fix(codegen/aws): write custom-method output to dedicated resources (swamp-club #1735) #462

Merged
stack72 merged 1 commit from 1735 into main 2026-10-06 18:31:52 +00:00
Owner

Fixes swamp-club #1735.

Problem

AWS enrichment custom methods wrote their results into the CloudControl state resource (lifetime: infinite, StateSchema) under an instance name built from every argument value. Bedrock knowledge-base.retrieve therefore stored every query as a new, never-expiring state instance named after the query text (e.g. retrieve-KB123-What is Bedrock?), in a resource whose schema requires KnowledgeBaseId. garbageCollection caps versions per name, so it never bounded anything.

Fix (codegen)

Each custom method now declares an output resource in its enrichment config: schema (<Name>OutputSchema exported from methods.ts), lifetime, garbageCollection, and a stable instance key ({ arg } for single results, { itemFields } for arrays). The generator emits those resources and fails generation if a method targets state, a schema name breaks the convention or collides with a generated schema, the key kind does not match the return shape, or two methods declare the same resource differently.

Model Method Was Now
@swamp/aws/bedrock/knowledge-base retrieve state/retrieve-<all args> (infinite) retrieval/<knowledgeBaseId> (7d); query now in the payload
@swamp/aws/events/event-bus put_events state/put_events-[object Object] putEventsResult/<bus Name> (7d)
@swamp/aws/cloudformation/stack-set listInstances state/<index> stackInstance/<Account>-<Region> (30d)
listOperations, describeOperation state/<index>, state/describeOperation-<args> operation/<OperationId> (30d)
detectDrift state/detectDrift-<args> driftDetection/<StackSetName> (30d)

Consumer-visible change

  • Workflows or expressions that read StackSet or Events method output from state must switch to the resource names above.
  • Data already written to state by these methods is not migrated. To remove it, delete the state instances named retrieve-*, put_events-*, describeOperation-*, detectDrift-* and numeric (0, 1, ...) instances on stack-set models with swamp data — the CloudControl get/sync instance is unaffected.
  • retrieve keeps only the latest query as the latest version of retrieval/<kbId>; earlier queries survive as the last 10 versions for 7 days (documented in codegen/designs/aws.md).

Adjacent codegen fixes (found while regenerating)

  • Service filter deleted models. generate:aws events substring-matched type names, pulling AWS::RDS::EventSubscription, AWS::Lambda::EventSourceMapping, etc. into a partial regeneration that deleted every other model in rds, lambda, redshift, dms, neptune, docdb, customerprofiles and servicecatalog. The filter now matches the service segment exactly (matchesServiceFilter, with tests). Reproduced on clean main.
  • Every run bumped every manifest. The _lib change check compared unformatted output to the formatted on-disk file, so libChanged was always true. It now formats before comparing, like the README. Reproduced on clean main (bedrock .1 → .2 → .3 with zero model changes).

Verification

  • Codegen tests: 444 passed; generator tests cover emitted resources, write targets, executed naming expressions, and every validation error; enrichment tests parse results through the output schemas.
  • generate:aws bedrock cloudformation events changes exactly those three models + manifests; a full generate:aws changes nothing else (three new upstream types from schema drift were left for the nightly job); second runs produce zero diff.
  • End-to-end in a scratch swamp repo against a local fake AWS endpoint: all six methods ran; published bedrock reproduced the bug; the new code wrote retrieval/KB123 (7d, v1–v3 across three queries/pages), putEventsResult/orders-bus, stackInstance/111111111111-us-east-1 and eu-west-1 (missing Account), operation/op-1 v2, driftDetection/my-ss, and zero state instances.
  • verify-build 14/14, verify-reviews passed (code-review and adversarial-review: pass, no blocking findings). Attestation 4afe8efa-8728-4ad2-aee3-6dca00034a0e for 0970a624a.

Known trade-off flagged by review: listOperations after describeOperation makes the summary the latest version of operation/<id> (details remain in prior versions).

🤖 Generated with Claude Code

Fixes swamp-club #1735. ## Problem AWS enrichment custom methods wrote their results into the CloudControl `state` resource (`lifetime: infinite`, `StateSchema`) under an instance name built from every argument value. Bedrock `knowledge-base.retrieve` therefore stored every query as a new, never-expiring `state` instance named after the query text (e.g. `retrieve-KB123-What is Bedrock?`), in a resource whose schema requires `KnowledgeBaseId`. `garbageCollection` caps versions per name, so it never bounded anything. ## Fix (codegen) Each custom method now declares an `output` resource in its enrichment config: schema (`<Name>OutputSchema` exported from `methods.ts`), lifetime, garbageCollection, and a stable instance key (`{ arg }` for single results, `{ itemFields }` for arrays). The generator emits those resources and fails generation if a method targets `state`, a schema name breaks the convention or collides with a generated schema, the key kind does not match the return shape, or two methods declare the same resource differently. | Model | Method | Was | Now | | --- | --- | --- | --- | | `@swamp/aws/bedrock/knowledge-base` | `retrieve` | `state/retrieve-<all args>` (infinite) | `retrieval/<knowledgeBaseId>` (7d); query now in the payload | | `@swamp/aws/events/event-bus` | `put_events` | `state/put_events-[object Object]` | `putEventsResult/<bus Name>` (7d) | | `@swamp/aws/cloudformation/stack-set` | `listInstances` | `state/<index>` | `stackInstance/<Account>-<Region>` (30d) | | | `listOperations`, `describeOperation` | `state/<index>`, `state/describeOperation-<args>` | `operation/<OperationId>` (30d) | | | `detectDrift` | `state/detectDrift-<args>` | `driftDetection/<StackSetName>` (30d) | ## Consumer-visible change - Workflows or expressions that read StackSet or Events method output from `state` must switch to the resource names above. - Data already written to `state` by these methods is not migrated. To remove it, delete the `state` instances named `retrieve-*`, `put_events-*`, `describeOperation-*`, `detectDrift-*` and numeric (`0`, `1`, ...) instances on stack-set models with `swamp data` — the CloudControl `get`/`sync` instance is unaffected. - `retrieve` keeps only the latest query as the latest version of `retrieval/<kbId>`; earlier queries survive as the last 10 versions for 7 days (documented in `codegen/designs/aws.md`). ## Adjacent codegen fixes (found while regenerating) - **Service filter deleted models.** `generate:aws events` substring-matched type names, pulling `AWS::RDS::EventSubscription`, `AWS::Lambda::EventSourceMapping`, etc. into a partial regeneration that deleted every other model in rds, lambda, redshift, dms, neptune, docdb, customerprofiles and servicecatalog. The filter now matches the service segment exactly (`matchesServiceFilter`, with tests). Reproduced on clean main. - **Every run bumped every manifest.** The `_lib` change check compared unformatted output to the formatted on-disk file, so `libChanged` was always true. It now formats before comparing, like the README. Reproduced on clean main (bedrock `.1 → .2 → .3` with zero model changes). ## Verification - Codegen tests: 444 passed; generator tests cover emitted resources, write targets, executed naming expressions, and every validation error; enrichment tests parse results through the output schemas. - `generate:aws bedrock cloudformation events` changes exactly those three models + manifests; a full `generate:aws` changes nothing else (three new upstream types from schema drift were left for the nightly job); second runs produce zero diff. - End-to-end in a scratch swamp repo against a local fake AWS endpoint: all six methods ran; published bedrock reproduced the bug; the new code wrote `retrieval/KB123` (7d, v1–v3 across three queries/pages), `putEventsResult/orders-bus`, `stackInstance/111111111111-us-east-1` and `eu-west-1` (missing Account), `operation/op-1` v2, `driftDetection/my-ss`, and zero `state` instances. - verify-build 14/14, verify-reviews passed (code-review and adversarial-review: pass, no blocking findings). Attestation `4afe8efa-8728-4ad2-aee3-6dca00034a0e` for `0970a624a`. Known trade-off flagged by review: `listOperations` after `describeOperation` makes the summary the latest version of `operation/<id>` (details remain in prior versions). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(codegen/aws): write custom-method output to dedicated resources (swamp-club #1735)
All checks were successful
CI / Review Integrity (pull_request) Successful in 2m8s
CI / Validate Attestation (pull_request) Successful in 1m39s
0970a624a7
Enrichment custom methods wrote their results into the CloudControl
`state` resource (lifetime infinite, StateSchema) under an instance name
built from every argument value. Bedrock `retrieve` therefore stored each
query as a new, never-expiring instance named after the query text, in a
resource whose schema requires KnowledgeBaseId.

Each custom method now declares an `output` resource in its enrichment
config: schema, lifetime, garbageCollection and a stable instance key.
The generator validates the declarations and emits the resources.

- bedrock knowledge-base `retrieve` -> `retrieval` (7d), keyed by
  knowledgeBaseId; query moves into the payload
- events event-bus `put_events` -> `putEventsResult` (7d), keyed by bus
  Name (was named `[object Object]`)
- cloudformation stack-set `listInstances` -> `stackInstance`,
  `listOperations`/`describeOperation` -> `operation`, `detectDrift` ->
  `driftDetection` (30d), keyed by item fields / operation ID / StackSet

Also fixes two codegen bugs hit while regenerating:

- `generate:aws <service>` substring-matched type names, so `events`
  pulled AWS::RDS::EventSubscription etc. into rds, lambda, redshift and
  others and deleted their remaining models. The filter now matches the
  service segment exactly.
- the `_lib` change check compared unformatted output with the
  formatted on-disk file, so every run bumped every regenerated
  service's manifest.

Data previously written to `state` by these methods is left in place.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
stack72 deleted branch 1735 2026-10-06 18:31:52 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!462
No description provided.