Skip to content

Complete Pipeline Fix - PEP 668 + OIDC + Caching

Choose a tag to compare

@loganpowell loganpowell released this 25 Oct 22:56
· 10 commits to dev since this release

πŸŽ‰ Complete Pipeline Fix

This release includes all fixes needed for a successful GitHub Actions + OIDC + CodeBuild deployment:

βœ… Fixed Issues

1. PEP 668 - Externally Managed Environment (Primary Issue)

  • Added --break-system-packages flag to pip install in Dockerfile
  • Resolves Python 3.11+ (Debian Bookworm) package installation restrictions
  • Allows Lambda Runtime Interface Client installation

2. OIDC Authentication

  • Added missing IAM permissions for OIDC provider management
  • iam:UpdateOpenIDConnectProviderThumbprint
  • iam:CreateOpenIDConnectProvider, DeleteOpenIDConnectProvider
  • iam:GetOpenIDConnectProvider, ListOpenIDConnectProviders

3. Dynamic Repository Detection

  • Repository and organization names auto-detected from GitHub context
  • OIDC trust policies use dynamic values
  • Infrastructure portable for forkers

4. Base Image Caching (Re-enabled)

  • Simplified Docker manifest parsing logic
  • Non-blocking graceful error handling
  • Caches Debian base to private ECR for faster builds

πŸš€ Expected Behavior

Complete GitHub Actions workflow should now:

  1. βœ… Authenticate via OIDC (passwordless)
  2. βœ… Deploy infrastructure with dynamic detection
  3. βœ… Build Docker image with pip packages
  4. βœ… Cache base images to private ECR
  5. βœ… Deploy Lambda function successfully

πŸ“¦ Technical Details

  • Fixed: Docker build failing at pip install phase
  • Fixed: OIDC provider thumbprint update permission errors
  • Fixed: Dynamic repository/org detection for portable infrastructure
  • Improved: Base image caching with better error handling