You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Track the remaining findings from Npalm's review of PR #5299.
Required fixes
Resolve the controller task-role ssm:PutParameter mismatch. The controller writes discovered GitHub App installation IDs and runner-group IDs, but the current IAM policy grants read-only SSM access. Prefer removing write-back until both cache parameter ARNs are explicit Terraform inputs; do not introduce an unbounded write permission.
Replace the default scale-set controller :latest image with a verified immutable release digest and update tests/documentation.
Scope ECR layer-pull permissions to private-ECR deployments only; public GHCR deployments should not receive unused ECR permissions.
Align controller log retention with the repository baseline of 180 days, or document and justify a different default.
Preserve logger error redaction when normalizing Error values and add regression coverage.
Documentation and maintainability
Update docs/index.md and docs/configuration.md with scale-set architecture, ECS controller behavior, grouping, and experimental variables.
Extend the v1/v2 configuration and migration guides with scale-set selection guidance and limitations.
Add an ADR documenting that existing GitHub scale sets are adopted by name and are not created or deleted by Terraform.
Clarify the default 0.0.0.0/0 egress trade-off, GitHub Meta API ranges, and NAT/firewall/proxy alternatives in the module variables and README. Documentation issue docs(scale-set): document architecture and configuration options #5470 overlaps with this section and should be consolidated or closed as appropriate.
Remove duplicate controller startup log fields; keep the count at info level and names at debug level.
Align the step-security/harden-runner pin in .github/workflows/lambda.yml with the current repository pin.
Add a short comment documenting the security scope of the MiniStack Docker socket mount.
Validation
Run Terraform/OpenTofu formatting, validation, and scale-set tests.
Run focused TypeScript format, lint, build, and unit tests.
Regenerate Terraform documentation and run git diff --check.
Verify the final changed-file list and link the implementation branch/PR.
Context
Track the remaining findings from Npalm's review of PR #5299.
Required fixes
Documentation and maintainability
Validation
References