Skip to content

feat(#645): manage the full axiom resource set in the pulumi workspace - #666

Merged
zgeoff merged 2 commits into
mainfrom
645-axiom-resources
Jul 18, 2026
Merged

feat(#645): manage the full axiom resource set in the pulumi workspace#666
zgeoff merged 2 commits into
mainfrom
645-axiom-resources

Conversation

@zgeoff

@zgeoff zgeoff commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Description

Closes #645

Brings the remaining Axiom resources — the three vers-* datasets, the vers-production ingest and vers-mcp query tokens, and the baseline dashboard — under the vers-infra Pulumi program, so the whole observability backend is reviewable and drift-checked.

  • All six resources were imported into stack state before this PR; a --refresh --expect-no-changes preview passes, so no token rotated and nothing was recreated.
  • Datasets and tokens carry protect: true; vers-traces keeps its live axiom:events:v1 kind because a kind change forces a data-destroying replacement.
  • Token secret values stay in 1Password; the provider regenerates a token's secret on any argument change (48h grace), documented in infra/README.md.
  • The dashboard document serializes through a sorted-key, HTML-escaping JSON encoder so code stays byte-identical to the provider's Go-normalized state.
  • infra/tsconfig.json now extends tsconfig.base.json — its standalone ES2022 config broke type-aware linting of toSorted.
  • The provider's own credential (iac-token) stays console-managed: a token cannot rotate itself.

Testing

  • bun run typecheck passes
  • bun run test passes
  • bun run lint passes
  • New tests added for new functionality (infrastructure program — coverage is the drift-check preview)

Import the vers datasets, the ingest and query API tokens, and the baseline
dashboard into the vers-infra Pulumi program, alongside the monitors and
notifier already managed there. Imports were state-only adoptions verified
against a zero-change refresh preview — no token rotated, no resource
recreated.

- datasets carry protect: true; kind is declared to match live state since a
  kind change forces a data-destroying replacement
- token scopes mirror the live capabilities exactly; secret values stay in
  1Password, and the provider regenerates a token's secret on any arg change
- the dashboard document serializes through a Go-compatible JSON encoder
  (sorted keys, HTML escaping) so state stays byte-identical to code
- infra/tsconfig.json extends tsconfig.base.json so the type-aware linter
  resolves ES2024 lib types
- deployment and observability docs point at the program instead of the
  retired curl provisioning steps
@coderabbitai

coderabbitai Bot commented Jul 18, 2026

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Auto incremental reviews are disabled on this repository.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ccce77be-7f4c-4c4c-86ff-12831ef1946e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The Pulumi workspace now manages Axiom datasets, tokens, and a baseline dashboard. Infrastructure exports and TypeScript configuration were updated, while deployment and observability documentation now describe Pulumi provisioning, vault-managed secrets, token permissions, and drift reconciliation.

Changes

Axiom observability infrastructure

Layer / File(s) Summary
Axiom datasets, tokens, and dashboard
infra/axiom.ts
Adds protected trace, log, and metrics datasets, ingest and MCP query tokens, and a deterministically serialized baseline dashboard.
Infrastructure exports and provider configuration
infra/index.ts, infra/tsconfig.json, infra/README.md
Re-exports new identifiers, includes both Pulumi source files in TypeScript configuration, and documents Axiom resources, secret handling, and required permissions.
Provisioning and drift documentation
docs/architecture/deployment.md, docs/architecture/observability.md
Directs Axiom provisioning through Pulumi and documents token rotation, 1Password storage, and console-edit drift reconciliation.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Possibly related PRs

  • zgeoff/vers#606: Updates related Axiom deployment and observability documentation, including token and metrics-dataset provisioning.
  • zgeoff/vers#653: Extends the Pulumi Axiom infrastructure and exported monitor/notifier identifiers used by this change.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title matches the main change: managing the full Axiom resource set in Pulumi.
Description check ✅ Passed The description is directly about the Axiom Pulumi expansion and related docs/config changes.
Linked Issues check ✅ Passed The PR covers the datasets, ingest/query tokens, dashboard, docs, and safe import behavior, with the provider token left console-managed.
Out of Scope Changes check ✅ Passed The TypeScript config change supports the new Pulumi module and linting, so it is in scope.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 645-axiom-resources

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

🍹 preview on vers-infra/prod

Pulumi report
   Previewing update (prod):
Downloading plugin cloudflare-6.17.0: starting
Downloading plugin terraform-provider-1.2.0: starting
Downloading plugin cloudflare-6.17.0: done
Installing plugin cloudflare-6.17.0: starting
Downloading plugin terraform-provider-1.2.0: done
Installing plugin terraform-provider-1.2.0: starting
Installing plugin terraform-provider-1.2.0: done
@ previewing update....
Installing plugin cloudflare-6.17.0: done

