Skip to content

feat: describe affected evaluates all provisioned component sections - #2573

Merged
Andriy Knysh (aknysh) merged 11 commits into
mainfrom
osterman/affected-providers-bug
Jun 9, 2026
Merged

Andriy Knysh (aknysh) merged 11 commits into
mainfrom
osterman/affected-providers-bug

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jun 5, 2026 •

Copy link
Copy Markdown
Member

what

  • Fix atmos describe affected so it detects changes in every provisioned component section, not just vars/env/settings/metadata/source/provision.
  • Newly evaluated sections: providers, required_providers (provider versions), required_version, hooks, generate, backend, backend_type, remote_state_backend, remote_state_backend_type, auth, command, and dependencies — including scalar sections (previously only map sections were compared).
  • Add a configurable describe.affected.sections setting in atmos.yaml that fully replaces the evaluated set (e.g. to track a custom section or narrow the list); metadata/settings are always evaluated.
  • Refactor the three component processors to a single table-driven comparison, add a documented "Evaluated sections" list, tests, a changelog blog post, and a roadmap milestone.

why

  • The comparison ran against a hand-maintained allow-list that had drifted out of sync with what Atmos actually merges into a component, so changes to providers, hooks, provider versions, backend, etc. were silently missed — a false negative that could let CI pipelines skip components that genuinely changed.
  • The table is now tied (via comments) to the sections written in stack_processor_merge.go, and the new config setting gives users an escape hatch so the bug class can't quietly return.
  • locals, overrides, inheritance, and retry are intentionally excluded (they either fold into other sections or are execution-time only).

references

Summary by CodeRabbit

  • New Features

    • Describe now evaluates and reports changes across a comprehensive set of top-level component sections (including scalar sections) with per-section reasons; first changed section becomes the headline reason.
    • Added configurable describe.affected.sections to fully replace the default evaluated set (metadata/settings remain always evaluated).
  • Documentation

    • Blog and CLI/config docs updated with evaluated-sections details, output reason entries, and configuration examples.
  • Tests

    • Added tests for section evaluation, equality behavior, remote-locator logic, and override/no-false-positive cases.
  • Chores

    • Updated snapshots, roadmap, CI workflow pins, link-checker exclusions, and changelog guidance.

`atmos describe affected` compared only a hand-maintained subset of
component sections (metadata, vars, env, settings, source, provision),
so changes to providers, required_providers (provider versions), hooks,
generate, backend, backend_type, remote_state_backend(_type), auth,
command, and dependencies were never detected — a false-negative that
could let CI skip components that genuinely changed.

- Replace the inline per-section blocks in the terraform/helmfile/packer
  processors with a single table-driven comparison covering every
  provisioned section, including scalar sections.
- Add isSectionValueEqual so scalar sections (backend_type,
  required_version, command, ...) are compared, not just maps.
- Add describe.affected.sections config to fully override the evaluated
  set (metadata/settings are always evaluated). Defaults apply when unset.
- locals/overrides/inheritance/retry are intentionally excluded.
- Tests, docs (Evaluated sections list + config reference), blog post,
  and roadmap milestone.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@atmos-pro

atmos-pro Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@osterman Erik Osterman (Cloud Posse) (osterman) added the minor New features that do not break anything label Jun 5, 2026
@github-actions github-actions Bot added the size/m Medium size PR label Jun 5, 2026
@github-actions

github-actions Bot commented Jun 5, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 5 package(s) with unknown licenses.
See the Details below.

License Issues

.github/workflows/test.yml

PackageVersionLicenseIssue Type
actions/download-artifact8.*.*NullUnknown License
actions/setup-go6.*.*NullUnknown License
codecov/codecov-action7.*.*NullUnknown License
hashicorp/setup-terraform4.*.*NullUnknown License
opentofu/setup-opentofu2.*.*NullUnknown License
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-2-Clause, BSD-2-Clause-Views, BSD-3-Clause, ISC, MPL-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, Python-2.0, OFL-1.1, LicenseRef-scancode-generic-cla, LicenseRef-scancode-unknown-license-reference, LicenseRef-scancode-unicode, LicenseRef-scancode-google-patent-license-golang
Excluded from license check: pkg:golang/modernc.org/libc

Scanned Files

  • .github/workflows/test.yml

@coderabbitai

coderabbitai Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: b7bf8589-1f25-469d-a513-529ae98f7aa7

📥 Commits

Reviewing files that changed from the base of the PR and between 37147db and f7d5cdf.

