Skip to content

feat: add verified Linux package handling for AWS agents - #629

Open
damacus wants to merge 3 commits into
mainfrom
codex/aws-agent-foundation
Open

damacus wants to merge 3 commits into
mainfrom
codex/aws-agent-foundation

Conversation

@damacus

@damacus damacus commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Adds shared package handling for Linux AWS agents, so the CloudWatch and Systems Manager resources can install explicit vendor builds with SHA-256 verification on x86-64 and ARM64.

DEB removal purges package-owned configuration; RPM removal uses the native package provider. Unit tests resolve the local cookbooks without contacting Supermarket.

Restores the shared Ruby 3.2 CI job by selecting a compatible Chef test runtime in Gemfile, independently of the runtime SDK pins. Fixes full-tree Cookstyle offences while preserving EBS volume persistence, and covers IAM policy decoding of literal plus signs with regression tests.

Stack created with GitHub Stacks CLI • Give Feedback 💬

@damacus
damacus added this pull request to stack #632 September 19, 2026 09:36
@damacus damacus changed the title codex/aws agent foundation feat: add verified Linux package handling for AWS agents Sep 19, 2026
@github-actions

Copy link
Copy Markdown

Slowest examples

Top 10 slowest examples (45.09 seconds, 99.99% of total time)
Example Description Time in seconds
spec/resources/security_group_spec.rb:26 aws_security_group should create a security group when it does not exist is expected to eq {:description=>"hello_world_description", :group_name=>"hello_world", :vpc_id=>"vpc-00000000"} 9.93011
spec/resources/security_group_spec.rb:443 aws_security_group should update ingress/egress rules is expected to eq "Egress rule to remove" 4.4575
spec/resources/security_group_spec.rb:78 aws_security_group should not create a security group which already exists is expected to eq nil 4.43372
spec/resources/security_group_spec.rb:189 aws_security_group should create and delete update tags is expected to eq "ToRemove" 4.41696
spec/resources/security_group_spec.rb:130 aws_security_group should not update tags is expected to eq nil 4.40987
spec/resources/security_group_spec.rb:294 aws_security_group should not update ingress/egress rules even when properties unsorted is expected to eq nil 4.39771
spec/resources/iam_policy_decoding_spec.rb:32 IAM policy document decoding decodes assume-role policy escapes without changing literal plus signs 4.32964
spec/recipes/default_spec.rb:9 aws::default does not raise an error is expected not to raise Exception 4.3188
spec/resources/iam_policy_decoding_spec.rb:22 IAM policy document decoding decodes managed policy escapes without turning literal plus signs into spaces 4.27879
spec/libraries/security_group_spec.rb:5 AwsCookbook::SecurityGroup should remove empty arrays from hash 0.12602

@damacus
damacus marked this pull request as ready for review September 22, 2026 22:07
@damacus
damacus requested a review from a team as a code owner September 22, 2026 22:07

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant