Skip to content

Releases: loganpowell/knock-lambda

explicit lambda URL sharing permissions fix

Choose a tag to compare

@loganpowell loganpowell released this 27 Oct 17:56

What Changed
The AWS update requires us to explicitly declare the permissions that were previously implicit.

Before the fix:

❌ Missing explicit permissions (worked due to temporary AWS exception)
After the fix:

✅ Explicit lambda:InvokeFunctionUrl permission with principal=''
✅ Explicit lambda:InvokeFunction permission with principal='
'
✅ Same public access as before

Better Setup

Choose a tag to compare

@loganpowell loganpowell released this 27 Oct 03:25

...

Dev Release v0.0.16

Dev Release v0.0.16 Pre-release
Pre-release

Choose a tag to compare

@loganpowell loganpowell released this 27 Oct 00:44

Testing new features

Split Stack with OIDC separated

Choose a tag to compare

@loganpowell loganpowell released this 27 Oct 00:32
  • Deduplicates shared resources
  • Leans heavily on Pulumi ESC

Complete Pipeline Fix - PEP 668 + OIDC + Caching

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 22:56

🎉 Complete Pipeline Fix

This release includes all fixes needed for a successful GitHub Actions + OIDC + CodeBuild deployment:

✅ Fixed Issues

1. PEP 668 - Externally Managed Environment (Primary Issue)

  • Added --break-system-packages flag to pip install in Dockerfile
  • Resolves Python 3.11+ (Debian Bookworm) package installation restrictions
  • Allows Lambda Runtime Interface Client installation

2. OIDC Authentication

  • Added missing IAM permissions for OIDC provider management
  • iam:UpdateOpenIDConnectProviderThumbprint
  • iam:CreateOpenIDConnectProvider, DeleteOpenIDConnectProvider
  • iam:GetOpenIDConnectProvider, ListOpenIDConnectProviders

3. Dynamic Repository Detection

  • Repository and organization names auto-detected from GitHub context
  • OIDC trust policies use dynamic values
  • Infrastructure portable for forkers

4. Base Image Caching (Re-enabled)

  • Simplified Docker manifest parsing logic
  • Non-blocking graceful error handling
  • Caches Debian base to private ECR for faster builds

🚀 Expected Behavior

Complete GitHub Actions workflow should now:

  1. ✅ Authenticate via OIDC (passwordless)
  2. ✅ Deploy infrastructure with dynamic detection
  3. ✅ Build Docker image with pip packages
  4. ✅ Cache base images to private ECR
  5. ✅ Deploy Lambda function successfully

📦 Technical Details

  • Fixed: Docker build failing at pip install phase
  • Fixed: OIDC provider thumbprint update permission errors
  • Fixed: Dynamic repository/org detection for portable infrastructure
  • Improved: Base image caching with better error handling

Simplified image cache

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 22:46

...

CodeBuild Cache Script Fix

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 21:57

🔧 CodeBuild Fix

Fixed Docker Manifest Parsing:

  • Improved digest extraction with multiple fallback methods
  • More robust jq parsing for Docker manifest responses
  • Handles edge cases where specific digest cannot be determined
  • Prevents parsing errors that caused pre-build phase failures

What This Fixes:

  • CodeBuild pre-build phase should now complete successfully
  • Resolves jq: error: Cannot index array with string "Descriptor"
  • Enables reliable Docker base image caching in ECR

Testing:
This release tests the complete GitHub Actions + OIDC + CodeBuild pipeline with all fixes applied:

  • ✅ OIDC authentication with required permissions
  • ✅ Dynamic repository detection
  • ✅ Improved Docker manifest parsing

OIDC Permissions Fix

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 21:42

🔧 OIDC Authentication Fix

Added Missing IAM Permissions:

  • iam:UpdateOpenIDConnectProviderThumbprint - Required for updating OIDC provider thumbprints
  • iam:CreateOpenIDConnectProvider - For creating OIDC providers
  • iam:DeleteOpenIDConnectProvider - For cleanup operations
  • iam:GetOpenIDConnectProvider - For reading OIDC provider details
  • iam:ListOpenIDConnectProviders - For listing providers

What This Fixes:

  • GitHub Actions should now be able to update OIDC provider thumbprints
  • Resolves AccessDenied errors during infrastructure deployment
  • Enables full OIDC-based authentication workflow

Testing:
This release will test the complete GitHub Actions + OIDC authentication flow with all required permissions.

Dynamic Repo Detection + OIDC Fix

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 21:36

🔧 Infrastructure Updates

Dynamic Repository Detection:

  • Repository and organization names now detected automatically
  • Supports both GitHub Actions and local development
  • OIDC trust policies use dynamic repository information
  • Makes infrastructure portable for forkers

OIDC Authentication Fix:

  • Updated trust policy to allow release tag references
  • Added debug logging for OIDC context
  • Should resolve GitHub Actions OIDC authentication errors

Forker-Friendly:

  • No hardcoded organization or repository names
  • Infrastructure automatically adapts to any GitHub repository
  • ESC environment names based on repository name

Pulumi Cache clean (test)

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 21:25

just a test of gh action with refreshed pulumi state