Skip to content

test(iac): the LocalStack and moto e2e rigs compile the module for an emulator, so provider 6 reads a Glue database back - #708

Merged
fas89 merged 2 commits into
mainfrom
fix/glue-catalog-id-empty
Oct 9, 2026
Merged

fas89 merged 2 commits into
mainfrom
fix/glue-catalog-id-empty

Conversation

@fas89

@fas89 fas89 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Description

The admin-gated heavy emulated lane (integration-emulated-heavy.yml) has been red since the 2026-10-06 nightly (37416453679), and on #707 (37535681413). Six round-trips in tests/iac/test_iac_aws_localstack_e2e.py fail at tofu apply:

Error: unexpected format for ID (:mesh_silver), expected catalog-id:database-name

All six apply an aws_glue_catalog_database. Every LocalStack round-trip in the same run that applies no Glue database passed. The three Glue tests in tests/iac/test_iac_moto_e2e.py fail the same way against moto, and that file runs in no CI lane.

Root cause

#700 (ff26cb10) moved hashicorp/aws from ~> 5.0 to ~> 6.0. That commit sits between the last green nightly (93e78d43, 2026-10-05) and the first red one (9b17c273). Provider 6 sets a Glue database's id to <catalog id>:<name>. The catalog id is the resource's catalog_id, or else the provider's account id. Provider 6 then refuses to read back an id whose catalog is empty.

Both rigs set skip_requesting_account_id in a sidecar provider block, which an emulator needs, so the id became :<name>.

#700 already handles this in the plugin. When AWS_ENDPOINT_URL names an emulator, each Glue database and table takes its catalog from data.aws_caller_identity (aws._emulator_catalog_id). #700 also moved the apply-engine moto rig onto that path. The LocalStack rig (LocalStackProject in tests/iac/conftest.py) and the moto e2e rig do not set AWS_ENDPOINT_URL. They aim tofu at the emulator only through the sidecar's endpoints map, so the plugin compiled their module for real AWS.

The AlreadyExistsException on CreateDatabase has the same cause. moto's backends are process-wide, so the database that one failed test leaves behind breaks the next test's create.

Fix (test rigs only)

  • Both rigs compile the module with AWS_ENDPOINT_URL naming the emulator, as an emulator user sets it. LocalStackProject scopes the variable to the emit.
  • The emitted module now has its own provider "aws" block. Each sidecar is therefore written as provider_override.tf.json, an override file that merges into that block. A second plain block would be a duplicate provider configuration. This matches the apply-engine rig from feat(governance): column masking, row filters and governance labels on AWS and GCP #700.
  • The moto e2e fixture resets moto (/moto-api/reset) before each test, as the apply-engine rig does.

No product code changes. The plugin already emits the right module for an emulator user, and the module for real AWS stays the same.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)

Documentation

  • No docs needed
    • Justification: test-rig-only change; no user-facing behaviour changes.

Checklist

  • I have read the Contributing Guide
  • My code follows the project's coding standards
  • I have added tests that prove my fix/feature works (the existing failing tests are the proof)
  • All new and existing tests pass (pytest): see Testing; the local venv has a pre-existing sqlglot mismatch
  • I have run ruff check and black with no errors (black pinned to 24.10.0, as CI pins it)
  • New maintained Python files include license headers (no new files)

Testing

Local runs used OpenTofu 1.12.0, moto 5.2.1 and Python 3.12. LocalStack runs in Docker, so it is covered in CI only, by this PR's ci:integration-emulated heavy-lane run.

tests/iac/test_iac_moto_e2e.py

Result
Before (origin/main 9acc511d) 3 failed, 1 passed, 1 skipped: :analytics ×2, :mesh_silver, then AlreadyExistsException on mesh_silver
After, fixed order 4 passed, 1 skipped
After, --randomly-seed=7 4 passed, 1 skipped

The remaining skip is the existing Redshift Serverless skip, a moto-side bug.

The patched LocalStackProject rig run against a moto server (scratch driver, no Docker). This runs the rig's emit, the override merge, the Glue Iceberg apply, and a re-plan:

Result
Patched rig catalog_id is emitted as data.aws_caller_identity...account_id; the Iceberg table lands; re-plan is {add: 0, change: 0, remove: 0}; AWS_ENDPOINT_URL does not leak after the emit
Pre-fix emit (negative control) fails with unexpected format for ID

Broader suite

  • pytest tests/iac -m "not slow" -n 8: the failing set is identical to origin/main, apart from 5 tofu validate/plan tests that fail only under xdist contention and pass when run alone.
  • The 56 shared failures are a local venv sqlglot mismatch (TokenType.LLRR_ARROW). CI's iac-tests is green on 9acc511d.
  • tests/iac --collect-only: 2037 collected.

Heavy lane on this PR (LocalStack)

Run 37608645176 on a171cf6b passed: 33 passed, 0 failed, 2 xfailed. Before the fix it was 6 failed, 27 passed. All six previously failing tests ran and passed; none skipped:

  • test_full_aws_contract_iceberg_plus_lambda_plus_sfn
  • test_iceberg_plus_kinesis_single_apply
  • test_iceberg_on_glue_round_trip
  • test_emitted_resources_carry_fluid_tags
  • test_reapply_produces_zero_changes
  • test_athena_can_address_iceberg_table_via_glue_catalog

The later commit 0cf7d899 changes only .secrets.baseline. detect-secrets 1.5.0 moved the line numbers of the two dummy emulator credentials already in the baseline; no secret was added.

… emulator, so provider 6 reads a Glue database back

The heavy emulated lane went red on 2026-10-06, and stayed red: six
round-trips in test_iac_aws_localstack_e2e.py failed at tofu apply with
"unexpected format for ID (:mesh_silver), expected
catalog-id:database-name". All six apply a Glue database. Every
LocalStack round-trip that applies none of them passed in the same run.
The three Glue tests in test_iac_moto_e2e.py fail the same way against
moto, and that file runs in no CI lane.

#700 moved hashicorp/aws from ~> 5.0 to ~> 6.0. Provider 6 gives a Glue
database the id <catalog id>:<name>, the catalog id being the resource's
catalog_id or else the provider's account id, and refuses to read back
an id whose catalog is empty. Both rigs skip requesting the account id
in a sidecar provider block, as an emulator needs, so the id was
":<name>". #700 handled this in the plugin: when AWS_ENDPOINT_URL names
an emulator, each Glue database and table names its catalog from
data.aws_caller_identity (aws._emulator_catalog_id). It moved the
apply-engine moto rig onto that path. The LocalStack rig and the moto
e2e rig aim tofu at the emulator only through the sidecar's endpoints
map and never set AWS_ENDPOINT_URL, so the plugin compiled their module
for real AWS.

Both rigs now compile the module with AWS_ENDPOINT_URL naming the
emulator, as an emulator user sets it. The module then carries its own
provider "aws" block, so each sidecar is written as
provider_override.tf.json, which merges into it. A second plain block
would be a duplicate provider configuration. LocalStackProject scopes
the variable to the emit, so it reaches neither the tofu child nor the
rest of the test.

The moto e2e fixture also resets moto between tests, as the apply-engine
rig does. moto's backends are process-wide, so the database a failed
test leaves behind made the next test's CreateDatabase fail with
AlreadyExistsException, a second failure with the same cause.

No product code changes. The plugin already emits the right module for
an emulator user, and nothing changes on real AWS.
@fas89 fas89 added the ci:integration-emulated Maintainer vouch — run the admin-gated heavy-emulated lane (bigquery-emulator + LocalStack) label Oct 7, 2026
@fas89
fas89 deployed to integration-emulated October 7, 2026 10:37 — with GitHub Actions Active
@fas89
fas89 deployed to integration-emulated October 7, 2026 10:37 — with GitHub Actions Active
@github-actions github-actions Bot added the tests Test coverage or test infrastructure changes label Oct 7, 2026
detect-secrets 1.5.0 (the CI pin) moves the line numbers of the two
dummy emulator credentials already in the baseline, in
tests/iac/conftest.py and tests/iac/test_iac_moto_e2e.py. No secret is
added.
@fas89
fas89 deployed to integration-emulated October 7, 2026 14:58 — with GitHub Actions Active
@fas89
fas89 deployed to integration-emulated October 7, 2026 14:58 — with GitHub Actions Active
@github-actions github-actions Bot added security Security-related changes or reports ci:integration-emulated Maintainer vouch — run the admin-gated heavy-emulated lane (bigquery-emulator + LocalStack) and removed ci:integration-emulated Maintainer vouch — run the admin-gated heavy-emulated lane (bigquery-emulator + LocalStack) labels Oct 7, 2026
@fas89
fas89 merged commit d8cd2ab into main Oct 9, 2026
41 checks passed

This branch was successfully deployed

1 active deployment
integration-emulated — 0cf7d899 Deployed Oct 7, 2026 by fas89 via DataHub Quickstart integration #392
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:integration-emulated Maintainer vouch — run the admin-gated heavy-emulated lane (bigquery-emulator + LocalStack) security Security-related changes or reports tests Test coverage or test infrastructure changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant