.Execute`.
The executor then built a `DescribeDependentsArgs` without the flag, so the
inner `ExecuteDescribeStacksWithAuthDisabled` always received
`authDisabled=false` — re-introducing the per-component auth attempt for
`atmos describe dependents --identity=false`.

- internal/exec/describe_dependents.go: add `AuthDisabled` to
  `DescribeDependentsExecProps` and forward it into `DescribeDependentsArgs`
  inside `describeDependentsExec.Execute`.
- cmd/describe_dependents.go: set `describe.AuthDisabled` from the
  normalized identity name, mirroring the wiring in `cmd/describe_affected.go`.

Tests:
- cmd/describe_dependents_test.go::TestDescribeDependentsSetsAuthDisabled —
  table covers `false`/`off`/`0`/`no` env spellings.
- internal/exec/describe_dependents_authdisabled_test.go —
  TestDescribeDependentsExec_Execute_ForwardsAuthDisabled pins the
  executor-side prop → arg propagation.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Andriy Knysh <aknysh@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants