Repository navigation
test(iac): the LocalStack and moto e2e rigs compile the module for an emulator, so provider 6 reads a Glue database back - #708
Merged
Conversation
… emulator, so provider 6 reads a Glue database back The heavy emulated lane went red on 2026-10-06, and stayed red: six round-trips in test_iac_aws_localstack_e2e.py failed at tofu apply with "unexpected format for ID (:mesh_silver), expected catalog-id:database-name". All six apply a Glue database. Every LocalStack round-trip that applies none of them passed in the same run. The three Glue tests in test_iac_moto_e2e.py fail the same way against moto, and that file runs in no CI lane. #700 moved hashicorp/aws from ~> 5.0 to ~> 6.0. Provider 6 gives a Glue database the id <catalog id>:<name>, the catalog id being the resource's catalog_id or else the provider's account id, and refuses to read back an id whose catalog is empty. Both rigs skip requesting the account id in a sidecar provider block, as an emulator needs, so the id was ":<name>". #700 handled this in the plugin: when AWS_ENDPOINT_URL names an emulator, each Glue database and table names its catalog from data.aws_caller_identity (aws._emulator_catalog_id). It moved the apply-engine moto rig onto that path. The LocalStack rig and the moto e2e rig aim tofu at the emulator only through the sidecar's endpoints map and never set AWS_ENDPOINT_URL, so the plugin compiled their module for real AWS. Both rigs now compile the module with AWS_ENDPOINT_URL naming the emulator, as an emulator user sets it. The module then carries its own provider "aws" block, so each sidecar is written as provider_override.tf.json, which merges into it. A second plain block would be a duplicate provider configuration. LocalStackProject scopes the variable to the emit, so it reaches neither the tofu child nor the rest of the test. The moto e2e fixture also resets moto between tests, as the apply-engine rig does. moto's backends are process-wide, so the database a failed test leaves behind made the next test's CreateDatabase fail with AlreadyExistsException, a second failure with the same cause. No product code changes. The plugin already emits the right module for an emulator user, and nothing changes on real AWS.
detect-secrets 1.5.0 (the CI pin) moves the line numbers of the two dummy emulator credentials already in the baseline, in tests/iac/conftest.py and tests/iac/test_iac_moto_e2e.py. No secret is added.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The admin-gated heavy emulated lane (
integration-emulated-heavy.yml) has been red since the 2026-10-06 nightly (37416453679), and on #707 (37535681413). Six round-trips intests/iac/test_iac_aws_localstack_e2e.pyfail attofu apply:All six apply an
aws_glue_catalog_database. Every LocalStack round-trip in the same run that applies no Glue database passed. The three Glue tests intests/iac/test_iac_moto_e2e.pyfail the same way against moto, and that file runs in no CI lane.Root cause
#700 (
ff26cb10) movedhashicorp/awsfrom~> 5.0to~> 6.0. That commit sits between the last green nightly (93e78d43, 2026-10-05) and the first red one (9b17c273). Provider 6 sets a Glue database's id to<catalog id>:<name>. The catalog id is the resource'scatalog_id, or else the provider's account id. Provider 6 then refuses to read back an id whose catalog is empty.Both rigs set
skip_requesting_account_idin a sidecar provider block, which an emulator needs, so the id became:<name>.#700 already handles this in the plugin. When
AWS_ENDPOINT_URLnames an emulator, each Glue database and table takes its catalog fromdata.aws_caller_identity(aws._emulator_catalog_id). #700 also moved the apply-engine moto rig onto that path. The LocalStack rig (LocalStackProjectintests/iac/conftest.py) and the moto e2e rig do not setAWS_ENDPOINT_URL. They aim tofu at the emulator only through the sidecar'sendpointsmap, so the plugin compiled their module for real AWS.The
AlreadyExistsExceptiononCreateDatabasehas the same cause. moto's backends are process-wide, so the database that one failed test leaves behind breaks the next test's create.Fix (test rigs only)
AWS_ENDPOINT_URLnaming the emulator, as an emulator user sets it.LocalStackProjectscopes the variable to the emit.provider "aws"block. Each sidecar is therefore written asprovider_override.tf.json, an override file that merges into that block. A second plain block would be a duplicate provider configuration. This matches the apply-engine rig from feat(governance): column masking, row filters and governance labels on AWS and GCP #700./moto-api/reset) before each test, as the apply-engine rig does.No product code changes. The plugin already emits the right module for an emulator user, and the module for real AWS stays the same.
Type of Change
Documentation
Checklist
pytest): see Testing; the local venv has a pre-existingsqlglotmismatchruff checkandblackwith no errors (black pinned to 24.10.0, as CI pins it)Testing
Local runs used OpenTofu 1.12.0, moto 5.2.1 and Python 3.12. LocalStack runs in Docker, so it is covered in CI only, by this PR's
ci:integration-emulatedheavy-lane run.tests/iac/test_iac_moto_e2e.pyorigin/main9acc511d):analytics×2,:mesh_silver, thenAlreadyExistsExceptiononmesh_silver--randomly-seed=7The remaining skip is the existing Redshift Serverless skip, a moto-side bug.
The patched
LocalStackProjectrig run against a moto server (scratch driver, no Docker). This runs the rig's emit, the override merge, the Glue Iceberg apply, and a re-plan:catalog_idis emitted asdata.aws_caller_identity...account_id; the Iceberg table lands; re-plan is{add: 0, change: 0, remove: 0};AWS_ENDPOINT_URLdoes not leak after the emitunexpected format for IDBroader suite
pytest tests/iac -m "not slow" -n 8: the failing set is identical toorigin/main, apart from 5tofu validate/plantests that fail only under xdist contention and pass when run alone.sqlglotmismatch (TokenType.LLRR_ARROW). CI'siac-testsis green on9acc511d.tests/iac --collect-only: 2037 collected.Heavy lane on this PR (LocalStack)
Run 37608645176 on
a171cf6bpassed: 33 passed, 0 failed, 2 xfailed. Before the fix it was 6 failed, 27 passed. All six previously failing tests ran and passed; none skipped:test_full_aws_contract_iceberg_plus_lambda_plus_sfntest_iceberg_plus_kinesis_single_applytest_iceberg_on_glue_round_triptest_emitted_resources_carry_fluid_tagstest_reapply_produces_zero_changestest_athena_can_address_iceberg_table_via_glue_catalogThe later commit
0cf7d899changes only.secrets.baseline. detect-secrets 1.5.0 moved the line numbers of the two dummy emulator credentials already in the baseline; no secret was added.