Skip to content

fix(cloudfront): map CFn->SDK casing/shapes and merge UpdateDistribution config #2964

fix(cloudfront): map CFn->SDK casing/shapes and merge UpdateDistribution config

fix(cloudfront): map CFn->SDK casing/shapes and merge UpdateDistribution config #2964

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
check-build-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: voidzero-dev/setup-vp@ca1c46663915d6c1042ae23bd39ab85718bfb0fa # v1
with:
node-version: "24"
cache: true
run-install: false
- run: vp install --frozen-lockfile
- run: vp run check
# Issue #1133 — `vp run check` type-checks tsconfig.json only (src/** +
# types/**), which excludes `**/*.test.ts`. Type-check the test project
# separately so a wrong `import type` or a stale mock shape in a test
# file fails CI instead of slipping through.
- run: vp run typecheck:test
- run: vp run test
- run: vp run build
# Issue #399 — fail CI when docs/integ-coverage.md or
# docs/_generated/integ-coverage.json is stale relative to
# src/provisioning/register-providers.ts +
# tests/integration/*/{lib,bin}/*.ts. Regenerate via the same
# `vp run integ-coverage` task the contributor would run, then
# fail-on-diff. Closes the "forgot to regenerate after editing"
# gap that the /verify-pr skill step is the manual fallback for.
- name: integ-coverage matrix is up-to-date
run: |
vp run integ-coverage
if ! git diff --quiet -- docs/integ-coverage.md docs/_generated/integ-coverage.json; then
echo "::error::integ-coverage matrix is stale — run \`vp run integ-coverage\` and commit the regenerated docs/integ-coverage.md + docs/_generated/integ-coverage.json"
git --no-pager diff -- docs/integ-coverage.md docs/_generated/integ-coverage.json
exit 1
fi
# Issue #1071 — fail CI when docs/cli-flag-coverage.md or
# docs/_generated/cli-flag-coverage.json is stale relative to the
# declared CLI flags (src/cli/options.ts) + tests/integration/*/verify.sh.
# Same `vp run ... && git diff --exit-code` shape as the
# integ-coverage step above. This is a STALENESS guard only (the
# generated file must track its inputs); it deliberately does NOT
# hard-fail on low coverage % — many flags are unit-tested rather
# than exercised in an integ verify.sh (see the report's own
# "VISIBILITY report, not a CI gate" note). Closes the gap where the
# matrix had not been regenerated since PR #504 and drifted silently.
- name: cli-flag-coverage matrix is up-to-date
run: |
vp run cli-flag-coverage
if ! git diff --quiet -- docs/cli-flag-coverage.md docs/_generated/cli-flag-coverage.json; then
echo "::error::cli-flag-coverage matrix is stale — run \`vp run cli-flag-coverage\` and commit the regenerated docs/cli-flag-coverage.md + docs/_generated/cli-flag-coverage.json"
git --no-pager diff -- docs/cli-flag-coverage.md docs/_generated/cli-flag-coverage.json
exit 1
fi
# Issue #1112 — fail CI when docs/_generated/integ-last-run.tsv breaks
# its "exactly one row per test" invariant or its sorted order. The
# ledger is an update-type file, but /run-integ appends to it, so a
# rebase replays the append against a base that already carries the
# row and git auto-merge takes BOTH sides — 10 tests on main had
# silently accumulated duplicates that way. `vp run
# integ-ledger-normalize` rewrites the whole file deterministically
# (newest row per test, sorted by test name), which is both the
# rebase-safe write path and the invariant check: a replayed commit
# now produces an IDENTICAL file rather than an additive diff. Same
# `vp run ... && git diff --exit-code` shape as the matrix steps
# above. The script ALSO hard-fails on a malformed row (wrong column
# count / unparseable timestamp) rather than dropping it silently, so
# this step covers both classes.
- name: integ-last-run ledger is normalized
run: |
vp run integ-ledger-normalize
if ! git diff --quiet -- docs/_generated/integ-last-run.tsv; then
echo "::error::integ-last-run ledger is not normalized (duplicate rows or wrong order) — run \`vp run integ-ledger-normalize\` and commit docs/_generated/integ-last-run.tsv"
git --no-pager diff -- docs/_generated/integ-last-run.tsv
exit 1
fi
# Issue #398 — fail CI when the cached three-tier provider-coverage
# audit (docs/_generated/provider-coverage.json) Tier 1 list drifts
# from src/provisioning/register-providers.ts. Offline check (<1s,
# no AWS calls — the full regeneration via
# `vp run audit:coverage:regenerate` would take 10-30 min + AWS
# CFn DescribeType throttling and stays a manual / future-cron job
# per issue #398 Option A). Catches the "added a new provider but
# forgot to regen the audit cache" case structurally, mirroring
# the integ-coverage step above.
- run: vp run audit:coverage:check
# Issue #423 — fail CI when docs/scenario-coverage.md or
# docs/_generated/scenario-coverage.json is stale relative to
# the KNOWN_SCENARIOS taxonomy in
# scripts/build-scenario-coverage-matrix.ts and the per-fixture
# tests/integration/<name>/.scenarios.json sidecars. Same shape as
# the integ-coverage step above. The script ALSO hard-fails on a
# sidecar carrying an unknown tag (typo guard), so the step covers
# both "forgot to regenerate" and "wrote a typo tag" classes.
- name: scenario-coverage matrix is up-to-date
run: |
vp run scenario-coverage
if ! git diff --quiet -- docs/scenario-coverage.md docs/_generated/scenario-coverage.json; then
echo "::error::scenario-coverage matrix is stale — run \`vp run scenario-coverage\` and commit the regenerated docs/scenario-coverage.md + docs/_generated/scenario-coverage.json"
git --no-pager diff -- docs/scenario-coverage.md docs/_generated/scenario-coverage.json
exit 1
fi
# Fail CI when src/provisioning/unsupported-types.generated.ts is stale
# relative to docs/_generated/provider-coverage.json (tier3). The runtime
# pre-flight reads the generated module, so it must track the audit cache.
# Same shape as the integ-coverage / scenario-coverage staleness guards.
- name: unsupported-types module is up-to-date
run: |
vp run gen:unsupported-types
if ! git diff --quiet -- src/provisioning/unsupported-types.generated.ts; then
echo "::error::src/provisioning/unsupported-types.generated.ts is stale — run \`vp run gen:unsupported-types\` and commit the regenerated module"
git --no-pager diff -- src/provisioning/unsupported-types.generated.ts
exit 1
fi
# Fail CI when src/provisioning/property-coverage.generated.ts is stale
# relative to the CFn schema fixtures + each SDK provider's
# handledProperties / unhandledByDesign declarations. The runtime
# property-level pre-flight (ProviderRegistry.validateResourceProperties)
# reads the generated module, so it must track the source data.
# The codegen writes a raw multi-line shape; the committed module is
# Prettier-formatted, so we run `vp run format` after the codegen to
# canonicalize before diffing (mirrors how the file was written at
# scaffold time in 476d3c1).
- name: property-coverage module is up-to-date
run: |
vp run gen:property-coverage
vp run format
if ! git diff --quiet -- src/provisioning/property-coverage.generated.ts; then
echo "::error::src/provisioning/property-coverage.generated.ts is stale — run \`vp run gen:property-coverage && vp run format\` and commit the regenerated module"
git --no-pager diff -- src/provisioning/property-coverage.generated.ts
exit 1
fi
# Fail CI when docs/_generated/enrichment-coverage.{json,md} is stale
# relative to the CFn schema fixtures + the enrichResourceAttributes
# switch in src/provisioning/cloud-control-provider.ts. The matrix records
# which CC-routable types' computed readOnly Fn::GetAtt attributes are
# populated by enrichment (the bug class fixed in #844/#864/#865/#866).
# Same diff-on-stale shape as the integ-coverage / property-coverage
# guards above. The second step is the CRITIC: it hard-fails on a pure-CC
# (no-SDK-provider) latent gap that is neither enriched nor allow-listed.
- name: enrichment-coverage matrix is up-to-date
run: |
vp run gen:enrichment-coverage
if ! git diff --quiet -- docs/_generated/enrichment-coverage.json docs/_generated/enrichment-coverage.md; then
echo "::error::enrichment-coverage matrix is stale — run \`vp run gen:enrichment-coverage\` and commit the regenerated docs/_generated/enrichment-coverage.{json,md}"
git --no-pager diff -- docs/_generated/enrichment-coverage.json docs/_generated/enrichment-coverage.md
exit 1
fi
- run: vp run audit:enrichment-coverage:check
# Fail CI when docs/_generated/sdk-attr-coverage.{json,md} is stale
# relative to the CFn schema fixtures + each SDK provider's create/update
# attribute keys + the constructAttribute type coverage. The matrix records
# which SDK-backed types' read-only Arn/Url Fn::GetAtt attributes are
# resolvable (cached by the provider OR constructAttribute-handled); a gap
# is the #1179 deploy-break class. The second step is the CRITIC: it
# hard-fails on any unresolvable Arn/Url attribute that is not allow-listed.
- name: sdk-attr-coverage matrix is up-to-date
run: |
vp run gen:sdk-attr-coverage
if ! git diff --quiet -- docs/_generated/sdk-attr-coverage.json docs/_generated/sdk-attr-coverage.md; then
echo "::error::sdk-attr-coverage matrix is stale — run \`vp run gen:sdk-attr-coverage\` and commit the regenerated docs/_generated/sdk-attr-coverage.{json,md}"
git --no-pager diff -- docs/_generated/sdk-attr-coverage.json docs/_generated/sdk-attr-coverage.md
exit 1
fi
- run: vp run audit:sdk-attr-coverage:check
# Fail CI when docs/_generated/update-wrap-coverage.{json,md} is stale
# relative to the provider sources. The matrix records, per provider
# class declaring update(), whether every AWS `send` reachable from
# update() (following this.x() delegation edges) is wrapped in a
# ProvisioningError — and whether that wrap re-throws cdkd-typed errors
# untouched. An unwrapped send is the #1263 / #1267 class (a raw SDK
# error bypassing cdkd's exit-code handling); an unguarded wrap silently
# disables the deploy engine's by-class replacement fallback. The second
# step is the CRITIC: it hard-fails on either, unless allow-listed.
- name: update-wrap-coverage matrix is up-to-date
run: |
vp run gen:update-wrap-coverage
if ! git diff --quiet -- docs/_generated/update-wrap-coverage.json docs/_generated/update-wrap-coverage.md; then
echo "::error::update-wrap-coverage matrix is stale — run \`vp run gen:update-wrap-coverage\` and commit the regenerated docs/_generated/update-wrap-coverage.{json,md}"
git --no-pager diff -- docs/_generated/update-wrap-coverage.json docs/_generated/update-wrap-coverage.md
exit 1
fi
- run: vp run audit:update-wrap-coverage:check
runtime-compat:
runs-on: ubuntu-latest
needs: check-build-test
strategy:
matrix:
node-version: [20, 22, 24]
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: voidzero-dev/setup-vp@ca1c46663915d6c1042ae23bd39ab85718bfb0fa # v1
with:
node-version: "24"
cache: true
run-install: false
- run: vp install --frozen-lockfile
- run: vp run build
- run: vp env exec --node ${{ matrix.node-version }} node dist/cli.js --version