From 405f4bbfab8af6d6d0d70cca7c19ea7615d29629 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 18 Jun 2026 13:57:15 -0400 Subject: [PATCH] fix(infra): distinct Aurora construct ID; group + unpause Dependabot (#129) * fix(infra): give the Aurora cluster a distinct construct ID The RDS->Aurora swap (PR3 #125) kept construct ID 'Database', so CloudFormation saw the same logical ID change from AWS::RDS::DBInstance to AWS::RDS::DBCluster and rejected the changeset ('Update of resource type is not permitted'). Renaming the construct to 'AuroraCluster' gives the cluster a new logical ID, so CFN does a clean replace (remove old DBInstance, add new DBCluster) instead of an in-place type change. * chore(deps): group Dependabot minor/patch updates per ecosystem Add a group to each update entry so weekly minor/patch bumps land as a single PR per ecosystem/directory instead of one PR per package. Major bumps remain individual PRs so breaking changes get isolated review. Grouping takes effect when open-pull-requests-limit is raised above 0 (version updates are still paused during development, #109). * chore(deps): unpause Dependabot version updates Raise open-pull-requests-limit from 0 to 10 across all ecosystems, re-enabling weekly version updates (paused during development, #109). With grouping now in place, minor/patch bumps land as one grouped PR per ecosystem; the limit caps outstanding major-bump PRs. --- .github/dependabot.yml | 109 +++++++++++++++++++++++++++------- infra/lib/foundation-stack.ts | 6 +- 2 files changed, 93 insertions(+), 22 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6fb6d0a..43487a6 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,74 +4,141 @@ updates: directory: /infra schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + infra: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: npm directory: /web schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + web: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: npm directory: /mobile schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + mobile-npm: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: bundler directory: /mobile schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + mobile-bundler: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: nuget directory: /api schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + api: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: pip directory: /lambdas/pdf-extract schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + pdf-extract: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: pip directory: /lambdas/pdf-generate schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + pdf-generate: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: pip directory: /lambdas/library-ingest schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + library-ingest: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: pip directory: /lambdas/suggestions schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + suggestions: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: pip directory: /lambdas/oss-index-creator schedule: interval: weekly - open-pull-requests-limit: 0 - + open-pull-requests-limit: 10 + groups: + oss-index-creator: + patterns: + - "*" + update-types: + - "minor" + - "patch" - package-ecosystem: github-actions directory: / schedule: interval: weekly - open-pull-requests-limit: 0 + open-pull-requests-limit: 10 + groups: + github-actions: + patterns: + - "*" + update-types: + - "minor" + - "patch" diff --git a/infra/lib/foundation-stack.ts b/infra/lib/foundation-stack.ts index b2fa4ab..c5bb5ef 100644 --- a/infra/lib/foundation-stack.ts +++ b/infra/lib/foundation-stack.ts @@ -88,7 +88,11 @@ export class FoundationStack extends cdk.Stack { // PR3: replaced the RDS instance + OpenSearch Serverless with Aurora + pgvector // (kills the AOSS OCU floor; scales toward 0 ACU when idle). Data API is required // by Bedrock Knowledge Bases to query the vector table. - const dbCluster = new rds.DatabaseCluster(this, 'Database', { + // Construct ID is 'AuroraCluster' (not 'Database') so CloudFormation gets a NEW + // logical ID for the cluster — the old RDS DBInstance shared logical ID 'Database*' + // and CFN forbids changing a resource's type in place ("Update of resource type is + // not permitted"). A distinct ID makes it a clean replace instead. + const dbCluster = new rds.DatabaseCluster(this, 'AuroraCluster', { clusterIdentifier: `proposal-system-db${config.stackSuffix}`, engine: rds.DatabaseClusterEngine.auroraPostgres({ version: rds.AuroraPostgresEngineVersion.VER_15_4,