Repository navigation
Complete Pipeline Fix - PEP 668 + OIDC + Caching
π Complete Pipeline Fix
This release includes all fixes needed for a successful GitHub Actions + OIDC + CodeBuild deployment:
β Fixed Issues
1. PEP 668 - Externally Managed Environment (Primary Issue)
- Added
--break-system-packagesflag to pip install in Dockerfile - Resolves Python 3.11+ (Debian Bookworm) package installation restrictions
- Allows Lambda Runtime Interface Client installation
2. OIDC Authentication
- Added missing IAM permissions for OIDC provider management
iam:UpdateOpenIDConnectProviderThumbprintiam:CreateOpenIDConnectProvider,DeleteOpenIDConnectProvideriam:GetOpenIDConnectProvider,ListOpenIDConnectProviders
3. Dynamic Repository Detection
- Repository and organization names auto-detected from GitHub context
- OIDC trust policies use dynamic values
- Infrastructure portable for forkers
4. Base Image Caching (Re-enabled)
- Simplified Docker manifest parsing logic
- Non-blocking graceful error handling
- Caches Debian base to private ECR for faster builds
π Expected Behavior
Complete GitHub Actions workflow should now:
- β Authenticate via OIDC (passwordless)
- β Deploy infrastructure with dynamic detection
- β Build Docker image with pip packages
- β Cache base images to private ECR
- β Deploy Lambda function successfully
π¦ Technical Details
- Fixed: Docker build failing at pip install phase
- Fixed: OIDC provider thumbprint update permission errors
- Fixed: Dynamic repository/org detection for portable infrastructure
- Improved: Base image caching with better error handling