📒 Files selected for processing (2)
  • .github/workflows/test.yml
  • website/src/data/roadmap.js
✅ Files skipped from review due to trivial changes (1)
  • website/src/data/roadmap.js
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/test.yml

📝 Walkthrough

Walkthrough

Unifies and centralizes component-section comparisons into a configurable pipeline used by Terraform, Helmfile, and Packer indexed processors. Adds a DescribeAffected schema (describe.affected.sections) to override evaluated sections, updates equality helpers and tests, and documents the evaluated sections and config surface.

Changes

Configurable affected section evaluation

Layer / File(s) Summary
Configuration schema and types
pkg/schema/schema.go
DescribeAffected struct adds Sections []string; Describe type extended with Affected field to bind describe.affected.sections.
Section-comparison infrastructure and helpers
internal/exec/describe_affected_components.go, internal/exec/describe_affected_utils_2.go
Adds affected-reason constants and ordered sectionCheck defaults; resolveComponentSectionChecks builds effective checks from config (unknown names map to stack.<name>); checkComponentSections iterates and records differences; remoteComponentLocator and isSectionValueEqual centralize remote lookup and equality logic.
Processor integration across platforms
internal/exec/describe_affected_components.go
Terraform, Helmfile, and Packer indexed processors replace bespoke per-section checks with checkComponentSections(...); settings and dependency checks still use checkSettingsAndDependenciesIndexed.
Comprehensive section-diff test suite
internal/exec/describe_affected_components_test.go, internal/exec/describe_affected_utils_2_test.go
Table-driven tests validate built-in Terraform section evaluation and reported affected reasons, assert no false positives for identical/empty/absent sections, verify describe.affected.sections override semantics, and add unit tests for remote locator and section equality.
User documentation and roadmap
website/docs/cli/commands/describe/describe-affected.mdx, website/docs/cli/configuration/describe.mdx, website/blog/2026-06-05-describe-affected-all-sections.mdx, website/src/data/roadmap.js
Document evaluated vs intentionally excluded sections, describe describe.affected.sections (authoritative override), publish blog announcing behavior, and update roadmap progress/milestone.
Snapshots and contributor docs
.claude/skills/docs/SKILL.md, tests/snapshots/*
Add changelog-post guidance and update CLI golden snapshots to include the new affected config block in outputs.
CI workflow updates
.github/workflows/test.yml
Bump multiple GitHub Action step versions (setup-go, download-artifact, setup-terraform, setup-opentofu, codecov).
Link checker
lychee.toml
Add tldp.org to Lychee exclude patterns with comment.

🎯 4 (Complex) | ⏱️ ~40 minutes

Possibly related PRs

  • cloudposse/atmos#2127: Related to stack.dependencies extraction/propagation which affects values compared by the new section-diff logic.
  • cloudposse/atmos#2061: Overlaps on source/provision change detection now folded into the shared section-comparison pipeline.
  • cloudposse/atmos#1267: Related affected_all semantics and describe-affected output adjustments.

Suggested reviewers

  • aknysh
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and specifically describes the main change: expanding atmos describe affected to evaluate all provisioned component sections rather than a limited subset.
Docstring Coverage ✅ Passed Docstring coverage is 92.86% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/affected-providers-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 5, 2026
- Add a Changelog Posts rule to the docs skill: never begin a sentence,
  paragraph, heading body, list item, or post intro with a backtick
  (inline code span) or code fence — lead with prose, then the code.
- Fix the describe-affected blog post intro and two other lines that
  opened on a code span.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
List the default evaluated sections inline in the config reference instead
of linking out to the command page, and explain replace-not-additive
semantics, custom-section reasons, and why metadata/settings are always on.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…section

The describe.affected config section (added in 1c55cc1) now serializes
as "affected": {} in `atmos describe config` output. Regenerate the two
golden snapshots that capture the full Atmos config to include it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 5, 2026
@codecov

codecov Bot commented Jun 5, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.40580% with 8 lines in your changes missing coverage. Please review.
✅ Project coverage is 78.93%. Comparing base (ad569a0) to head (f7d5cdf).

