Skip to content

[cli] Include queue and compute-resource tags in runInstance dry run - #7639

Open
himani2411 wants to merge 1 commit into
aws:developfrom
himani2411:fsx-efa-integ-test
Open

himani2411 wants to merge 1 commit into
aws:developfrom
himani2411:fsx-efa-integ-test

Conversation

@himani2411

@himani2411 himani2411 commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description of changes

The ComputeResourceLaunchTemplateValidator's RunInstances dry run only carried cluster-level Tags, so environments with tag-based SCPs that key on queue- or compute-resource-level tags failed validation even though a real launch would succeed.

Merge cluster, queue, and compute-resource tags (compute-resource wins on key conflicts, mirroring launch-time precedence) before the dry run. The dedup/precedence logic is extracted into a shared config.common.merge_tags util, also reused by queues_stack._get_custom_compute_resource_tags.

Tests

  • Unit tests
  • DryRun for Ec2 RunInstance Request with 3.16.0
2026-09-25 13:35:37,157 - INFO - common.py:134:_log_boto3_calls() - Executing boto3 call: region=us-west-2, service=ec2, operation=RunInstances, params={'InstanceType': 'c5.xlarge', 'MinCount': 1, 'MaxCount': 1, 'ImageId': 'ami-07342fbbb6de1b89f', 'Placement': {}, 'NetworkInterfaces': [{'DeviceIndex': 0, 'NetworkCardIndex': 0, 'InterfaceType': 'interface', 'Groups': [], 'SubnetId': 'subnet-0d0b4ab9833291b8e'}], 'DryRun': True, 'TagSpecifications': [{'ResourceType': 'instance', 'Tags': [{'Key': 'QueueOverrideTag', 'Value': 'ClusterLevelValue'}, {'Key': 'ConfigFileTag2', 'Value': 'ConfigFileTagValue'}, {'Key': 'AdditionalTag', 'Value': 'AdditionalTagValue'}, {'Key': 'ComputeOverrideTag', 'Value': 'ClusterLevelValue'}]}], 'BlockDeviceMappings': [{'DeviceName': '/dev/xvdba', 'VirtualName': 'ephemeral0'}, {'DeviceName': '/dev/xvdbb', 'VirtualName': 'ephemeral1'}, {'DeviceName': '/dev/xvdbc', 'VirtualName': 'ephemeral2'}, {'DeviceName': '/dev/xvdbd', 'VirtualName': 'ephemeral3'}, {'DeviceName': '/dev/xvdbe', 'VirtualName': 'ephemeral4'}, {'DeviceName': '/dev/xvdbf', 'VirtualName': 'ephemeral5'}, {'DeviceName': '/dev/xvdbg', 'VirtualName': 'ephemeral6'}, {'DeviceName': '/dev/xvdbh', 'VirtualName': 'ephemeral7'}, {'DeviceName': '/dev/xvdbi', 'VirtualName': 'ephemeral8'}, {'DeviceName': '/dev/xvdbj', 'VirtualName': 'ephemeral9'}, {'DeviceName': '/dev/xvdbk', 'VirtualName': 'ephemeral10'}, {'DeviceName': '/dev/xvdbl', 'VirtualName': 'ephemeral11'}, {'DeviceName': '/dev/xvdbm', 'VirtualName': 'ephemeral12'}, {'DeviceName': '/dev/xvdbn', 'VirtualName': 'ephemeral13'}, {'DeviceName': '/dev/xvdbo', 'VirtualName': 'ephemeral14'}, {'DeviceName': '/dev/xvdbp', 'VirtualName': 'ephemeral15'}, {'DeviceName': '/dev/xvdbq', 'VirtualName': 'ephemeral16'}, {'DeviceName': '/dev/xvdbr', 'VirtualName': 'ephemeral17'}, {'DeviceName': '/dev/xvdbs', 'VirtualName': 'ephemeral18'}, {'DeviceName': '/dev/xvdbt', 'VirtualName': 'ephemeral19'}, {'DeviceName': '/dev/xvdbu', 'VirtualName': 'ephemeral20'}, {'DeviceName': '/dev/xvdbv', 'VirtualName': 'ephemeral21'}, {'DeviceName': '/dev/xvdbw', 'VirtualName': 'ephemeral22'}, {'DeviceName': '/dev/xvdbx', 'VirtualName': 'ephemeral23'}, {'DeviceName': '/dev/xvda', 'Ebs': {'Encrypted': True, 'VolumeType': 'gp3', 'Iops': 3000, 'Throughput': 125, 'DeleteOnTermination': True}}], 'MetadataOptions': {'HttpTokens': 'required'}}
  • With Current PR the DRY run request

