fix(aws): bind DynamoDB token and profile options - #11290
ReubenBond merged 1 commit into
Conversation
Read Token and ProfileName from their own configuration keys for silo clustering, client gateway discovery, and reminders. Cover distinct credential values and SecretKey-only configuration through each provider-builder options pipeline. Extracted from dotnet#10798, originally authored by Reuben Bond in commit c5eae99. Parent snapshot: ee12e8b.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The fix is narrowly scoped to configuration key binding and is backed by targeted regression tests covering the affected builder pipelines.
Review effort: Lite
Findings: None
What changed in this PR
Fixes DynamoDB provider-builder configuration binding so Token and ProfileName are read from their own configuration keys (instead of incorrectly reading from SecretKey), preventing credential leakage/overrides across settings in Orleans’ AWS DynamoDB clustering and reminders integrations.
Changes:
- Correct
Token/ProfileNamekey lookups in the DynamoDB reminders provider builder. - Correct
Token/ProfileNamekey lookups in the DynamoDB clustering provider builder (silo + client paths). - Add regression tests validating independent binding of
SecretKey,Token, andProfileNamefor clustering and reminders builders.
| File | Description |
|---|---|
| test/Extensions/Orleans.AWS.Tests/Reminder/DynamoDBRemindersProviderBuilderTests.cs | Adds regression coverage ensuring reminders builder binds Token/ProfileName independently from SecretKey. |
| test/Extensions/Orleans.AWS.Tests/MembershipTests/DynamoDBClusteringProviderBuilderTests.cs | Adds regression coverage for clustering builder credential binding on both silo and client configuration paths. |
| src/AWS/Orleans.Reminders.DynamoDB/DynamoDBRemindersProviderBuilder.cs | Fixes reminders builder to read Token and ProfileName from the correct configuration keys. |
| src/AWS/Orleans.Clustering.DynamoDB/DynamoDBClusteringProviderBuilder.cs | Fixes clustering builder (silo + client) to read Token and ProfileName from the correct configuration keys. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Code coverage
Report-only conclusion: improved. The current-main baseline is commit Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities. The comparison remains report-only while normal line and branch variance is calibrated. Coverage details |
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
The DynamoDB clustering provider builders for silos and clients, and the DynamoDB reminders provider builder, read both
TokenandProfileNamefrom theSecretKeyconfiguration key. This copies the secret into unrelated credential settings and overrides explicitly configured token and profile values.Read each option from its corresponding configuration key. The production change is limited to six key expressions across the existing builders. Regression cases exercise the provider-builder options pipelines with distinct credential values and with only
SecretKeyconfigured, preserving the default token and profile values in the latter case.Extracted from #10798 as an independent fix against upstream
main. Original contribution: Reuben Bond reuben.bond@gmail.com, commitc5eae99187c1a4216c7adcb034ff12af9c00eea8(parent snapshotee12e8b08d5fc9a0d514bd54f2e98f908e947847). The extraction retains the existing provider-builder implementation and public API.Microsoft Reviewers: Open in CodeFlow