open-swe/infra/lib/constructs
Adam Moussa f379fbdaa9
Some checks are pending
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
docs: document RETAIN secret-shell orphan gotcha (#52)
RETAIN + a fixed secret name means a failed FIRST create leaves empty
secret shells behind when the stack rolls back. The shells keep the
global `open-swe-<env>/<VAR>` names, so every later create fails with
`AlreadyExists`, and a plain delete-secret keeps the name reserved for
the recovery window rather than freeing it.

Record the trap and the force-delete recovery (only for empty shells)
in the config-store construct and the infra README so the next
teardown/rebuild, secret logical-id change, or new-env stand-up does
not rediscover it the hard way.

Prod's first deploy hit this on 2026-06-29: 28 orphaned shells from an
earlier failed create reserved the names and had to be force-deleted
before the stack would create.
2026-06-29 10:51:49 -04:00
..
ami-cache.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
app-service.ts fix: env-scope the EC2 launch template name (unblocks prod deploy) (#51) 2026-06-29 00:51:16 -04:00
assets-bucket.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
config-store.ts docs: document RETAIN secret-shell orphan gotcha (#52) 2026-06-29 10:51:49 -04:00
github-deploy-roles.ts ci: gate dev→prod promotion on green checks + add rollback safety net (#28) 2026-06-27 20:21:59 -04:00
instance-role.ts fix: BatchGetSecretValue must be granted on * (corrects #48, fixes dev crash-loop) (#50) 2026-06-28 22:08:02 -04:00