feat(compute): add AWS Lambda MicroVMs ComputeStrategy backend — P1 (#645) - #689
Draft
dreamorosi wants to merge 1 commit into
Draft
feat(compute): add AWS Lambda MicroVMs ComputeStrategy backend — P1 (#645)#689dreamorosi wants to merge 1 commit into
dreamorosi wants to merge 1 commit into
Conversation
…ws-samples#645) Implement Phase P1 of ADR-021: the lambda-microvm compute backend (start/poll/stop), its CDK infrastructure, bootstrap policy, CLI support, and regional-availability enforcement. Suspend/resume (P3) and agent-side hook serving / smoke parity (P2) follow separately; a P1-built image is documented as not yet runnable end to end. Handlers (cdk/src/handlers): - ComputeType widens to 'agentcore' | 'ecs' | 'lambda-microvm'; SessionHandle gains {microvmId, endpoint}; SessionStatus gains 'suspended'; resolveComputeStrategy keeps the exhaustive-never gate - LambdaMicrovmComputeStrategy: RunMicrovm with idlePolicy omitted (auto-suspend disabled by construction) and maximumDurationInSeconds=28800 (AgentCore 8h parity); payload inline in runHookPayload up to exactly 16384 bytes, S3 pointer above; GetMicrovm poll maps the six-state MicrovmState enum mechanically (no task-state interpretation in the strategy); TerminateMicrovm best-effort with differentiated error handling; errors wrapped with a MicroVM marker so classifier entries cannot leak retry semantics onto other backends (regression-pinned) - Orchestrator: persists {microvmId, endpoint} to compute_metadata; cross-references substrate state vs DynamoDB (terminal + non- terminal -> failed with confirm re-read; suspended + non- AWAITING_APPROVAL -> anomaly event, no fail-fast); finalization and cancellation terminate the MicroVM (cancel branch ordered before the AgentCore RUNTIME_ARN fallback to avoid stopping an unrelated runtime in mixed deployments) Infra (cdk/src/constructs, stacks, bootstrap): - LambdaMicrovmCompute construct: CfnMicrovmImage + CfnNetworkConnector L1s (platform-VPC egress, 443-only SG), build/ execution roles trusted by lambda.amazonaws.com with sts:TagSession + aws:SourceAccount, execution role admitted via AgentSessionRole.admitComputeRole, payload bucket (1-day expiry, execution-role read-only, orchestrator put-only), three documented image-config states with mutually exclusive synth warnings - IAM scoped to the exact image ARN (+ ':*' version hedge; image names cannot contain ':') — no microvm-image:* wildcard anywhere; orchestrator gets only RunMicrovm/GetMicrovm/TerminateMicrovm/ PassNetworkConnector + scoped iam:PassRole; cancel Lambda gets TerminateMicrovm only; no Suspend/Resume/auth-token grants (P3) - Synth-time region gate (5 launch regions) with microvm_region_override escape hatch; token regions skipped - Bootstrap: conditional IaCRole-ABCA-Compute-LambdaMicrovms policy behind ComputeTypes (1.2.0 -> 1.3.0), deploy-time actions only; DEPLOYMENT_ROLES.md golden block [5] + golden-baseline parity test - abca:compute-backend=lambda-microvm cost tags; scripts/package-microvm-artifact.sh for the zip+Dockerfile flow CLI (cli/src): - Onboarding probes availability (ListManagedMicrovmImages) on the EFFECTIVE compute type (flag ?? stored ?? default) before any write, rejecting with launch-region list + agentcore/ecs remedy - platform doctor check when an active blueprint uses the backend (access-denied -> warn per checkBedrockModel precedent); runtime status groups the substrate like ECS ADR-021 refined in place (proposed): six-state poll mapping table, GetMicrovm NotFound -> completed rationale, microvmId vs microvmIdentifier seam, per-hook phasing table and the explicit "P1 image is not runnable end to end" consequence. Verification: cdk 141 suites / 2744 tests; cli 52 suites / 651 tests; tsc + eslint clean in both; types-sync green; knip at baseline (78); bootstrap generation and docs sync deterministic. Refs aws-samples#645 Co-authored-by: Claude <noreply@anthropic.com>
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #689 +/- ##
=======================================
Coverage ? 90.80%
=======================================
Files ? 246
Lines ? 61358
Branches ? 6522
=======================================
Hits ? 55716
Misses ? 5642
Partials ? 0 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Member
Author
|
I'll address the CI comments tomorrow |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements Phase P1 of ADR-021 (#688): the
lambda-microvmcompute backend — strategy (start/poll/stop), CDK infrastructure, bootstrap policy, CLI support, and layered regional-availability enforcement. AgentCore remains the default. Suspend/resume is P3; agent-side hook serving and smoke parity are P2 — the ADR and the construct both warn explicitly that a P1-built image is not runnable end to end.Strategy reports, orchestrator interprets
LambdaMicrovmComputeStrategy.pollSessionmaps the six-stateMicrovmStateenum mechanically (SessionStatusgains'suspended'); the orchestrator cross-references DynamoDB — substrate-terminal + non-terminal status → failed (with a confirm re-read to avoid failing a successful fast teardown),suspended+ non-AWAITING_APPROVAL→ anomaly event, no fail-fast.RunMicrovmalways omitsidlePolicy(auto-suspend disabled by construction, asserted by tests) and pinsmaximumDurationInSecondsat 28 800 s (AgentCore 8 h parity). Strategy errors carry aMicroVM <op> failedmarker so the new classifier entries cannot change agentcore/ECS retry semantics — pinned by regression tests against the pre-changeUNKNOWNshape.No image wildcards in IAM
Every grant is scoped to the exact image ARN (bare names are resolved via
formatArn; a':*'sibling covers version-qualified forms — image names cannot contain:).microvmConfig.imageArnis compiler-required, so the account-wide fallback cannot return silently. Orchestrator gets exactlyRunMicrovm/GetMicrovm/TerminateMicrovm/PassNetworkConnector+ scopediam:PassRole; the cancel Lambda getsTerminateMicrovmonly; no Suspend/Resume/auth-token grants anywhere (P3), asserted by tests including on the generated bootstrap JSON.Regional availability enforced in layers
Synth-time gate on the 5 launch regions with a
microvm_region_overrideescape hatch (token regions skipped, documented); CLI onboarding probesListManagedMicrovmImageson the effective compute type (flag ?? stored ?? default) before any write;platform doctorprobes when an active blueprint uses the backend; orchestration-time classification is non-retryable with a configuration remedy.Cancellation ordering fix worth reviewer attention
The new
lambda-microvmbranch incancel-task.tsis deliberately placed before theagentRuntimeArnfallback:RUNTIME_ARNis set stack-wide whenever AgentCore stop is wired, so a MicroVM task would otherwise have invokedStopRuntimeSessionagainst an unrelated runtime in mixed deployments. Pinned by a regression test.ADR-021 refined in place (
proposed): six-state poll-mapping table,GetMicrovmNotFound →completedrationale,microvmId/microvmIdentifierseam, per-hook phasing table.Verification: cdk 141 suites / 2 744 tests, cli 52 / 651, tsc + eslint clean in both, types-sync green, knip at baseline (78), bootstrap generation and docs sync deterministic.
DEPLOYMENT_ROLES.mdgains golden policy block [5] with test parity.Refs #645