Files with missing lines Patch % Lines
internal/exec/describe_affected_components.go 84.00% 4 Missing and 4 partials ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2573      +/-   ##
==========================================
+ Coverage   78.89%   78.93%   +0.03%     
==========================================
  Files        1207     1207              
  Lines      116441   116438       -3     
==========================================
+ Hits        91869    91911      +42     
+ Misses      19494    19455      -39     
+ Partials     5078     5072       -6     
Flag Coverage Δ
unittests 78.93% <88.40%> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
internal/exec/describe_affected_utils_2.go 79.26% <100.00%> (+0.94%) ⬆️
pkg/schema/schema.go 87.70% <ø> (ø)
internal/exec/describe_affected_components.go 66.78% <84.00%> (+2.85%) ⬆️

... and 7 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Hooks are operational/execution-time behavior (commands that run
before/after an operation, e.g. policy or cost checks), not provisioned
infrastructure. A hook change should not mark a component as affected by
default — same rationale as the already-excluded `retry` section.

Users who want hook changes to count can opt in via
`describe.affected.sections`, where hooks reports as `stack.hooks` (the
generic stack.<name> fallback yields the identical reason). Docs and the
feature blog post are updated to describe the default set and the opt-in.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 8, 2026
The Check Markdown Links job failed on a single transient error:
https://tldp.org/LDP/abs/html/exitcodes.html returned 502 Bad Gateway.
This is a long-standing valid reference (The Linux Documentation Project,
in docs/prd/exit-codes.md, unchanged on main) whose server intermittently
502s under CI's non-browser requests.

Add tldp.org to the lychee exclude list alongside the other known-flaky
doc sites (gnu.org, kubernetes.io, etc.). Verified locally: lychee now
reports 0 errors with the link marked EXCLUDED.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 8, 2026
@mergify

mergify Bot commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
.github/workflows/test.yml (1)

132-132: actions/download-artifact@v8 is available; name/path inputs match
The workflow’s uses: actions/download-artifact@v8 is valid (v8.0.0/v8.0.1 exist), and the action interface still supports the name and path inputs used here (same as v4.3.0). Keep the version jump in mind, but this specific change shouldn’t break artifact downloads due to missing/renamed name/path. Consider skimming v4→v8 release notes for any behavioral/default changes (decompression/digest handling) and optionally pinning to a specific v8 release.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/test.yml at line 132, The workflow currently uses the
floating tag actions/download-artifact@v8; update it to pin a specific v8
release (e.g., actions/download-artifact@v8.0.1) to ensure reproducible runs and
review the action's v4→v8 release notes for any behavioral changes around
decompression or digest handling; verify the existing inputs name and path still
match the pinned version and adjust invocation if the action renamed or changed
input semantics.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/test.yml:
- Line 76: The workflow change incorrectly removed or altered the setup-go
usage; restore and keep uses: actions/setup-go@v6 and retain the go-version-file
inputs where they were changed, and add a short inline comment near that uses
entry (and the other occurrence referencing go-version-file) that v6 requires
runner v2.327.1+ and may affect toolchain handling so CI runs should be
validated on the target runner; optionally pin to a specific v6.x release if you
want stricter stability.

In `@internal/exec/describe_affected_utils_2_test.go`:
- Around line 993-995: The final line of the multi-line comment that starts
"Fixed navigation keys for the remote-stacks fixtures below. The locator's
lookup is" is missing a trailing period; update that comment block so the last
line ends with a period to satisfy the godot linter (i.e., ensure the comment
ending the block is punctuated with a period).

---

Nitpick comments:
In @.github/workflows/test.yml:
- Line 132: The workflow currently uses the floating tag
actions/download-artifact@v8; update it to pin a specific v8 release (e.g.,
actions/download-artifact@v8.0.1) to ensure reproducible runs and review the
action's v4→v8 release notes for any behavioral changes around decompression or
digest handling; verify the existing inputs name and path still match the pinned
version and adjust invocation if the action renamed or changed input semantics.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: dcfb38ad-c32f-4725-9a74-a7d9b2e64db8

📥 Commits

Reviewing files that changed from the base of the PR and between 02d927a and f8f8775.

📒 Files selected for processing (3)
  • .github/workflows/test.yml
  • internal/exec/describe_affected_utils_2_test.go
  • lychee.toml
🚧 Files skipped from review as they are similar to previous changes (1)
  • lychee.toml

Comment thread .github/workflows/test.yml
Comment thread internal/exec/describe_affected_utils_2_test.go

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/test.yml (1)

133-137: ⚠️ Potential issue | 🟠 Major

Harden actions/download-artifact@v8 for self-hosted runner + digest mismatch behavior.

  • Lines 133-137 (also 340-343, 404-407, 484-487): current with: name + path usage matches v8’s action.yml, so the input schema isn’t the likely issue.
  • actions/download-artifact@v8 runs on node24; ensure any self-hosted runners used by this workflow meet the minimum runner requirement (v7 release notes call out 2.327.1+) or the action can fail at runtime.
  • v8 defaults digest-mismatch to error; if you want the workflow to be tolerant of digest mismatches, set digest-mismatch: warn|info|ignore explicitly.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/test.yml around lines 133 - 137, The workflow uses
actions/download-artifact@v8 (the steps invoking it with name:
build-artifacts-${{ matrix.flavor.target }} and path: ${{ github.workspace }})
which requires node24 and can error on older self-hosted runners; either ensure
any self-hosted runner used meets the minimum GitHub Actions runner version (>=
2.327.1) or switch to a compatible runner image, and explicitly add the
digest-mismatch input (e.g., digest-mismatch: warn|info|ignore) to the action
invocation to control digest-mismatch behavior instead of relying on the default
error mode.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/test.yml:
- Around line 133-137: The workflow uses actions/download-artifact@v8 (the steps
invoking it with name: build-artifacts-${{ matrix.flavor.target }} and path: ${{
github.workspace }}) which requires node24 and can error on older self-hosted
runners; either ensure any self-hosted runner used meets the minimum GitHub
Actions runner version (>= 2.327.1) or switch to a compatible runner image, and
explicitly add the digest-mismatch input (e.g., digest-mismatch:
warn|info|ignore) to the action invocation to control digest-mismatch behavior
instead of relying on the default error mode.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 6d9e4bc8-8600-4a07-a15d-628a2e66145d

📥 Commits

Reviewing files that changed from the base of the PR and between 02d927a and 9cacd0a.

📒 Files selected for processing (3)
  • .github/workflows/test.yml
  • internal/exec/describe_affected_utils_2_test.go
  • lychee.toml
✅ Files skipped from review due to trivial changes (1)
  • lychee.toml

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 9, 2026
@aknysh
Andriy Knysh (aknysh) merged commit 12859a0 into main Jun 9, 2026
61 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/affected-providers-bug branch June 9, 2026 23:09
@atmos-pro

atmos-pro Bot commented Jun 9, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@mergify mergify Bot removed the needs-cloudposse Needs Cloud Posse assistance label Jun 9, 2026
@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown

Warning

Release Documentation Required

This PR is labeled minor or major and requires documentation updates:

  • Changelog entry - Add a blog post in website/blog/YYYY-MM-DD-feature-name.mdx
  • Roadmap update - Update website/src/data/roadmap.js with the new milestone

Alternatively: If this change doesn't require release documentation, remove the minor or major label.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.221.0-rc.7.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.221.0.

Igor Rodionov (goruha) added a commit that referenced this pull request Jun 11, 2026
…atmos into 1198-pact-consumer-contracts

* '1198-pact-consumer-contracts' of github.com:cloudposse/atmos:
  fix(ansible): forward `-- <args>` passthrough to ansible-playbook (#2594)
  fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs (#2598)
  DAG follow-up: aggregate CI output for concurrent Terraform runs (#2577)
  fix(list): prevent nil pointer panic when spinner exits early (#2591)
  feat: describe affected evaluates all provisioned component sections (#2573)

This branch was successfully deployed

1 active deployment
preview — f7d5cdf1 Deployed Jun 9, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

minor New features that do not break anything size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants