refactor(storage): route lambda access through storage providers - #5449
Merged
Merged
Conversation
Contributor
Dependency ReviewThe following issues were found:
License Issueslambdas/functions/termination-watcher/package.json
OpenSSF Scorecard
Scanned Files
|
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Clear the cached credential-load rejection so warm Lambda invocations can retry after transient SSM errors.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
What changed in this PR
Refactors Lambda credential and runner configuration access through shared storage-provider interfaces, removing legacy control-plane SSM wrappers.
Changes:
- Updates provider-contract mocks and related tests.
- Relocates housekeeper coverage under the SSM provider.
- Updates dependencies, typings, and lockfile.
- Removes obsolete SSM wrappers.
| File | Summary |
|---|---|
lambdas/yarn.lock |
Updates workspace dependencies. |
lambdas/libs/storage-providers/aws/ssm/runner-config-housekeeper.test.ts |
Updates housekeeper test coverage. |
lambdas/libs/storage-providers/aws/ssm/environment.d.ts |
Adds cleanup configuration typing. |
lambdas/libs/compute-providers/aws/ec2/src/environment.d.ts |
Adds failover configuration typing. |
lambdas/functions/termination-watcher/src/deregister.ts |
Uses shared credential storage; rejected loads remain cached and prevent retries. |
lambdas/functions/termination-watcher/src/deregister.test.ts |
Mocks the credential provider contract. |
lambdas/functions/termination-watcher/package.json |
Replaces the direct SSM dependency. |
lambdas/functions/control-plane/src/scale-runners/ssm-housekeeper.ts |
Removes the legacy wrapper. |
lambdas/functions/control-plane/src/scale-runners/scale-up.test.ts |
Mocks storage provider contracts. |
lambdas/functions/control-plane/src/modules.d.ts |
Removes moved environment declarations. |
lambdas/functions/control-plane/src/local-ssm-housekeeper.ts |
Removes the obsolete local helper. |
lambdas/functions/control-plane/src/lambda.test.ts |
Updates housekeeper tests. |
lambdas/functions/control-plane/src/github/auth.test.ts |
Mocks shared credential storage. |
lambdas/functions/control-plane/package.json |
Removes the direct SSM dependency. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Brend-Smits
approved these changes
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
Move Lambda GitHub App credentials and runner configuration access behind the shared storage-provider interfaces. Control-plane and termination-watcher tests now mock provider contracts, while SSM-specific behavior remains covered by the SSM storage-provider tests. The legacy control-plane SSM housekeeper wrappers were removed and the housekeeper test was moved under the SSM provider.
Test Plan
git diff --checkRelated Issues
Not applicable.