mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
Packer-build the custom base image and repoint AppService off the AL2023
placeholder onto it.
deploy/ami/open-swe-base.pkr.hcl — fix two bugs that blocked the first real
`packer build` (the config had only ever been `packer validate`'d at T8):
- the file provisioner failed uploading the templates dir ('scp: …: Is a
directory') — a trailing-slash contents-upload needs the dest dir to exist;
added a 'mkdir -p /tmp/open-swe-templates' shell provisioner + dropped the
dest trailing slash.
- the shell provisioner's custom execute_command omitted {{ .Vars }}, so the
environment_vars never reached provision.sh (which runs under set -u and
aborted on CLOUDWATCH_AGENT_DEB_URL). Added {{ .Vars }}.
infra:
- ami-cache.ts: BAKED_OPEN_SWE_AMI_ID = ami-0545363bb147229ff (built 2026-06-26
from open-swe-base-arm64-20260626-201929) + bakedOpenSweArm64() pinning it by
exact id via MachineImage.genericLinux (offline, deterministic). Dropped the
now-dead AL2023 cachedInContext helper + context key; kept the EBS/replacement
discipline docs.
- app-service.ts: machineImage → bakedOpenSweArm64().
- open-swe-stack.ts: output BakedAmiId (was the AL2023 PinnedAmiId guard).
- cdk.context.json → {} (AMI is a static id pin; no context lookups remain).
- README: Baked AMI + EBS-replacement-discipline section.
tsc + cdk synth(dev+prod) + jest(16) clean; template ImageId = the baked AMI.
NOTE: held — do NOT merge until the open-swe-dev secret values are populated
(put-config.sh). The infra CD is live, so merging this to dev auto-deploys
OpenSweDevStack; without secrets the box boots but fetch-config fail-fasts →
unhealthy ALB target on the shared prod ALB. Merge once secrets are set (T14).
35 lines
1.7 KiB
TypeScript
35 lines
1.7 KiB
TypeScript
import * as ec2 from "aws-cdk-lib/aws-ec2";
|
|
import { REGION } from "../config";
|
|
|
|
/**
|
|
* The baked open-swe base AMI (ARM64 Ubuntu 24.04 + uv/py3.12 + nginx + CW agent
|
|
* + boot templates — NO secrets), produced by `deploy/ami/open-swe-base.pkr.hcl`.
|
|
* Pinned by EXACT id (not a name filter) so synth/deploy is fully offline and
|
|
* deterministic.
|
|
*
|
|
* Built 2026-06-26 from open-swe-base-arm64-20260626-201929.
|
|
*
|
|
* ── EBS / AMI replacement discipline (memory feedback_inline_ebs_volumes) ──
|
|
*
|
|
* Refresh DELIBERATELY: `cd deploy/ami && packer build open-swe-base.pkr.hcl`,
|
|
* then update this id. A new id → EC2 instance REPLACEMENT. Pinning by exact id
|
|
* (vs a `most_recent` name filter) is what prevents a routine deploy from silently
|
|
* swapping the AMI — the root cause of the file-share data-loss incidents
|
|
* (5/15, 5/27, 6/5).
|
|
*
|
|
* `userDataCausesReplacement: true` (AppService) is likewise DELIBERATE: user-data
|
|
* is provisioning-only and the box holds NO durable state (the langgraph store is
|
|
* in-memory, rebuilt every boot from S3 + Secrets Manager / SSM), so there is
|
|
* intentionally no standalone `ec2.Volume` + `removalPolicy.RETAIN`. The design
|
|
* goal is replacement-TOLERANCE, not avoidance.
|
|
*
|
|
* Operational guard before ANY replacing deploy (AMI / userData / instance-type):
|
|
* snapshot the root volume AND wait `state=completed`, re-verify "no local-only
|
|
* durable state", and review the `cdk diff` replacement at PR time.
|
|
*/
|
|
export const BAKED_OPEN_SWE_AMI_ID = "ami-0545363bb147229ff";
|
|
|
|
/** The baked open-swe base image, pinned by id (offline, deterministic). */
|
|
export function bakedOpenSweArm64(): ec2.IMachineImage {
|
|
return ec2.MachineImage.genericLinux({ [REGION]: BAKED_OPEN_SWE_AMI_ID });
|
|
}
|