Skip to content

fix(aws): bind DynamoDB token and profile options - #11290

Merged
ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-aws-bind-dynamodb-token-and-profile
Sep 17, 2026
Merged

ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-aws-bind-dynamodb-token-and-profile

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

The DynamoDB clustering provider builders for silos and clients, and the DynamoDB reminders provider builder, read both Token and ProfileName from the SecretKey configuration key. This copies the secret into unrelated credential settings and overrides explicitly configured token and profile values.

Read each option from its corresponding configuration key. The production change is limited to six key expressions across the existing builders. Regression cases exercise the provider-builder options pipelines with distinct credential values and with only SecretKey configured, preserving the default token and profile values in the latter case.

Extracted from #10798 as an independent fix against upstream main. Original contribution: Reuben Bond reuben.bond@gmail.com, commit c5eae99187c1a4216c7adcb034ff12af9c00eea8 (parent snapshot ee12e8b08d5fc9a0d514bd54f2e98f908e947847). The extraction retains the existing provider-builder implementation and public API.

Microsoft Reviewers: Open in CodeFlow

Read Token and ProfileName from their own configuration keys for silo clustering, client gateway discovery, and reminders. Cover distinct credential values and SecretKey-only configuration through each provider-builder options pipeline.

Extracted from dotnet#10798, originally authored by Reuben Bond in commit c5eae99. Parent snapshot: ee12e8b.
Copilot AI lite review requested due to automatic review settings September 17, 2026 02:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The fix is narrowly scoped to configuration key binding and is backed by targeted regression tests covering the affected builder pipelines.

Review effort: Lite
Findings: None

What changed in this PR

Fixes DynamoDB provider-builder configuration binding so Token and ProfileName are read from their own configuration keys (instead of incorrectly reading from SecretKey), preventing credential leakage/overrides across settings in Orleans’ AWS DynamoDB clustering and reminders integrations.

Changes:

  • Correct Token/ProfileName key lookups in the DynamoDB reminders provider builder.
  • Correct Token/ProfileName key lookups in the DynamoDB clustering provider builder (silo + client paths).
  • Add regression tests validating independent binding of SecretKey, Token, and ProfileName for clustering and reminders builders.
File Description
test/​Extensions/​Orleans.AWS.Tests/​Reminder/​DynamoDBRemindersProviderBuilderTests.cs Adds regression coverage ensuring reminders builder binds Token/ProfileName independently from SecretKey.
test/​Extensions/​Orleans.AWS.Tests/​MembershipTests/​DynamoDBClusteringProviderBuilderTests.cs Adds regression coverage for clustering builder credential binding on both silo and client configuration paths.
src/​AWS/​Orleans.Reminders.DynamoDB/​DynamoDBRemindersProviderBuilder.cs Fixes reminders builder to read Token and ProfileName from the correct configuration keys.
src/​AWS/​Orleans.Clustering.DynamoDB/​DynamoDBClusteringProviderBuilder.cs Fixes clustering builder (silo + client) to read Token and ProfileName from the correct configuration keys.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
@github-actions

Copy link
Copy Markdown
Contributor

Code coverage

Metric Pull request Current main Variance
Lines 82.20% (112,369 / 136,709) 82.12% (112,272 / 136,709) +0.0710 pp
Branches 71.39% (32,336 / 45,295) 71.32% (32,306 / 45,295) +0.0662 pp

Report-only conclusion: improved.

The current-main baseline is commit 2e40fa8a3b and uses the same reviewed coverage matrix.

Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities.

The comparison remains report-only while normal line and branch variance is calibrated.

Coverage details

@ReubenBond
ReubenBond merged commit 7d3b28d into dotnet:main Sep 17, 2026
73 checks passed
@ReubenBond
ReubenBond deleted the rb-fix-aws-bind-dynamodb-token-and-profile branch September 17, 2026 14:22
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants