Promotion 2026-08-25 anvilprod (#8245, #8255, #8282, DataBiosphere/azul-private#377, DataBiosphere/azul-private#414) - #8262
Merged
Conversation
These targets ran scripts/rename_resources.py and scripts/import_default_vpc.py as part of every plan/apply/destroy. Both scripts are no longer needed and have been moved to the attic. All downstream targets now depend directly on validate. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Move aws_kms_key and aws_kms_alias resources from the main component into a new `base` component that is applied before `make lambdas`. This eliminates the chicken-and-egg problem where Lambda packaging needs the KMS keys to exist but they were created by the same Terraform apply that depends on the Lambda packages. The main component now uses data source lookups for the KMS key ARNs and `removed` blocks to drop the resources from its state without destroying them. The base component uses `import` blocks to adopt the existing keys during the first apply. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…ul-private#377) The test for the unit `_log_request` reproduces the leak of the `authorization` header value in the `Received … request` log message. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…ul-private#377) The `CaseInsensitiveMapping` branch of `_LogJSONEncoder` serialized request headers verbatim. Apply `redact_header` (renamed from the private `_redact_header`) to each header value, using the same policy as `LoggingHttpClient`: pattern-based redaction, falling back to full redaction for `authorization` headers with unrecognized secret types. Also rename `_redact_headers` to `redact_headers` and add a `Mapping[str, str]` type hint to its `headers` parameter. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…here/azul-private#377) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…-private#377) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Issue dependencies are now expressed with GitHub's built-in issue dependencies, PR merge order with the field of the same name in the Azul project, and pipelines with the statuses of that project. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Developers may still chain PRs while working on them, but a PR must be unchained and its base PR merged before review of it can be requested. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…updates Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## anvilprod #8262 +/- ##
=============================================
- Coverage 84.54% 84.54% -0.01%
=============================================
Files 166 169 +3
Lines 24577 25248 +671
=============================================
+ Hits 20779 21345 +566
- Misses 3798 3903 +105 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
hannes-ucsc
force-pushed
the
promotions/2026-08-25-anvilprod
branch
2 times, most recently
from
August 28, 2026 22:09
3ed7782 to
273ddbe
Compare
#8245 (comment) Derive HTTP timeout from Lambda context's remaining time Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
hannes-ucsc
force-pushed
the
promotions/2026-08-25-anvilprod
branch
from
August 29, 2026 03:52
273ddbe to
2aeed9a
Compare
#8245 (comment) Add RateLimitingCacheService Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
hannes-ucsc
force-pushed
the
promotions/2026-08-25-anvilprod
branch
from
August 29, 2026 06:32
2aeed9a to
e58c1c7
Compare
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…size (DataBiosphere/azul-private#414) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ate#377) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
hannes-ucsc
force-pushed
the
promotions/2026-08-25-anvilprod
branch
from
September 2, 2026 16:14
38a175c to
fab6d3e
Compare
hannes-ucsc
added a commit
that referenced
this pull request
Sep 2, 2026
7 tasks
…ng (#8282) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was
linked to
issues
Sep 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linked issues: #8245, #8255, #8282, DataBiosphere/azul-private#377, DataBiosphere/azul-private#414
Checklist
Author
anvilprodpromotions/yyyy-mm-dd-anvilprodPromotion yyyy-mm-ddanvilprodAuthor (reindex)
reindex:anvilprodor the changes introduced by it will not require reindexing ofanvilprodreindex:partialand its description documents the specific reindexing procedure foranvilprodor requires a full reindex or is not labeledreindex:anvilprodAuthor (mirror)
mirror:anvilprodor the changes introduced by it will not require mirroring ofanvilprodmirror:partialand its description documents the specific mirroring procedure foranvilprodor requires a full mirroring or is not labeledmirror:anvilprodAuthor (upgrading deployments)
upgradeor does not require upgrading deploymentsdeploy:sharedor does not modifydocker_images.json, and does not require deploying thesharedcomponent for any other reasondeploy:gitlabor does not require deploying thegitlabcomponentdeploy:runneror does not require deploying therunnerimageAuthor (before every review)
anvilprodinto PR branch to integrate upstream changes)System administrator (after approval)
no sandboxN reviewslabel is accurateOperator
Operator (deploy
.sharedand.gitlabcomponents)_select anvilprod.shared && CI_COMMIT_REF_NAME=anvilprod make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:shared_select anvilprod.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlab_select anvilprod.gitlab && CI_COMMIT_REF_NAME=anvilprod make -C terraform/gitlab apply(an error from _login_docker_gitlab is benign if the instance was stopped for backup) or this PR is not labeleddeploy:gitlabdeploy:gitlabdeploy:gitlabSystem administrator (post-deploy of
.gitlabcomponent)anvilprod.gitlabare complete or this PR is not labeleddeploy:gitlabOperator (deploy runner image)
_select anvilprod.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runnerOperator (sandbox build)
sandboxlabel or PR is labeledno sandboxanvilprodor PR is labeledno sandboxhammerboxdeployment or PR is labeledno sandboxhammerboxdeployment or PR is labeledno sandboxhammerboxor this PR is not labeledupgrade, or upgrade instructions do not apply tohammerboxhammerbox, deleted the catalogs specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothhammerbox, deindexed the sources sepcified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothhammerbox, indexed the sources specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothhammerbox, indexed the catalogs specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothhammerboxor this PR is not labeledreindex:anvilprodor it is labeled reindex:partialhammerboxor this PR is not labeledreindex:anvilprodhammerboxor this PR is not labeledmirror:anvilprodhammerboxor this PR is not labeledmirror:anvilprodOperator (merge the branch)
ptagsOperator (main build)
anvilprodanvilprodanvilprodanvilprodor this PR is not labeledupgrade, or upgrade instructions do not apply toanvilprod_select anvilprod.shared && make -C terraform/shared applyor this PR is not labeleddeploy:sharedanvilprod1 Promoted issues and PRs are referenced in the titles of the commits
that the promotion branch introduces to the stable branch. Prior to the
promotion, the status of promoted issues (PRs) is Lower (Merged lower).
Promoted PRs in status Done do not need to be moved.
Operator (reindex)
anvilprod, deleted the catalogs specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothanvilprod, deindexed the sources sepcified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothanvilprod, indexed the sources specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothanvilprod, indexed the catalogs specified in the notes or this PR is missing either thereindex:partialor thereindex:anvilprodlabel, or bothanvilprodor this PR is not labeledreindex:anvilprodor it is labeled reindex:partialanvilprodor this PR is not labeledreindex:anvilprodor it is labeled reindex:partialanvilprodor this PR is not labeledreindex:anvilprodor it is labeled reindex:partialanvilprodor this PR is not labeledreindex:anvilproddeploy_browserjob in the GitLab pipeline for this PR inanvilprodor this PR is not labeledreindex:anvilprodOperator (mirroring)
anvilprodor this PR is not labelledmirror:anvilprodanvilprodor this PR is not labelledmirror:anvilprodanvilprodor this PR is not labelledmirror:anvilprodOperator
System administrator
Shorthand for review comments
Lline is too longWline wrapping is wrongQbad quotesFother formatting problem