Skip to content

chore(deps): roll out Azure reservation fixes to platform - #475

Open
cristim wants to merge 1 commit into
mainfrom
codex/go76-platform-azure-rollout
Open

cristim wants to merge 1 commit into
mainfrom
codex/go76-platform-azure-rollout

Conversation

@cristim

@cristim cristim commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Why

The platform still resolves the older Azure commitments module. This PR updates the Azure provider pin, the shared pkg pin required by the new Azure module, and their Go-generated checksums. AWS and GCP pins stay unchanged.

Evidence

  • The published Azure and required pkg module versions were fetched through Go's public module proxy and authenticated by Go checksums. Offline module inspection selected Azure v0.0.0-20261004143708-56555e1be095 and pkg v0.0.0-20260929105827-b3b4cb5e3d80; AWS and GCP stayed at ce9513612901.
  • A scratch overlay exercised Manager.executeSinglePurchase with a concrete Azure compute client, fake credential, synthetic HTTP responses, and mocked platform dependencies. With the old Azure module, monthly and upfront assertions failed on both initial purchase and matching-order re-drive: purchase history stored 2000 and logs printed cost=2000.00. With the new module, all four cases passed. Monthly stored a non-nil zero and logged cost=0.00; upfront stored nil and logged cost=unknown. The plan's totalUpfront still reads the recommendation's planned upfront cost.
  • Three selected existing mock-backed tests passed under -race -short in internal/purchase and internal/scheduler. A separate loopback managed-identity fixture confirmed the scheduler's all-accounts-fail error path without ambient credentials or a cloud request. The server command built to a scratch output, and go mod tidy -diff was clean after the required direct pkg pin update.
  • The normal commit hooks passed, including tidy across the root and standard-library-only tests/e2e modules, file checks, git-secrets, and Trivy. Hooks without matching manifest files were skipped normally.
  • An independent gpt-6-astra review of exact commit 369728d5ecaa45cc9191bcd8d59c8f35b2757056 found no actionable issue in the full effective Azure and pkg source delta from the older published versions. The reviewer independently reran all four synthetic concrete-client cases under -race; monthly and upfront initial purchases and matching-order re-drives passed. The raw replay log is /tmp/claude/go76-platform-azure-astra-replay-v1.log (SHA256 829b57e16a76edc965c18c460b57f2f2821913e8dd63d6905f5fa7300775f400).

The tests use synthetic Azure responses and local fixtures. They do not establish live Azure catalog availability, a real reservation purchase, or end-user acceptance. PR-triggered Linux CI still needs to run.

Dependency and scope

This PR depends on the still-open Azure pricing stack PR #187 and its ancestors. Keep this consumer PR open until the upstream stack and real-scenario acceptance are complete. The independent upstream review covered the 9962786 to 56555e1 delta, and the consumer review covered the full effective ce951 to 56555e1 Azure and pkg source delta. Real-scenario acceptance remains unproved. This dependency update is not the full fix for cloud-commitments-go #76 or #132. Both issues remain open. Refs LeanerCloud/cloud-commitments-go#76 and LeanerCloud/cloud-commitments-go#132.

Summary by CodeRabbit

  • Chores
    • No end-user-visible changes are described in this update. The summary reports no changes to public interfaces and identifies no new features, fixes, or changes to the product experience. Accordingly, there are no user-facing updates to highlight in these release notes.

@cristim cristim added urgency/this-sprint Within the current sprint triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm impact/many Affects most users effort/m Days type/bug Defect labels Oct 4, 2026
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: f554b4b1-5c5a-43c5-a178-582a244b39e5
📥 Commits

Reviewing files that changed from the base of the PR and between 6d9a70f and 369728d.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The pkg and providers/azure dependencies now use newer pseudo-versions of github.com/LeanerCloud/cloud-commitments-go. The providers/aws dependency remains at its previous version.

Changes

Module dependency update

Layer / File(s) Summary
Update module versions
go.mod
The pkg and providers/azure dependencies use newer pseudo-versions. The providers/aws dependency retains its previous version.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 36972

The updated dependencies resolve together and their checksums verify. No concrete merge-blocking issue is evident; normal build and CI checks remain.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the Azure reservation dependency update being rolled out to the platform.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cristim

cristim commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

CI result for exact commit 369728d5ecaa45cc9191bcd8d59c8f35b2757056:

  • pre-commit run 37225100804 passed.
  • CI - Build & Test run 37225100807 failed. Unit Tests, Integration Tests, E2E Tests, lint, Terraform validation, and the other successful jobs passed. The failing steps were Scan the shipped image for Go advisories in Build Docker Image, plus Run govulncheck CVE scanner (all modules) and Run npm audit (frontend) in Security Scanning. The CI Success aggregate failed as a result.
  • Both Go scans flagged fixable GO-2026-6505 in go.opentelemetry.io/otel/sdk@v1.44.0 (fixed in v1.45.0). npm audit reported 34 frontend vulnerabilities, 32 high. The parent commit and this commit both pin otel/sdk@v1.44.0; this PR changes only go.mod and go.sum for Azure and required pkg versions, and leaves the frontend unchanged. These findings belong to the existing security baseline tracked by PR #473.

Keep this PR open. Do not treat the passing affected-path tests as green CI or full security coverage. Verify the combined tree and required CI after #473 lands; the upstream Azure stack and real-scenario acceptance also remain open.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/m Days impact/many Affects most users priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/bug Defect urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant