Preserve runtime agent images when Terraform changes sizing - #127
Merged
Merged
Conversation
anchoo2kewl
marked this pull request as ready for review
October 2, 2026 00:42
YakubchikV
approved these changes
Oct 2, 2026
maksvet
approved these changes
Oct 2, 2026
anchoo2kewl
added a commit
that referenced
this pull request
Oct 2, 2026
…d ECS service (module 0.3.0) (#129) Closes #128. Fargate deployments have no host to run the deployment updater on, so "Update to latest" never appears for them. With `updater = true` the module now runs the updater as a second ECS service in the agent's cluster. **New inputs:** `updater` (default `false`), `updater_image` (default by channel: `public.ecr.aws/elastio/elastio-database-monitoring-updater:0.1.10` for production, `public.ecr.aws/elastio-development/elastio-database-monitoring-updater:latest` for development), `update_channel` (`production` | `development`), `agent_id` (default `""`, **required and validated as a UUID when `updater = true`**: the updater cannot discover it, and without it the service would run and never update anything; the agent logs it on every start as `registered as <id>`). New outputs: `updater_service_name` and `updater_task_role_arn`. The module version goes to **0.3.0**. That release also carries `runtime_updates` from #127, which merged after 0.2.1 was tagged. **What `updater = true` creates:** one service, `<name>-updater` (desired 1, minimum healthy 0 / maximum 100 so two never run at once), with a 0.25 vCPU / 512 MiB ARM64 task. It runs in the agent's subnets and security groups and needs no inbound rules. It logs to the module's log group under `updater/`. Its environment is `ELASTIO_DBMON_SERVER_URL`, `_AGENT_ID`, `_DEPLOYMENT=ecs`, `_UPDATE_CHANNEL`, `_ECS_CLUSTER`, `_ECS_SERVICE` and `_ECS_CONTAINER`, plus `ELASTIO_DBMON_API_KEY` from the agent's own secret. The service also gets its own two roles: - **Execution role:** `AmazonECSTaskExecutionRolePolicy`, the same as the agent's (image pull and log write), plus `secretsmanager:GetSecretValue` on the agent's API-key secret only. - **Task role**, the whole policy: | Sid | Action | Resource | Condition | |---|---|---|---| | ReadAgentService | `ecs:DescribeServices` | the agent's service ARN | | | ReadTaskDefinitions | `ecs:DescribeTaskDefinition` | `*` (ECS supports no resource scoping for this action) | | | RegisterAgentTaskDefinition | `ecs:RegisterTaskDefinition` | `arn:…:task-definition/<agent family>:*` | | | DeployAgentService | `ecs:UpdateService` | the agent's service ARN | `ArnLike ecs:task-definition = arn:…:task-definition/<agent family>:*` | | PassAgentRoles | `iam:PassRole` | the agent's task role and execution role | `iam:PassedToService = ecs-tasks.amazonaws.com` | The `ecs:task-definition` condition stops the service from being pointed at another family's task definition, along with that family's roles. IAM Access Analyzer `validate-policy` returned no findings on the rendered policy. **`updater` requires `runtime_updates`.** This is a variable validation, so `updater = true` on its own is refused at plan. Without `runtime_updates`, the next apply would put the module's `image` back over the one the updater deployed. `runtime_updates` reads the existing service, so both can only be enabled **after the first apply**. The README says so. The updater docs in the agent repo should say "set `runtime_updates = true` and `updater = true`" rather than `updater = true` alone. ### Verified - `terraform test` passes 24 of 24: the existing 18 plus 6 new ones in `tests/updater.tftest.hcl`. The new tests cover off by default, the `runtime_updates` requirement, channel validation, the full execution- and task-role policy JSON, PassRole limited to the two agent roles, the container's environment and secret, and the image defaults and override. They are in their own file so that their apply starts from empty state: run-level `override_resource` doesn't reach resources that earlier applies in `module.tftest.hcl` already created. - Each of these seeded violations fails a test: a third PassRole ARN, dropping the UpdateService condition, and neutering the validation. - `terraform fmt -check`, `terraform validate` (module and `examples/basic`), `tflint`, `typos` and `prettier --check` all pass. terraform-docs v0.19.0 + prettier output is unchanged on a rerun. Terraform used locally: 1.12.2. ### Depends on, and not exercised before merge - **The updater image.** `elastio-database-monitoring-updater` is published by the round-2 PR in elastio/database-monitoring-agent. Its ECR Public repos come from infraworld. The production default `:0.1.10` exists only once `agent-v0.1.10` is released with it. **Merge after that image is published.** - No real apply has been run. The IAM policy was checked by Access Analyzer and the mocked tests, not against a live ECS UpdateService call. Please review; Anshuman will merge after approval. --------- Co-authored-by: Anshuman Biswas <abiswas@elastio.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Terraform sizing changes must preserve agent versions selected through Elastio. Add opt-in
runtime_updatesto read the currently running agent and ED images from the existing ECS deployment when creating a new task definition. CPU/memory remain controlled by Terraform; image selection remains controlled by Elastio.Keep the default false for first-time bootstrap. Enable after the ECS service and trusted deployment updater exist. This avoids ignoring task_definition, which would also discard sizing changes.
Validation: terraform validate and 18 mocked tests pass, including retaining current image digests while changing CPU/memory. Companion agent #13 and UI #740. No ED source changes.
Please review; Anshuman will merge after approval.