feat(github-app): use ssm manifest for extra apps - #5282
Open
guicaulada wants to merge 2 commits into
Open
Conversation
Deliver additional GitHub App credentials to the lambdas through a manifest SSM parameter listing the per-app credential parameter names, instead of colon-joined parameter names in the environment. The lambda environment size stays constant regardless of app count, avoiding the 4 KB Lambda environment limit (roughly 15-20 apps with typical paths). The manifest also removes the positional alignment between the id, key, and installation-id lists, which could silently shift installation ids across apps if the lists drifted. The rate-limit metric now reads app ids from the credentials already loaded by the auth module instead of re-reading SSM per app index. Document that additional apps must be installed on the same organizations or repositories as the primary app.
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Follow-up to #5269, as promised in the #5038 review (items 1, 3, 4, and 5). We run this design in production.
getLoadedAppId) instead of re-reading SSM per app index; out-of-range indexes no longer throw inside the swallowed catch.Internal contract only: Terraform and the lambdas deploy together, so the env transport change is invisible to module users.
additional_github_appsis unchanged.Test Plan
terraform fmt/validateclean on root, runners, multi-runner, ssm;terraform testinmodules/runnerspasses.Related Issues
Follow-up to #5269 / #5038.