-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix: Alarm api_unauthorized for HeadBucket/Object from SSM agent (#6141) #6151
Fix: Alarm api_unauthorized for HeadBucket/Object from SSM agent (#6141) #6151
Conversation
With this change, the
|
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## develop #6151 +/- ##
===========================================
- Coverage 85.32% 85.32% -0.01%
===========================================
Files 154 154
Lines 20129 20129
===========================================
- Hits 17176 17175 -1
- Misses 2953 2954 +1 ☔ View full report in Codecov by Sentry. |
6da2f86
to
24b7b1e
Compare
Security design review
|
Security design review: This PR grants the required permissions to SSM agent running on the GitLab instance. A previous PR attempted to grant the same permissions but failed to do so correctly. This PR addresses that. It affects the monitoring of the system in that it will cause fewer false positive alarms to be triaged. |
|
24b7b1e
to
2a3e350
Compare
Connected issues: #6141
Checklist
Author
develop
issues/<GitHub handle of author>/<issue#>-<slug>
Author (partiality)
p
tag to titles of partial commitspartial
or completely resolves all connected issuespartial
label1 when the issue title describes a problem, the corresponding PR
title is
Fix:
followed by the issue titleAuthor (chains)
base
or this PR is not chained to another PRchained
or is not chained to another PRAuthor (reindex, API changes)
r
tag to commit title or this PR does not require reindexingreindex:dev
or does not require reindexingdev
reindex:anvildev
or does not require reindexinganvildev
reindex:anvilprod
or does not require reindexinganvilprod
reindex:partial
and its description documents the specific reindexing procedure fordev
,anvildev
,anvilprod
andprod
or requires a full reindex or carries none of the labelsreindex:dev
,reindex:anvildev
,reindex:anvilprod
andreindex:prod
API
or this PR does not modify a REST APIa
(A
) tag to commit title for backwards (in)compatible changes or this PR does not modify a REST APIapp.py
or this PR does not modify a REST APIAuthor (upgrading deployments)
u
tag to commit title or this PR does not require upgrading deploymentsmake image_manifests.json
and committed the resulting changes or this PR does not modifyazul_docker_images
, or any other variables referenced in the definition of that variableupgrade
or does not require upgrading deploymentsdeploy:shared
or does not modifyimage_manifests.json
, and does not require deploying theshared
component for any other reasondeploy:gitlab
or does not require deploying thegitlab
componentdeploy:runner
or does not require deploying therunner
imageAuthor (operator tasks)
Author (hotfixes)
F
tag to main commit title or this PR does not include permanent fix for a temporary hotfixprod
branch has no temporary hotfixes for any connected issuesAuthor (before every review)
develop
, squashed old fixupsmake requirements_update
or this PR does not modifyrequirements*.txt
,common.mk
,Makefile
andDockerfile
R
tag to commit title or this PR does not modifyrequirements*.txt
reqs
or does not modifyrequirements*.txt
make integration_test
passes in personal deployment or this PR does not modify functionality that could affect the IT outcomePeer reviewer (after requesting changes)
Uncheck the Author (before every review) checklists.
Peer reviewer (after approval)
System administrator (after requesting changes)
Uncheck the before every review checklists. Update the
N reviews
label.System administrator (after approval)
demo
orno demo
no demo
no sandbox
N reviews
label is accurateOperator (before pushing merge the commit)
reindex:…
labels andr
commit title tagno demo
upgrade
develop
_select dev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unused
or this PR is not labeleddeploy:shared
_select dev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply
or this PR is not labeleddeploy:gitlab
_select anvildev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unused
or this PR is not labeleddeploy:shared
_select anvildev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply
or this PR is not labeleddeploy:gitlab
_select anvilprod.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unused
or this PR is not labeleddeploy:shared
_select anvilprod.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply
or this PR is not labeleddeploy:gitlab
deploy:gitlab
deploy:gitlab
System administrator
dev.gitlab
are complete or this PR is not labeleddeploy:gitlab
anvildev.gitlab
are complete or this PR is not labeleddeploy:gitlab
anvilprod.gitlab
are complete or this PR is not labeleddeploy:gitlab
Operator (before pushing merge the commit)
_select dev.gitlab && make -C terraform/gitlab/runner
or this PR is not labeleddeploy:runner
_select anvildev.gitlab && make -C terraform/gitlab/runner
or this PR is not labeleddeploy:runner
_select anvilprod.gitlab && make -C terraform/gitlab/runner
or this PR is not labeleddeploy:runner
sandbox
label or PR is labeledno sandbox
dev
or PR is labeledno sandbox
anvildev
or PR is labeledno sandbox
anvilprod
or PR is labeledno sandbox
sandbox
deployment or PR is labeledno sandbox
anvilbox
deployment or PR is labeledno sandbox
hammerbox
deployment or PR is labeledno sandbox
sandbox
deployment or PR is labeledno sandbox
anvilbox
deployment or PR is labeledno sandbox
hammerbox
deployment or PR is labeledno sandbox
sandbox
or this PR does not remove catalogs or otherwise causes unreferenced indices indev
anvilbox
or this PR does not remove catalogs or otherwise causes unreferenced indices inanvildev
hammerbox
or this PR does not remove catalogs or otherwise causes unreferenced indices inanvilprod
sandbox
or this PR is not labeledreindex:dev
anvilbox
or this PR is not labeledreindex:anvildev
hammerbox
or this PR is not labeledreindex:anvilprod
sandbox
or this PR is not labeledreindex:dev
anvilbox
or this PR is not labeledreindex:anvildev
hammerbox
or this PR is not labeledreindex:anvilprod
p
if the PR is also labeledpartial
Operator (chain shortening)
develop
or this PR is not labeledbase
chained
label from the blocked PR or this PR is not labeledbase
base
base
label from this PR or this PR is not labeledbase
Operator (after pushing the merge commit)
dev
or PR is labeledno sandbox
anvildev
or PR is labeledno sandbox
anvilprod
or PR is labeledno sandbox
dev
1dev
1anvildev
1anvildev
1anvilprod
1anvilprod
1_select dev.shared && make -C terraform/shared apply
or this PR is not labeleddeploy:shared
_select anvildev.shared && make -C terraform/shared apply
or this PR is not labeleddeploy:shared
_select anvilprod.shared && make -C terraform/shared apply
or this PR is not labeleddeploy:shared
dev
anvildev
anvilprod
1 When pushing the merge commit is skipped due to the PR being
labelled
no sandbox
, the next build triggered by a PR whose merge commit ispushed determines this checklist item.
Operator (reindex)
dev
or this PR is neither labeledreindex:partial
norreindex:dev
anvildev
or this PR is neither labeledreindex:partial
norreindex:anvildev
anvilprod
or this PR is neither labeledreindex:partial
norreindex:anvilprod
dev
or this PR is neither labeledreindex:partial
norreindex:dev
anvildev
or this PR is neither labeledreindex:partial
norreindex:anvildev
anvilprod
or this PR is neither labeledreindex:partial
norreindex:anvilprod
dev
or this PR is neither labeledreindex:partial
norreindex:dev
anvildev
or this PR is neither labeledreindex:partial
norreindex:anvildev
anvilprod
or this PR is neither labeledreindex:partial
norreindex:anvilprod
dev
or this PR does not require reindexingdev
anvildev
or this PR does not require reindexinganvildev
anvilprod
or this PR does not require reindexinganvilprod
dev
or this PR does not require reindexingdev
anvildev
or this PR does not require reindexinganvildev
anvilprod
or this PR does not require reindexinganvilprod
dev
or this PR does not require reindexingdev
anvildev
or this PR does not require reindexinganvildev
anvilprod
or this PR does not require reindexinganvilprod
Operator
deploy:shared
,deploy:gitlab
,deploy:runner
,reindex:partial
andreindex:prod
labels to the next promotion PR or this PR carries none of these labelsdeploy:shared
,deploy:gitlab
,deploy:runner
,reindex:partial
andreindex:prod
labels from the description of this PR to that of the next promotion PR or this PR carries none of these labelsShorthand for review comments
L
line is too longW
line wrapping is wrongQ
bad quotesF
other formatting problem