@ previewing update.....
~  pulumi:pulumi:Stack vers-infra-prod refreshing 
~  pulumi:pulumi:Stack vers-infra-prod refreshing 
~  pulumi:providers:axiom axiom refreshing 
~  pulumi:providers:axiom axiom refresh 
~  axiom:index:Monitor vers-verification-lag refreshing 
~  cloudflare:index:DnsRecord resend-dkim refreshing 
~  cloudflare:index:DnsRecord resend-return-path-mx refreshing 
~  axiom:index:Dashboard vers-services-baseline refreshing 
~  axiom:index:Token vers-production refreshing 
~  cloudflare:index:DnsRecord apex refreshing 
~  axiom:index:Dataset vers-traces refreshing 
~  cloudflare:index:DnsRecord www refreshing 
~  axiom:index:Dataset vers-logs refreshing 
~  axiom:index:Dataset vers-metrics refreshing 
~  axiom:index:Monitor vers-5xx-responses refreshing 
~  axiom:index:Token vers-mcp refreshing 
~  cloudflare:index:DnsRecord resend-return-path-spf refreshing 
~  axiom:index:Notifier vers-alarms refreshing 
~  cloudflare:index:DnsRecord resend-dmarc refreshing 
~  cloudflare:index:DnsRecord resend-return-path-spf refresh 
~  cloudflare:index:DnsRecord resend-dmarc refresh 
~  cloudflare:index:DnsRecord apex refresh 
~  cloudflare:index:DnsRecord www refresh 
~  cloudflare:index:DnsRecord resend-return-path-mx refresh 
~  cloudflare:index:DnsRecord resend-dkim refresh 
~  axiom:index:Dataset vers-metrics refresh 
~  axiom:index:Dataset vers-logs refresh 
~  axiom:index:Dataset vers-traces refresh 
~  axiom:index:Notifier vers-alarms refresh 
~  axiom:index:Monitor vers-5xx-responses refresh 
~  axiom:index:Monitor vers-verification-lag refresh 
~  axiom:index:Token vers-production refresh 
~  axiom:index:Token vers-mcp refresh 
~  axiom:index:Dashboard vers-services-baseline refresh 
   pulumi:pulumi:Stack vers-infra-prod running 
@ previewing update.....
   pulumi:providers:axiom axiom  
   cloudflare:index:DnsRecord resend-return-path-spf  
   cloudflare:index:DnsRecord resend-dkim  
   cloudflare:index:DnsRecord resend-return-path-mx  
   cloudflare:index:DnsRecord www  
   cloudflare:index:DnsRecord resend-dmarc  
   cloudflare:index:DnsRecord apex  
   axiom:index:Token vers-mcp  
   axiom:index:Token vers-production  
   axiom:index:Dataset vers-metrics  
   axiom:index:Dataset vers-logs  
   axiom:index:Dataset vers-traces  
   axiom:index:Dashboard vers-services-baseline  
   axiom:index:Notifier vers-alarms  
   axiom:index:Monitor vers-5xx-responses  
   axiom:index:Monitor vers-verification-lag  
@ previewing update....
   pulumi:pulumi:Stack vers-infra-prod  
Resources:
   17 unchanged

   

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/architecture/observability.md`:
- Around line 69-72: Update the Axiom resource-management documentation to
clarify that token secret values are kept in 1Password as the source of truth
but may be stored in encrypted Pulumi stack state; remove the inaccurate claim
that they never reach state while preserving the surrounding drift-management
guidance.

In `@infra/axiom.ts`:
- Around line 10-16: Convert the declaration-level rationale comments near the
affected configurations in infra/axiom.ts to multiline JSDoc, attaching each
block directly to its enclosing declaration or configured property. Apply this
consistently to the referenced comment ranges, and retain // comments only for
statement-level commentary.
- Around line 70-83: Update the datasetCapabilities objects for both Axiom
tokens to explicitly include vers-traces, vers-logs, and vers-metrics as dataset
keys, preserving the existing ingests/create scope for the ingest token and
queries/read scope for mcpToken; remove the '*' entries.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6ca4e18b-aa16-487b-acf7-211908182c2a

📥 Commits

Reviewing files that changed from the base of the PR and between a22f628 and cc03c29.

📒 Files selected for processing (6)
  • docs/architecture/deployment.md
  • docs/architecture/observability.md
  • infra/README.md
  • infra/axiom.ts
  • infra/index.ts
  • infra/tsconfig.json

Comment thread docs/architecture/observability.md Outdated
Comment thread infra/axiom.ts Outdated
Comment thread infra/axiom.ts
Token secrets reach Pulumi stack state encrypted after a regeneration, so the
docs say that instead of claiming they never touch state. Declaration comments
in the Axiom program convert from // blocks to multiline JSDoc per the comment
conventions.
@zgeoff
zgeoff merged commit 8a694c0 into main Jul 18, 2026
7 checks passed
@zgeoff
zgeoff deleted the 645-axiom-resources branch July 18, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

manage the full Axiom resource set in the Pulumi workspace

1 participant