Skip to content

fix(tests): stabilize shared CI fixtures and timing - #3235

Open
Erik Osterman (Cloud Posse) (osterman) wants to merge 9 commits into
mainfrom
osterman/fix-auth-whoami-test-isolation
Open

Erik Osterman (Cloud Posse) (osterman) wants to merge 9 commits into
mainfrom
osterman/fix-auth-whoami-test-isolation

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

what

Stabilize shared test failures exposed by the CloudFormation stack without changing production behavior.

  • Run the two successful auth-whoami tests serially because authentication temporarily changes the process-wide logger.
  • Use loopback GitHub releases and local include fixtures while retaining real HTTP request, installation, extraction, and cache assertions. Cover terraform@latest installation and YAML tool metadata with fixed local releases.
  • Permit the Go release metadata and fallback download endpoints in hardened jobs, including local composite-action callers, so cold runners can install the pinned Go version when GitHub API requests fail.
  • Verify the final viewport summary while allowing transient frames in raw ANSI terminal captures; retain the model assertion that the display is cleared.
  • Reset the shared Terraform/source Cobra flags as well as Viper in JIT/source tests, and isolate writable fixtures in temporary directories.
  • Give each planfile generation test a private copy of the three checked-in scenario/component inputs, excluding generated state, so concurrent Windows test binaries cannot share Terraform state.
  • Drain captured command output concurrently so large debug logs cannot fill the varfile tests' stderr pipe.
  • Give scheduler test harnesses a ten-second deadlock budget instead of a one-second scheduling deadline. Preserve concurrency bounds, ordering, cancellation, and worker-drain assertions.

why

Live GitHub requests exhausted shared API quotas, auth logging setup raced parallel command logging, raw terminal captures retained cleared frames, and a loaded Windows runner exceeded the scheduler test's one-second startup allowance. The suite also leaked Cobra dry-run flags across invocations and blocked while writing large debug logs to an unread pipe. Concurrent Windows test binaries also locked the same shared Terraform state file. These tests now isolate command state and fixtures, drain output while commands run, and distinguish scheduling delays from behavior failures. CI shard counts and suite-wide parallelism stay the same.

Go setup also failed on cold runners when installation API quotas were exhausted: hardened jobs blocked the fallback metadata and download hosts. The allowlists now include those required hosts, with network blocking still enabled. A recursive audit covers all 24 Go setup jobs, including local composite-action callers. Shard counts and parallelism remain unchanged.

Validation passed:

  • Five shuffled race runs of the auth tool package.
  • Three shuffled race runs of affected toolchain installation cases, plus repeated include and CLI fixture tests.
  • Fifty shuffled race runs of the viewport regression and ten viewport model runs.
  • One hundred shuffled race runs of the scheduler package.
  • Three shuffled race runs of source/JIT acceptance tests, including an ordered dry-run-to-delete regression, on both the shared base and CloudFormation layer.
  • Twenty shuffled race runs of the varfile output/color tests.
  • Five shuffled race runs of planfile generation, followed by two concurrent processes running three shuffled race repetitions each and three additional runs on the full CloudFormation layer.
  • Reproduced failure when the original directory copy included invalid generated state; the narrowed copy passed two concurrent processes with three shuffled race runs each against the same contaminated source.
  • Ten shuffled race runs of local latest installation and three shuffled race runs of the YAML toolchain-info snapshot.
  • Workflow linting and the acceptance-check package tests.
  • Changed-code lint, pre-commit hooks, and the website build.

This PR changes only tests, fixtures, and the CI network allowlist; production Go patch coverage is not applicable.

references

Summary by CodeRabbit

  • Tests & Reliability
    • Expanded coverage for authentication identity output, toolchain installation, remote includes, and source command behavior.
    • Test scenarios now use controlled release data and isolated fixtures, making results more consistent across environments.
    • Updated test timeouts and output checks to better accommodate slower CI runs and terminal behavior.

@osterman Erik Osterman (Cloud Posse) (osterman) added the no-release Do not create a new release (wait for additional code changes) label Sep 30, 2026
@atmos-pro

atmos-pro Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions github-actions Bot added the size/m Medium size PR label Sep 30, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Note

Repository guideline files applied to this review (1)
CLAUDE.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cloudposse/atmos/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 1a6a7b7b-7213-4832-a33b-0629c6f28c34

📥 Commits

Reviewing files that changed from the base of the PR and between 8f0188c and 54754e0.

📒 Files selected for processing (14)
  • .github/workflows/codeql.yml
  • .github/workflows/native-ci.yml
  • .github/workflows/planfile-artifacts-e2e.yml
  • .github/workflows/planfile-verify-e2e.yml
  • .github/workflows/rerun-infra-failures.yml
  • .github/workflows/setup-go-cache-warmup.yml
  • .github/workflows/test.yml
  • .github/workflows/validation-e2e.yml
  • .github/workflows/website-deploy-prod.yml
  • .github/workflows/website-preview-build.yml
  • .github/workflows/website-preview-deploy.yml
  • internal/exec/terraform_generate_planfile_test.go
  • pkg/toolchain/install_test.go
  • tests/test-cases/toolchain.yaml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The changes update tests for authentication, toolchain releases, YAML includes, command output, scheduler timing, planfile generation, and Terraform source command state. They add local and loopback fixtures, reset shared test state, adjust output assertions and timeout values, and extend CI workflow egress allowlists.

Changes

Authentication test execution

Layer / File(s) Summary
Run whoami tests serially
pkg/ai/tools/atmos/auth_whoami_serial_test.go, pkg/ai/tools/atmos/auth_whoami_test.go
Moves the default and explicit mock identity tests to a serial test file. The tests check execution results and identity data. The default test also checks output and absence of mock credentials.

Toolchain test fixtures

Layer / File(s) Summary
Resolve and install from loopback fixtures
pkg/toolchain/update_test.go, pkg/toolchain/install_test.go
Installation tests use loopback release metadata and ZIP fixtures. The success tests check requests and verify the extracted binary contents.
Use fixed release data in CLI tests
tests/cli_test.go, tests/test-cases/toolchain.yaml, tests/snapshots/*toolchain*
The shared mock registers fixed release metadata. Toolchain info tests direct API requests to the mock and check available-version output against updated snapshots.

YAML include test fixtures

Layer / File(s) Summary
Separate local and mocked remote includes
tests/yaml_functions_include_test.go, tests/test-cases/atmos-include-yaml-function.yaml, tests/fixtures/scenarios/atmos-include-yaml-function*/stacks/deploy/*
The local stack fixture reads a sibling YAML file. The remote include test uses a GitHub mock and checks that the remote fixture was requested.

Command output capture

Layer / File(s) Summary
Capture and check command output
cmd/custom_command_output_test.go, cmd/terraform_generate_varfile_test.go
The live stderr assertion strips ANSI control sequences and checks the completion suffix. Varfile tests use shared output capture instead of manual stderr pipes.

Scheduler test timeouts

Layer / File(s) Summary
Use a shared scheduler timeout
pkg/scheduler/scheduler_test.go
Scheduler completion checks and worker-start waits use a shared ten-second timeout instead of one second.

Terraform source command state

Layer / File(s) Summary
Reset and verify source command state
tests/cli_source_provisioner_test.go, tests/cli_source_provisioner_workdir_test.go, tests/cli_source_state_test.go, tests/cli_jit_source_oci_test.go, tests/cli_jit_source_workdir_test.go
Shared helpers reset source command flags and Viper state. Source command tests use temporary fixtures, and a new test checks dry-run state reset and delete behavior.

Terraform planfile test fixtures

Layer / File(s) Summary
Isolate planfile test inputs
internal/exec/terraform_generate_planfile_test.go
Planfile tests copy required inputs into a temporary fixture and use its component path. Command failures now stop the test immediately.

CI workflow egress

Layer / File(s) Summary
Extend workflow endpoint allowlists
.github/workflows/*.yml
Harden Runner endpoint allowlists add HTTPS access to Go hosts, Google downloads, and raw GitHub content across the listed workflows.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Suggested reviewers: goruha

Merge Risk: ⚪ Minimal · up to 54754

The changes improve test determinism and allow required CI downloads without changing production behavior. No actionable merge-blocking issue is established; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 54754

CI jobs gain access to additional download hosts, including jobs with cloud credentials. Existing blocking policies, action pins, and permission boundaries remain. No introduced exploit or authority escalation was established, but download verification and effective cloud-role restrictions were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A compromised process in a widened job gains additional outbound destinations within that runner. Relevant existing assets include repository-reporting tokens and documentation deployment credentials. Actual AWS role permissions and environment approval rules were unavailable, so maximum cloud exposure is not established.

Security Findings and Attack Paths

  • inferred — New access to raw GitHub content alone does not establish an introduced arbitrary-content attack path: the inspected jobs already permitted GitHub API, release-asset, and Google storage hosts. No changed consumer was shown executing newly attacker-selected content. This counterevidence limits the concern but does not prove complete coverage.

Trust Boundaries and Controls

  • observed — The inspected PR build paths use pull_request rather than pull_request_target and disable persisted checkout credentials. Preview deployment remains a separate workflow_run job requiring a successful associated PR run. These controls and declared permissions are unchanged; external enforcement and approval settings were not verified.

Hardening Proposals

  • proposed — Document or verify the pinned setup action's authenticity checks for fallback Go downloads. Where practical, keep tool acquisition separate from credential-bearing deployment steps. These are hardening options, not verified defects introduced by this PR.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 56.10% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 41 functions across 14 files. (12 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main changes: stabilizing shared test fixtures and timing across tests and CI workflows.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 56.10% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 41 functions across 14 files. (12 skipped: 12 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Already reviewed the last commit. Use @coderabbitai full review to rerun a review of the entire changeset.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.51%. Comparing base (67c4102) to head (54754e0).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #3235      +/-   ##
==========================================
- Coverage   84.56%   84.51%   -0.05%     
==========================================
  Files        2095     2095              
  Lines      205082   205082              
==========================================
- Hits       173429   173327     -102     
- Misses      23406    23517     +111     
+ Partials     8247     8238       -9     
Flag Coverage Δ
unittests 84.51% <ø> (-0.05%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 12 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

CI timing summary

Latest completed GitHub Actions runs for 54754e09dd23.

  • PR wall-clock time: 48m 38s
  • Aggregate runner time: 10h 06m 58s
  • Included: 19 workflows, 132 jobs (including matrix jobs)

Wall-clock time spans the earliest included workflow creation through the latest completion. Aggregate runner time adds each job's execution time, so concurrent jobs are counted separately.

Workflow Elapsed Runner time Jobs
⏹️ Tests 48m 38s 8h 21m 42s 98
✅ Screengrabs 25m 47s 25m 15s 2
✅ Planfile Verify E2E 14m 02s 19m 47s 3
✅ Planfile Artifacts E2E 12m 05s 11m 58s 2
✅ Native CI 7m 46s 15m 49s 6
✅ CodeQL 7m 33s 16m 12s 6
✅ atmos.ci 3m 52s 3m 49s 1
✅ Dependency Review 3m 38s 3m 34s 1
✅ Validation E2E 2m 53s 2m 49s 1
✅ Pre-commit 2m 23s 2m 20s 1
✅ Verify SHA Pinning 1m 05s 1m 01s 1
✅ TruffleHog secret scan 43s 39s 1
✅ vhs 33s 29s 3
✅ Validate Codeowners 26s 22s 1
✅ PR Size Labeler 25s 23s 1
✅ Release Documentation Check 24s 20s 1
✅ Verify Repository Symlinks 23s 19s 1
✅ autofix.ci 13s 10s 1
⏭️ Feature release 1s 0s 1
Longest jobs (top 10)
Job Workflow Duration Conclusion
build Screengrabs 24m 53s ✅ success
[mock-macos] tests/fixtures/scenarios/complete Tests 20m 20s ⏹️ cancelled
[race] non-acceptance test suite (shard 4/4) Tests 17m 19s ✅ success
Acceptance Tests (macos, shard 1/10) Tests 16m 26s ✅ success
Acceptance Tests (macos, shard 10/10) Tests 15m 36s ❌ failure
[k3s-macos] demo-helmfile Tests 15m 33s ✅ success
[floci] go e2e Tests 14m 27s ✅ success
Acceptance Tests (windows, shard 3/10) Tests 14m 17s ✅ success
Acceptance Tests (macos, shard 3/10) Tests 13m 23s ✅ success
Acceptance Tests (windows, shard 1/10) Tests 12m 58s ✅ success

Updated automatically when a PR workflow finishes.

@osterman Erik Osterman (Cloud Posse) (osterman) changed the title fix(tests): isolate auth logging and GitHub fixture traffic fix(tests): stabilize auth, terminal output, and external fixtures Sep 30, 2026
@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) full review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
@osterman Erik Osterman (Cloud Posse) (osterman) changed the title fix(tests): stabilize auth, terminal output, and external fixtures fix(tests): stabilize shared CI fixtures and timing Sep 30, 2026
@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) review

coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Already reviewed the last commit. Use @coderabbitai full review to rerun a review of the entire changeset.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@mergify

mergify Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@mergify mergify Bot added the needs-cloudposse Needs Cloud Posse assistance label Sep 30, 2026
@mergify
mergify Bot deployed to screengrabs September 30, 2026 23:10 Active
@github-actions

Copy link
Copy Markdown

Warning

SHA Pin Verification Passed — with documented exceptions

All 236 third-party action reference(s) are covered, but 2 rely on a documented allowlist entry in allowlist.json and could not be automatically drift-checked. This does not fail CI, but should be reviewed.

Action Location Status Details
aquasecurity/trivy-action@v0.36.0 build.yml:152 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.
aquasecurity/trivy-action@v0.36.0 test.yml:1306 ⚠️ Allowlisted (documented) The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.

See the action run for full details.

@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@github-actions

Copy link
Copy Markdown

Resource Changes Found for bucket in test

Atmos CI

create

Plan: 4 to add, 0 to change, 0 to destroy.
To reproduce this locally, run:

atmos terraform plan bucket -s test

Create

+ aws_s3_bucket.checkov_target
+ aws_s3_bucket.this
+ aws_s3_bucket.trivy_target
+ aws_s3_bucket_public_access_block.trivy_target
Terraform Plan Summary
  # aws_s3_bucket.checkov_target will be created
  + resource "aws_s3_bucket" "checkov_target" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-checkov-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags_all                    = (known after apply)
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket.this will be created
  + resource "aws_s3_bucket" "this" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags                        = {
          + "AtmosFixture" = "native-ci-e2e"
          + "Stage"        = "test"
        }
      + tags_all                    = {
          + "AtmosFixture" = "native-ci-e2e"
          + "Stage"        = "test"
        }
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket.trivy_target will be created
  + resource "aws_s3_bucket" "trivy_target" {
      + acceleration_status         = (known after apply)
      + acl                         = (known after apply)
      + arn                         = (known after apply)
      + bucket                      = "atmos-native-ci-e2e-trivy-test"
      + bucket_domain_name          = (known after apply)
      + bucket_prefix               = (known after apply)
      + bucket_regional_domain_name = (known after apply)
      + force_destroy               = false
      + hosted_zone_id              = (known after apply)
      + id                          = (known after apply)
      + object_lock_enabled         = (known after apply)
      + policy                      = (known after apply)
      + region                      = (known after apply)
      + request_payer               = (known after apply)
      + tags_all                    = (known after apply)
      + website_domain              = (known after apply)
      + website_endpoint            = (known after apply)

      + cors_rule (known after apply)

      + grant (known after apply)

      + lifecycle_rule (known after apply)

      + logging (known after apply)

      + object_lock_configuration (known after apply)

      + replication_configuration (known after apply)

      + server_side_encryption_configuration (known after apply)

      + versioning (known after apply)

      + website (known after apply)
    }

  # aws_s3_bucket_public_access_block.trivy_target will be created
  + resource "aws_s3_bucket_public_access_block" "trivy_target" {
      + block_public_acls       = true
      + block_public_policy     = true
      + bucket                  = (known after apply)
      + id                      = (known after apply)
      + ignore_public_acls      = true
      + restrict_public_buckets = true
    }

Plan: 4 to add, 0 to change, 0 to destroy.

Changes to Outputs:
  + bucket_name = "atmos-native-ci-e2e-test"

@osterman

Copy link
Copy Markdown
Member Author

CodeRabbit (@coderabbitai) review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

This branch was successfully deployed

1 active deployment
screengrabs — 54754e09 Deployed Sep 30, 2026 by osterman via build #2367
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-cloudposse Needs Cloud Posse assistance no-release Do not create a new release (wait for additional code changes) size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant