runtime icon indicating copy to clipboard operation
runtime copied to clipboard

Feat/account region protection

Open a-hilaly opened this issue 2 months ago • 6 comments

Adds protection against attempting to manage AWS resources that exist in a different region or account than the controller is configured to use. This prevents accidental resource hijacking and provides clear error messages.

  • Add regionDrifted() and accountDrifted() helper functions
  • Check for drift before creating resource manager in Reconcile
  • Return terminal errors when drift is detected
  • Add comprehensive tests for both region and account drift scenarios

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

a-hilaly avatar Sep 23 '25 18:09 a-hilaly

/test unit-test

michaelhtm avatar Sep 23 '25 22:09 michaelhtm

/retest

a-hilaly avatar Sep 24 '25 06:09 a-hilaly

/retest

a-hilaly avatar Sep 24 '25 15:09 a-hilaly

/retest

a-hilaly avatar Sep 24 '25 16:09 a-hilaly

/test ecr-controller-test

michaelhtm avatar Nov 10 '25 20:11 michaelhtm

/retest

michaelhtm avatar Nov 10 '25 21:11 michaelhtm

/lgtm

michaelhtm avatar Nov 10 '25 21:11 michaelhtm

/hold

michaelhtm avatar Nov 10 '25 21:11 michaelhtm

/lgtm /unhold

michaelhtm avatar Nov 10 '25 22:11 michaelhtm

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: a-hilaly, michaelhtm

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:
  • ~~OWNERS~~ [a-hilaly,michaelhtm]

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

ack-prow[bot] avatar Nov 10 '25 22:11 ack-prow[bot]

/test s3-controller-test

michaelhtm avatar Nov 10 '25 22:11 michaelhtm

/test ec2-controller-test

michaelhtm avatar Nov 10 '25 22:11 michaelhtm

@a-hilaly: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
verify-attribution c271c639b047ae65ee3c2fbca29eaf4e7e0f40fa link false /test verify-attribution

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

ack-prow[bot] avatar Nov 10 '25 23:11 ack-prow[bot]

/test sagemaker-controller-test

michaelhtm avatar Nov 10 '25 23:11 michaelhtm