Repository navigation
feat: describe affected evaluates all provisioned component sections - #2573
Conversation
`atmos describe affected` compared only a hand-maintained subset of component sections (metadata, vars, env, settings, source, provision), so changes to providers, required_providers (provider versions), hooks, generate, backend, backend_type, remote_state_backend(_type), auth, command, and dependencies were never detected — a false-negative that could let CI skip components that genuinely changed. - Replace the inline per-section blocks in the terraform/helmfile/packer processors with a single table-driven comparison covering every provisioned section, including scalar sections. - Add isSectionValueEqual so scalar sections (backend_type, required_version, command, ...) are compared, not just maps. - Add describe.affected.sections config to fully override the evaluated set (metadata/settings are always evaluated). Defaults apply when unset. - locals/overrides/inheritance/retry are intentionally excluded. - Tests, docs (Evaluated sections list + config reference), blog post, and roadmap milestone. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Dependency ReviewThe following issues were found:
License Issues.github/workflows/test.yml
Scanned Files
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✅ Files skipped from review due to trivial changes (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughUnifies and centralizes component-section comparisons into a configurable pipeline used by Terraform, Helmfile, and Packer indexed processors. Adds a DescribeAffected schema ( ChangesConfigurable affected section evaluation
🎯 4 (Complex) | ⏱️ ~40 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- Add a Changelog Posts rule to the docs skill: never begin a sentence, paragraph, heading body, list item, or post intro with a backtick (inline code span) or code fence — lead with prose, then the code. - Fix the describe-affected blog post intro and two other lines that opened on a code span. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
List the default evaluated sections inline in the config reference instead of linking out to the command page, and explain replace-not-additive semantics, custom-section reasons, and why metadata/settings are always on. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…section The describe.affected config section (added in 1c55cc1) now serializes as "affected": {} in `atmos describe config` output. Regenerate the two golden snapshots that capture the full Atmos config to include it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #2573 +/- ##
==========================================
+ Coverage 78.89% 78.93% +0.03%
==========================================
Files 1207 1207
Lines 116441 116438 -3
==========================================
+ Hits 91869 91911 +42
+ Misses 19494 19455 -39
+ Partials 5078 5072 -6
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
Hooks are operational/execution-time behavior (commands that run before/after an operation, e.g. policy or cost checks), not provisioned infrastructure. A hook change should not mark a component as affected by default — same rationale as the already-excluded `retry` section. Users who want hook changes to count can opt in via `describe.affected.sections`, where hooks reports as `stack.hooks` (the generic stack.<name> fallback yields the identical reason). Docs and the feature blog post are updated to describe the default set and the opt-in. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The Check Markdown Links job failed on a single transient error: https://tldp.org/LDP/abs/html/exitcodes.html returned 502 Bad Gateway. This is a long-standing valid reference (The Linux Documentation Project, in docs/prd/exit-codes.md, unchanged on main) whose server intermittently 502s under CI's non-browser requests. Add tldp.org to the lychee exclude list alongside the other known-flaky doc sites (gnu.org, kubernetes.io, etc.). Verified locally: lychee now reports 0 errors with the link marked EXCLUDED. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Important Cloud Posse Engineering Team Review RequiredThis pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes. To expedite this process, reach out to us on Slack in the |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
.github/workflows/test.yml (1)
132-132:actions/download-artifact@v8is available;name/pathinputs match
The workflow’suses: actions/download-artifact@v8is valid (v8.0.0/v8.0.1exist), and the action interface still supports thenameandpathinputs used here (same asv4.3.0). Keep the version jump in mind, but this specific change shouldn’t break artifact downloads due to missing/renamedname/path. Consider skimming v4→v8 release notes for any behavioral/default changes (decompression/digest handling) and optionally pinning to a specific v8 release.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/test.yml at line 132, The workflow currently uses the floating tag actions/download-artifact@v8; update it to pin a specific v8 release (e.g., actions/download-artifact@v8.0.1) to ensure reproducible runs and review the action's v4→v8 release notes for any behavioral changes around decompression or digest handling; verify the existing inputs name and path still match the pinned version and adjust invocation if the action renamed or changed input semantics.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/test.yml:
- Line 76: The workflow change incorrectly removed or altered the setup-go
usage; restore and keep uses: actions/setup-go@v6 and retain the go-version-file
inputs where they were changed, and add a short inline comment near that uses
entry (and the other occurrence referencing go-version-file) that v6 requires
runner v2.327.1+ and may affect toolchain handling so CI runs should be
validated on the target runner; optionally pin to a specific v6.x release if you
want stricter stability.
In `@internal/exec/describe_affected_utils_2_test.go`:
- Around line 993-995: The final line of the multi-line comment that starts
"Fixed navigation keys for the remote-stacks fixtures below. The locator's
lookup is" is missing a trailing period; update that comment block so the last
line ends with a period to satisfy the godot linter (i.e., ensure the comment
ending the block is punctuated with a period).
---
Nitpick comments:
In @.github/workflows/test.yml:
- Line 132: The workflow currently uses the floating tag
actions/download-artifact@v8; update it to pin a specific v8 release (e.g.,
actions/download-artifact@v8.0.1) to ensure reproducible runs and review the
action's v4→v8 release notes for any behavioral changes around decompression or
digest handling; verify the existing inputs name and path still match the pinned
version and adjust invocation if the action renamed or changed input semantics.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: dcfb38ad-c32f-4725-9a74-a7d9b2e64db8
📒 Files selected for processing (3)
.github/workflows/test.ymlinternal/exec/describe_affected_utils_2_test.golychee.toml
🚧 Files skipped from review as they are similar to previous changes (1)
- lychee.toml
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/test.yml (1)
133-137:⚠️ Potential issue | 🟠 MajorHarden
actions/download-artifact@v8for self-hosted runner + digest mismatch behavior.
- Lines 133-137 (also 340-343, 404-407, 484-487): current
with: name+pathusage matches v8’saction.yml, so the input schema isn’t the likely issue.actions/download-artifact@v8runs onnode24; ensure any self-hosted runners used by this workflow meet the minimum runner requirement (v7 release notes call out 2.327.1+) or the action can fail at runtime.- v8 defaults
digest-mismatchtoerror; if you want the workflow to be tolerant of digest mismatches, setdigest-mismatch: warn|info|ignoreexplicitly.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/test.yml around lines 133 - 137, The workflow uses actions/download-artifact@v8 (the steps invoking it with name: build-artifacts-${{ matrix.flavor.target }} and path: ${{ github.workspace }}) which requires node24 and can error on older self-hosted runners; either ensure any self-hosted runner used meets the minimum GitHub Actions runner version (>= 2.327.1) or switch to a compatible runner image, and explicitly add the digest-mismatch input (e.g., digest-mismatch: warn|info|ignore) to the action invocation to control digest-mismatch behavior instead of relying on the default error mode.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/test.yml:
- Around line 133-137: The workflow uses actions/download-artifact@v8 (the steps
invoking it with name: build-artifacts-${{ matrix.flavor.target }} and path: ${{
github.workspace }}) which requires node24 and can error on older self-hosted
runners; either ensure any self-hosted runner used meets the minimum GitHub
Actions runner version (>= 2.327.1) or switch to a compatible runner image, and
explicitly add the digest-mismatch input (e.g., digest-mismatch:
warn|info|ignore) to the action invocation to control digest-mismatch behavior
instead of relying on the default error mode.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 6d9e4bc8-8600-4a07-a15d-628a2e66145d
📒 Files selected for processing (3)
.github/workflows/test.ymlinternal/exec/describe_affected_utils_2_test.golychee.toml
✅ Files skipped from review due to trivial changes (1)
- lychee.toml
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
|
Warning Release Documentation RequiredThis PR is labeled
|
|
These changes were released in v1.221.0-rc.7. |
|
These changes were released in v1.221.0. |
…atmos into 1198-pact-consumer-contracts * '1198-pact-consumer-contracts' of github.com:cloudposse/atmos: fix(ansible): forward `-- <args>` passthrough to ansible-playbook (#2594) fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs (#2598) DAG follow-up: aggregate CI output for concurrent Terraform runs (#2577) fix(list): prevent nil pointer panic when spinner exits early (#2591) feat: describe affected evaluates all provisioned component sections (#2573)
what
atmos describe affectedso it detects changes in every provisioned component section, not justvars/env/settings/metadata/source/provision.providers,required_providers(provider versions),required_version,hooks,generate,backend,backend_type,remote_state_backend,remote_state_backend_type,auth,command, anddependencies— including scalar sections (previously only map sections were compared).describe.affected.sectionssetting inatmos.yamlthat fully replaces the evaluated set (e.g. to track a custom section or narrow the list);metadata/settingsare always evaluated.why
providers,hooks, provider versions,backend, etc. were silently missed — a false negative that could let CI pipelines skip components that genuinely changed.stack_processor_merge.go, and the new config setting gives users an escape hatch so the bug class can't quietly return.locals,overrides,inheritance, andretryare intentionally excluded (they either fold into other sections or are execution-time only).references
describe.affected.sectionsSummary by CodeRabbit
New Features
Documentation
Tests
Chores