Skip to content

Preserve runtime agent images when Terraform changes sizing - #127

Merged
maksvet merged 2 commits into
masterfrom
codex/dbmon-runtime-updates
Oct 2, 2026
Merged

maksvet merged 2 commits into
masterfrom
codex/dbmon-runtime-updates

Conversation

@anchoo2kewl

Copy link
Copy Markdown
Contributor

Terraform sizing changes must preserve agent versions selected through Elastio. Add opt-in runtime_updates to read the currently running agent and ED images from the existing ECS deployment when creating a new task definition. CPU/memory remain controlled by Terraform; image selection remains controlled by Elastio.

Keep the default false for first-time bootstrap. Enable after the ECS service and trusted deployment updater exist. This avoids ignoring task_definition, which would also discard sizing changes.

Validation: terraform validate and 18 mocked tests pass, including retaining current image digests while changing CPU/memory. Companion agent #13 and UI #740. No ED source changes.

Please review; Anshuman will merge after approval.

@anchoo2kewl
anchoo2kewl marked this pull request as ready for review October 2, 2026 00:42
Copilot AI balanced review requested due to automatic review settings October 2, 2026 00:42

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@maksvet
maksvet merged commit 160d078 into master Oct 2, 2026
22 checks passed
@maksvet
maksvet deleted the codex/dbmon-runtime-updates branch October 2, 2026 01:12
anchoo2kewl added a commit that referenced this pull request Oct 2, 2026
…d ECS service (module 0.3.0) (#129)

Closes #128.

Fargate deployments have no host to run the deployment updater on, so
"Update to latest" never appears for them. With `updater = true` the
module now runs the updater as a second ECS service in the agent's
cluster.

**New inputs:** `updater` (default `false`), `updater_image` (default by
channel:
`public.ecr.aws/elastio/elastio-database-monitoring-updater:0.1.10` for
production,
`public.ecr.aws/elastio-development/elastio-database-monitoring-updater:latest`
for development), `update_channel` (`production` | `development`),
`agent_id` (default `""`, **required and validated as a UUID when
`updater = true`**: the updater cannot discover it, and without it the
service would run and never update anything; the agent logs it on every
start as `registered as <id>`). New outputs: `updater_service_name` and
`updater_task_role_arn`. The module version goes to **0.3.0**. That
release also carries `runtime_updates` from #127, which merged after
0.2.1 was tagged.

**What `updater = true` creates:** one service, `<name>-updater`
(desired 1, minimum healthy 0 / maximum 100 so two never run at once),
with a 0.25 vCPU / 512 MiB ARM64 task. It runs in the agent's subnets
and security groups and needs no inbound rules. It logs to the module's
log group under `updater/`. Its environment is
`ELASTIO_DBMON_SERVER_URL`, `_AGENT_ID`, `_DEPLOYMENT=ecs`,
`_UPDATE_CHANNEL`, `_ECS_CLUSTER`, `_ECS_SERVICE` and `_ECS_CONTAINER`,
plus `ELASTIO_DBMON_API_KEY` from the agent's own secret.

The service also gets its own two roles:

- **Execution role:** `AmazonECSTaskExecutionRolePolicy`, the same as
the agent's (image pull and log write), plus
`secretsmanager:GetSecretValue` on the agent's API-key secret only.
- **Task role**, the whole policy:

| Sid | Action | Resource | Condition |
|---|---|---|---|
| ReadAgentService | `ecs:DescribeServices` | the agent's service ARN |
|
| ReadTaskDefinitions | `ecs:DescribeTaskDefinition` | `*` (ECS supports
no resource scoping for this action) | |
| RegisterAgentTaskDefinition | `ecs:RegisterTaskDefinition` |
`arn:…:task-definition/<agent family>:*` | |
| DeployAgentService | `ecs:UpdateService` | the agent's service ARN |
`ArnLike ecs:task-definition = arn:…:task-definition/<agent family>:*` |
| PassAgentRoles | `iam:PassRole` | the agent's task role and execution
role | `iam:PassedToService = ecs-tasks.amazonaws.com` |

The `ecs:task-definition` condition stops the service from being pointed
at another family's task definition, along with that family's roles. IAM
Access Analyzer `validate-policy` returned no findings on the rendered
policy.

**`updater` requires `runtime_updates`.** This is a variable validation,
so `updater = true` on its own is refused at plan. Without
`runtime_updates`, the next apply would put the module's `image` back
over the one the updater deployed. `runtime_updates` reads the existing
service, so both can only be enabled **after the first apply**. The
README says so. The updater docs in the agent repo should say "set
`runtime_updates = true` and `updater = true`" rather than `updater =
true` alone.

### Verified

- `terraform test` passes 24 of 24: the existing 18 plus 6 new ones in
`tests/updater.tftest.hcl`. The new tests cover off by default, the
`runtime_updates` requirement, channel validation, the full execution-
and task-role policy JSON, PassRole limited to the two agent roles, the
container's environment and secret, and the image defaults and override.
They are in their own file so that their apply starts from empty state:
run-level `override_resource` doesn't reach resources that earlier
applies in `module.tftest.hcl` already created.
- Each of these seeded violations fails a test: a third PassRole ARN,
dropping the UpdateService condition, and neutering the validation.
- `terraform fmt -check`, `terraform validate` (module and
`examples/basic`), `tflint`, `typos` and `prettier --check` all pass.
terraform-docs v0.19.0 + prettier output is unchanged on a rerun.
Terraform used locally: 1.12.2.

### Depends on, and not exercised before merge

- **The updater image.** `elastio-database-monitoring-updater` is
published by the round-2 PR in elastio/database-monitoring-agent. Its
ECR Public repos come from infraworld. The production default `:0.1.10`
exists only once `agent-v0.1.10` is released with it. **Merge after that
image is published.**
- No real apply has been run. The IAM policy was checked by Access
Analyzer and the mocked tests, not against a live ECS UpdateService
call.

Please review; Anshuman will merge after approval.

---------

Co-authored-by: Anshuman Biswas <abiswas@elastio.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants