feat(gcp): cloudasset inventory_project_metadata + enrichment snapshot name fix (swamp-club #2230, #2628) #337

Merged
stack72 merged 2 commits from 2230 into main 2026-09-28 21:39:58 +00:00
Owner

Summary

Closes swamp-club #2230 and #2628.

#2230: inventory_project_metadata on @swamp/gcp/cloudasset assets

A new GCP enrichment runs Cloud Asset searchAllResources over one project and saves one snapshot containing only resource metadata.

  • Pagination and failure: it follows every page (500 per page). If the count goes over maxAssets (default 10000, must be a positive whole number), or a page returns an error, isn't valid JSON, or repeats a page token, the method fails and saves nothing. It never truncates silently.
  • Fields kept: only identity, type, location and state. The request asks Google for just those fields, and the method also drops everything else from each result, so payloads such as additionalAttributes, description and versionedResources are never stored.
  • Query options: query and assetTypes are passed through unchanged, and results are sorted by name so snapshots of an unchanged project compare equal.
  • Coverage: the snapshot records coverage: "caller-visible" and source: "search-index", the convention from inventory_hierarchy (#2207). It includes a note that search-index results can lag and are not proof that backup or retention is complete.
  • Why it wasn't generated before: searchAllResources sits on the discovery document's v1 resource, which has no get, list or insert method, so the pipeline never produced a model for it.

#2628: enrichment snapshots include their required name

inventory_enabled, inventory_hierarchy, audit_effective_policies and inventory_recommendations saved snapshots without name, which each model's state schema requires. They now set name to the name the snapshot is saved under; that name itself is unchanged. Each test suite now checks the name and checks that the snapshot passes model.resources.state.schema. Those checks failed before the fix and pass after it.

Generated output

  • cloudasset, serviceusage, cloudresourcemanager, orgpolicy and recommender are regenerated to 2026.09.28.1. Each model has a new upgrade entry and a manifest bump.
  • The diffs contain only the enrichment changes and the version bumps. A second generation run changes nothing.
  • A full GCP generation also produced changes in 6 unrelated services, caused by Google updating its API definitions after the nightly run. Those were left out; the nightly regenerate job will pick them up.

Test plan

  • verify-build 14/14, on top of #2620, so the codegen test suites are gated: 314 tests passed, 0 failed, including the 12 new inventory_project_metadata tests.
  • The upgrade gate examined all 5 models, and the upgrade test moved published instances of each to 2026.09.28.1.
  • Codegen idempotency passed.
  • verify-reviews: code-review and adversarial-review both pass; ci-security-review was skipped by its guard.
  • Attestation d03d74ff-d896-4750-8105-b04a2cad8603 covers commit fd5afa1.
  • Not run against a real GCP project; testing uses mock servers, as the repo's rules require.

🤖 Generated with Claude Code

## Summary Closes swamp-club #2230 and #2628. **#2230: `inventory_project_metadata` on `@swamp/gcp/cloudasset` assets** A new GCP enrichment runs Cloud Asset `searchAllResources` over one project and saves one snapshot containing only resource metadata. - **Pagination and failure:** it follows every page (500 per page). If the count goes over `maxAssets` (default 10000, must be a positive whole number), or a page returns an error, isn't valid JSON, or repeats a page token, the method fails and saves nothing. It never truncates silently. - **Fields kept:** only identity, type, location and state. The request asks Google for just those fields, and the method also drops everything else from each result, so payloads such as `additionalAttributes`, `description` and `versionedResources` are never stored. - **Query options:** `query` and `assetTypes` are passed through unchanged, and results are sorted by name so snapshots of an unchanged project compare equal. - **Coverage:** the snapshot records `coverage: "caller-visible"` and `source: "search-index"`, the convention from `inventory_hierarchy` (#2207). It includes a note that search-index results can lag and are not proof that backup or retention is complete. - **Why it wasn't generated before:** `searchAllResources` sits on the discovery document's `v1` resource, which has no get, list or insert method, so the pipeline never produced a model for it. **#2628: enrichment snapshots include their required `name`** `inventory_enabled`, `inventory_hierarchy`, `audit_effective_policies` and `inventory_recommendations` saved snapshots without `name`, which each model's state schema requires. They now set `name` to the name the snapshot is saved under; that name itself is unchanged. Each test suite now checks the name and checks that the snapshot passes `model.resources.state.schema`. Those checks failed before the fix and pass after it. ## Generated output - `cloudasset`, `serviceusage`, `cloudresourcemanager`, `orgpolicy` and `recommender` are regenerated to `2026.09.28.1`. Each model has a new upgrade entry and a manifest bump. - The diffs contain only the enrichment changes and the version bumps. A second generation run changes nothing. - A full GCP generation also produced changes in 6 unrelated services, caused by Google updating its API definitions after the nightly run. Those were left out; the nightly regenerate job will pick them up. ## Test plan - [x] verify-build 14/14, on top of #2620, so the codegen test suites are gated: 314 tests passed, 0 failed, including the 12 new `inventory_project_metadata` tests. - [x] The upgrade gate examined all 5 models, and the upgrade test moved published instances of each to `2026.09.28.1`. - [x] Codegen idempotency passed. - [x] verify-reviews: code-review and adversarial-review both pass; ci-security-review was skipped by its guard. - [x] Attestation `d03d74ff-d896-4750-8105-b04a2cad8603` covers commit `fd5afa1`. - [ ] Not run against a real GCP project; testing uses mock servers, as the repo's rules require. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Add a GCP enrichment on cloudasset.assets that runs searchAllResources over a
single project and persists one metadata-only snapshot:

- full pagination (pageSize 500), failing on a maxAssets breach (default
  10000), non-2xx or non-JSON pages, or a repeated page token; nothing is
  persisted on failure
- identity/type/location/state fields only: fixed readMask plus a client-side
  allowlist, so payloads such as additionalAttributes and versionedResources
  are never stored
- query and assetTypes passed through verbatim; results sorted by name
- coverage "caller-visible" and source "search-index", following
  inventory_hierarchy, with a note that index results can lag and are not
  proof of backup or retention completeness

searchAllResources lives on the Discovery v1 resource, which has no
get/list/insert, so the pipeline never generated it. cloudasset regenerated
to 2026.09.28.1; idempotent on a second run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
fix(gcp): enrichment snapshots carry the name their StateSchema requires (swamp-club #2628)
All checks were successful
CI / Review Integrity (pull_request) Successful in 53s
CI / Validate Attestation (pull_request) Successful in 57s
fd5afa1660
inventory_enabled, inventory_hierarchy, audit_effective_policies and
inventory_recommendations wrote snapshot objects without name, which each
model's StateSchema declares as a required string, so the persisted data
failed schema validation. Each now writes name set to its instance name
(data names unchanged). Each suite asserts the name and that
model.resources.state.schema accepts the snapshot.

Regenerated serviceusage, cloudresourcemanager, orgpolicy and recommender
(fix plus version bumps only); idempotent on a second run.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
stack72 deleted branch 2230 2026-09-28 21:39:59 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!337
No description provided.