Releases: loganpowell/knock-lambda
Release list
explicit lambda URL sharing permissions fix
What Changed
The AWS update requires us to explicitly declare the permissions that were previously implicit.
Before the fix:
❌ Missing explicit permissions (worked due to temporary AWS exception)
After the fix:
✅ Explicit lambda:InvokeFunctionUrl permission with principal=''
✅ Explicit lambda:InvokeFunction permission with principal=''
✅ Same public access as before
Better Setup
Dev Release v0.0.16
Testing new features
Split Stack with OIDC separated
- Deduplicates shared resources
- Leans heavily on Pulumi ESC
Complete Pipeline Fix - PEP 668 + OIDC + Caching
🎉 Complete Pipeline Fix
This release includes all fixes needed for a successful GitHub Actions + OIDC + CodeBuild deployment:
✅ Fixed Issues
1. PEP 668 - Externally Managed Environment (Primary Issue)
- Added
--break-system-packagesflag to pip install in Dockerfile - Resolves Python 3.11+ (Debian Bookworm) package installation restrictions
- Allows Lambda Runtime Interface Client installation
2. OIDC Authentication
- Added missing IAM permissions for OIDC provider management
iam:UpdateOpenIDConnectProviderThumbprintiam:CreateOpenIDConnectProvider,DeleteOpenIDConnectProvideriam:GetOpenIDConnectProvider,ListOpenIDConnectProviders
3. Dynamic Repository Detection
- Repository and organization names auto-detected from GitHub context
- OIDC trust policies use dynamic values
- Infrastructure portable for forkers
4. Base Image Caching (Re-enabled)
- Simplified Docker manifest parsing logic
- Non-blocking graceful error handling
- Caches Debian base to private ECR for faster builds
🚀 Expected Behavior
Complete GitHub Actions workflow should now:
- ✅ Authenticate via OIDC (passwordless)
- ✅ Deploy infrastructure with dynamic detection
- ✅ Build Docker image with pip packages
- ✅ Cache base images to private ECR
- ✅ Deploy Lambda function successfully
📦 Technical Details
- Fixed: Docker build failing at pip install phase
- Fixed: OIDC provider thumbprint update permission errors
- Fixed: Dynamic repository/org detection for portable infrastructure
- Improved: Base image caching with better error handling
Simplified image cache
CodeBuild Cache Script Fix
🔧 CodeBuild Fix
Fixed Docker Manifest Parsing:
- Improved digest extraction with multiple fallback methods
- More robust jq parsing for Docker manifest responses
- Handles edge cases where specific digest cannot be determined
- Prevents parsing errors that caused pre-build phase failures
What This Fixes:
- CodeBuild pre-build phase should now complete successfully
- Resolves
jq: error: Cannot index array with string "Descriptor" - Enables reliable Docker base image caching in ECR
Testing:
This release tests the complete GitHub Actions + OIDC + CodeBuild pipeline with all fixes applied:
- ✅ OIDC authentication with required permissions
- ✅ Dynamic repository detection
- ✅ Improved Docker manifest parsing
OIDC Permissions Fix
🔧 OIDC Authentication Fix
Added Missing IAM Permissions:
iam:UpdateOpenIDConnectProviderThumbprint- Required for updating OIDC provider thumbprintsiam:CreateOpenIDConnectProvider- For creating OIDC providersiam:DeleteOpenIDConnectProvider- For cleanup operationsiam:GetOpenIDConnectProvider- For reading OIDC provider detailsiam:ListOpenIDConnectProviders- For listing providers
What This Fixes:
- GitHub Actions should now be able to update OIDC provider thumbprints
- Resolves AccessDenied errors during infrastructure deployment
- Enables full OIDC-based authentication workflow
Testing:
This release will test the complete GitHub Actions + OIDC authentication flow with all required permissions.
Dynamic Repo Detection + OIDC Fix
🔧 Infrastructure Updates
Dynamic Repository Detection:
- Repository and organization names now detected automatically
- Supports both GitHub Actions and local development
- OIDC trust policies use dynamic repository information
- Makes infrastructure portable for forkers
OIDC Authentication Fix:
- Updated trust policy to allow release tag references
- Added debug logging for OIDC context
- Should resolve GitHub Actions OIDC authentication errors
Forker-Friendly:
- No hardcoded organization or repository names
- Infrastructure automatically adapts to any GitHub repository
- ESC environment names based on repository name
Pulumi Cache clean (test)
just a test of gh action with refreshed pulumi state