2026-09-25 13:41:19,756 - INFO - common.py:134:_log_boto3_calls() - Executing boto3 call: region=us-west-2, service=ec2, operation=RunInstances, params={'InstanceType': 'c5.xlarge', 'MinCount': 1, 'MaxCount': 1, 'ImageId': 'ami-038f8eb1d51c43e2c', 'Placement': {}, 'NetworkInterfaces': [{'DeviceIndex': 0, 'NetworkCardIndex': 0, 'InterfaceType': 'interface', 'Groups': [], 'SubnetId': 'subnet-0d0b4ab9833291b8e'}], 'DryRun': True, 'TagSpecifications': [{'ResourceType': 'instance', 'Tags': [{'Key': 'QueueOverrideTag', 'Value': 'QueueLevelValue'}, {'Key': 'ConfigFileTag2', 'Value': 'ConfigFileTagValue'}, {'Key': 'AdditionalTag', 'Value': 'AdditionalTagValue'}, {'Key': 'ComputeOverrideTag', 'Value': 'ComputeLevelValue'}, {'Key': 'QueueTag', 'Value': 'QueueValue'}, {'Key': 'ComputeResourceTag', 'Value': 'ComputeResourceValue'}]}], 'BlockDeviceMappings': [{'DeviceName': '/dev/xvdba', 'VirtualName': 'ephemeral0'}, {'DeviceName': '/dev/xvdbb', 'VirtualName': 'ephemeral1'}, {'DeviceName': '/dev/xvdbc', 'VirtualName': 'ephemeral2'}, {'DeviceName': '/dev/xvdbd', 'VirtualName': 'ephemeral3'}, {'DeviceName': '/dev/xvdbe', 'VirtualName': 'ephemeral4'}, {'DeviceName': '/dev/xvdbf', 'VirtualName': 'ephemeral5'}, {'DeviceName': '/dev/xvdbg', 'VirtualName': 'ephemeral6'}, {'DeviceName': '/dev/xvdbh', 'VirtualName': 'ephemeral7'}, {'DeviceName': '/dev/xvdbi', 'VirtualName': 'ephemeral8'}, {'DeviceName': '/dev/xvdbj', 'VirtualName': 'ephemeral9'}, {'DeviceName': '/dev/xvdbk', 'VirtualName': 'ephemeral10'}, {'DeviceName': '/dev/xvdbl', 'VirtualName': 'ephemeral11'}, {'DeviceName': '/dev/xvdbm', 'VirtualName': 'ephemeral12'}, {'DeviceName': '/dev/xvdbn', 'VirtualName': 'ephemeral13'}, {'DeviceName': '/dev/xvdbo', 'VirtualName': 'ephemeral14'}, {'DeviceName': '/dev/xvdbp', 'VirtualName': 'ephemeral15'}, {'DeviceName': '/dev/xvdbq', 'VirtualName': 'ephemeral16'}, {'DeviceName': '/dev/xvdbr', 'VirtualName': 'ephemeral17'}, {'DeviceName': '/dev/xvdbs', 'VirtualName': 'ephemeral18'}, {'DeviceName': '/dev/xvdbt', 'VirtualName': 'ephemeral19'}, {'DeviceName': '/dev/xvdbu', 'VirtualName': 'ephemeral20'}, {'DeviceName': '/dev/xvdbv', 'VirtualName': 'ephemeral21'}, {'DeviceName': '/dev/xvdbw', 'VirtualName': 'ephemeral22'}, {'DeviceName': '/dev/xvdbx', 'VirtualName': 'ephemeral23'}, {'DeviceName': '/dev/xvda', 'Ebs': {'Encrypted': True, 'VolumeType': 'gp3', 'Iops': 3000, 'Throughput': 125, 'DeleteOnTermination': True}}], 'MetadataOptions': {'HttpTokens': 'required'}}

References

  • Link to impacted open issues.
  • Link to related PRs in other packages (i.e. cookbook, node).
  • Link to documentation useful to understand the changes.

Checklist

  • Make sure you are pointing to the right branch.
  • If you're creating a patch for a branch other than develop add the branch name as prefix in the PR title (e.g. [release-3.6]).
  • Check all commits' messages are clear, describing what and why vs how.
  • Make sure to have added unit tests or integration tests to cover the new/modified code.
  • Check if documentation is impacted by this change.

Please review the guidelines for contributing and Pull Request Instructions.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@himani2411
himani2411 requested review from a team as code owners September 25, 2026 17:17
@himani2411 himani2411 added skip-changelog-update Disables the check that enforces changelog updates in PRs 3.x labels Sep 25, 2026
@himani2411 himani2411 changed the title [cli] Include queue and compute-resource tags in ComputeResource launch-template dry run [cli] Include queue and compute-resource tags in runInstance dry run Sep 25, 2026
…ch-template dry run

The ComputeResourceLaunchTemplateValidator's RunInstances dry run only
carried cluster-level Tags, so environments with tag-based SCPs that key on
queue- or compute-resource-level tags failed validation even though a real
launch would succeed.

Merge cluster, queue, and compute-resource tags (compute-resource wins on
key conflicts, mirroring launch-time precedence) before the dry run. The
dedup/precedence logic is extracted into a shared config.common.merge_tags
util, also reused by queues_stack._get_custom_compute_resource_tags.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.x skip-changelog-update Disables the check that enforces changelog updates in PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant