github cloudposse/atmos v1.231.1-rc.0

pre-release2 hours ago
fix(ci): tap homebrew/core before bumping the Homebrew formula @aknysh (#3336) ## what
  • Tap homebrew/core before brew bump-formula-pr in the release "Bump Homebrew formula" step (.github/workflows/build.yml).
  • Correct the step comment, which incorrectly claimed no tap was needed.
  • Add a fix-log (docs/fixes/2026-10-09-homebrew-bump-needs-core-tap.md).

why

The "Bump Homebrew formula" step fails on every release with No available formula with the name "atmos", most recently on v1.231.0 (run 37862125521). Every Homebrew bump has had to be done manually (v1.228.0, v1.229.0, v1.230.0, v1.230.1, and now v1.231.0 via homebrew-core PR #316660).

brew bump-formula-pr is a developer command that edits the formula's .rb file, so it needs homebrew/core checked out as a local tap. A fresh runner uses the formulae API with no tap, so the formula file does not exist locally and the command can't resolve atmos. Dropping HOMEBREW_NO_INSTALL_FROM_API (#3240) never fixed this because the tap was still absent either way — the earlier dry-run that appeared to prove API mode worked was run on a machine that already had homebrew/core tapped, exactly the condition CI lacks.

Verified locally: the exact CI command fails with No available formula when homebrew/core is not tapped, and resolves atmos (reaching the duplicate-PR check) once it is. brew tap homebrew/core exits 0 on current Homebrew (7.0.8) — still permitted, just no longer implicit. This step only runs on release: published, so it can't be exercised by a PR check; the next release is the first real confirmation.

references

  • Supersedes the incorrect root-cause conclusion in #3240.
  • Related earlier fix: #3229 (brew shellenv PATH fix).

Summary by CodeRabbit

  • Bug Fixes

    • Updated Homebrew release publishing to tap homebrew/core before bumping the formula.
  • Documentation

    • Added guidance on the Homebrew tap requirement and dry-run results.
fix(ci): dedupe govulncheck SARIF stacks via ci:vulncheck mage target @osterman (#3347) ## what
  • Add a ci:vulncheck <output> Mage target that runs govulncheck -format sarif ./... and removes exact duplicate stack objects from the report before writing it.
  • Point the govulncheck job in codeql.yml at the target instead of redirecting the scanner's output straight into govulncheck.sarif.
  • The logic lives in a new internal/ci/vulncheck package with unit tests; the target is listed in magefiles/README.md.
  • The report replaces the output file atomically, and only after the scan succeeded and its output parsed as SARIF. A scanner failure, empty output, or malformed output fails the step and leaves any existing report untouched.

why

  • Job 113647222434 finished the scan but failed the SARIF upload: results 5, 11, 12, 13 and 15 contained duplicate stacks entries, and the SARIF schema requires that array to hold unique objects. Code scanning therefore received nothing.
  • Only complete duplicates are dropped. Every finding and every distinct stack (different message, different frame order) is kept, in its original position.
  • It is a Mage target, not workflow shell with jq, because the repo keeps CI logic of this size in unit-tested Go. A shell version also could not distinguish "no findings" from "scanner produced nothing", which matters when the output is uploaded to code scanning.
  • Coverage is 90.8% for the new package.

references

  • Failing job: https://github.com/cloudposse/atmos/actions/runs/37876824022/job/113647222434
  • Overlaps with #3339, which carries an earlier jq + shell-script version of the same fix (scripts/dedupe-sarif-stacks.jq, scripts/test-dedupe-sarif-stacks.sh, the codeql.yml step, and docs/fixes/2026-10-08-govulncheck-sarif-duplicate-stacks.md). Those pieces should be dropped from #3339 once this lands, so they do not conflict on codeql.yml.
  • The full scan and the code-scanning upload only run in CI; the call-graph pass is too expensive to repeat locally. Locally verified with a stand-in govulncheck through go tool mage ci:vulncheck.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Vulnerability scan reports now remove duplicate stack entries before submission, preventing duplicate-entry errors. Reports are preserved if scanning or report processing fails.
  • Chores
    • Updated the vulnerability scan workflow and artifact handling to improve CI reliability.
  • Documentation
    • Added guidance on vulnerability scan report handling and validation.

🚀 Enhancements

fix(config): preserve imported auth identities when main config defines identities @osterman (#3339) ## what
  • Identities from explicit imports, atmos.d / .atmos.d fragments, profiles, and provisioned identity files now survive when the main atmos.yaml also declares identities.
  • Source YAML is tracked per load, in effective merge order (including repeated merges), so temporary import files can be deleted and the identities still reconstructed.
  • Raw identity maps are deep-merged before decoding, so a partial override keeps the imported fields, including explicit false values. Dotted names and original key casing are preserved.
  • If reconstruction fails to decode an identity, the previously decoded one is kept and a warning is logged.
  • Regression tests assert the final LoadConfig result for explicit and default imports, nested imports, profiles, multiple config files, provisioned identities, dotted names, casing, YAML functions, concurrent loads, and tracker cleanup. The trace snapshot for Valid Log Level in Config File now counts repeated source merges.

why

  • Import merges ran on a temporary Viper instance that was never associated with the owning load's source tracker. Imported paths were silently omitted, and identity reconstruction then replaced the correctly merged identity map with only the main file's identities.
  • Existing tests covered the individual stages, but none asserted the final LoadConfig result with identities split between the main file and an import.

references

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Imported authentication identities are now preserved when configuration is loaded, including identities from temporary import files.
    • Identity fields merge correctly across configuration sources, preserving names and existing values when later sources provide partial overrides.
    • If identity reconstruction fails, an already decoded identity remains available when possible.
fix(auth): refresh AWS user chain sessions and stabilize CI @osterman (#3351) ## what
  • Authenticate standalone aws/user roots before assuming downstream roles, require unexpired session credentials for chain-cache reuse, and revalidate cached credentials before skipping authentication while preserving provider hooks, session persistence, and long-lived IAM keys.
  • Add generated mocks, authentication regressions, and fix logs; make include, docs-generation, and toolchain acceptance tests use local GitHub fixtures; cover Windows executable filenames; and correct CI Go-download allowlists, conditional SARIF uploads, and affected-file whitespace validation.

why

  • User-to-role chains previously failed with provider not registered when sessions were missing or expired, while cached IAM keys could bypass session creation and MFA; live GitHub quotas and mismatched Windows filenames also made acceptance tests fail independently of authentication behavior.
  • Validation includes auth and focused race tests, unchanged CLI snapshots, a regression that reproduced the Windows filename failure before the fix, passing native Windows shard 4, lint and pre-commit checks, and 100% changed-production-line coverage measured from merged Linux CI artifacts against the 85% target.

references

Closes #3348

Summary by CodeRabbit

  • Bug Fixes

    • AWS user credentials are validated before reuse in authentication chains. If cached credentials lack required session details or become invalid, authentication restarts from the chain root.
    • Standalone identities can authenticate as roots in longer identity chains.
  • Tests

    • Expanded coverage for authentication-chain credential handling and latest-version Terraform installation.
    • Updated acceptance tests to use local mocks for GitHub-dependent data and downloads.
  • Chores

    • Updated CI network policies to allow required Go downloads and skip SARIF uploads when no report is available.
fix(auth): paginate and cache SSO account name lookups @osterman (#3344) ## what
  • Paginate SSO account-name lookups and persist successful resolutions for one hour, isolated by SSO session, realm, region, endpoint, and account name while preserving explicit-ID precedence and credential refresh behavior.
  • Add pagination/cache regression tests and a fix log covering root cause, cache behavior, and validation.

why

  • Prevent false "account not found" errors beyond the first results page and repeated account listing across command invocations.

references

  • Closes #3343
  • Validation: Go build, full auth tests, changed-code lint, commit hooks, and website build passed; the repository-wide short test run was stopped after an unrelated pkg/ci/startup failure, documented in the fix log.

Summary by CodeRabbit

  • Bug Fixes
    • AWS SSO account-name lookups now search through all available account results, so accounts beyond the first page can be found.
    • Successful account-name lookups are cached for up to one hour, reducing repeated lookups. Cache issues won’t prevent account resolution, and unsuccessful lookups aren’t cached. Changes to an account name may take up to an hour to appear.
fix(store): cache deferred atmos.Store template lookups @osterman (#3354) ## what
  • Cache successful, non-nil deferred atmos.Store template results per invocation, keyed by backend, lookup, and effective auth; coalesce concurrent misses.
  • Add regression tests for 2,200 calls over 11 keys, auth isolation, retries, and concurrent reads, plus a fix-log explaining the regression.

why

  • PR #3212 moved list and describe to deferred authentication but left template store results uncached, causing repeated serialized remote reads and credential resets.

references

Summary by CodeRabbit

  • Performance
    • Deferred-auth store lookups reuse successful results within an invocation, reducing repeated backend reads.
    • Concurrent requests for the same store value share a single backend read.
  • Reliability
    • Failed lookups and nil results are not cached, allowing later requests to retry.
    • Cache entries are scoped to the relevant store configuration and credentials.

🤖 Automatic Updates

build(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 @[dependabot[bot]](https://github.com/apps/dependabot) (#3146) Bumps [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) from 0.21.9 to 0.22.0.
Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.22.0

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.21.9...v0.21.10

Commits
  • 3f4ff3c fix(build): unify new build flow into cloudbuild_v2.yaml (#2419)
  • c6b5acd fix(build): correct Cloud Build schema options and source provenance hash (#2...
  • 8f4a85d go.mod: bump Go version + add toolchain directive to replace .go-version file...
  • 5481560 build(deps): bump the go-deps group across 1 directory with 3 updates (#2415)
  • 5b5c272 build(deps): bump the actions group across 1 directory with 8 updates (#2405)
  • 66dd454 remote: retry failed Puller and Pusher initialization (#2406)
  • 3f47f91 fix: add missing substitutions and workspace cleanup to new build files (#2413)
  • 4cb3583 Allow single-character repository paths (#2407)
  • 82cc428 remote: resolve push-check credentials against the repository (#2411)
  • 97815aa build: add multi-architecture Cloud Build configurations for crane, gcrane, a...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
chore(deps): update floci/floci docker digest to 4e451c3 @[renovate[bot]](https://github.com/apps/renovate) (#3130) This PR contains the following updates:
Package Type Update Change
floci/floci service digest d2ecc80 → 4e451c3

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Don't miss a new atmos release

NewReleases is sending notifications on new releases.