Condition the scheduler role on the group Scheduler actually presents - #71
Merged
Merged
Conversation
Every schedule in the staging deploy failed with "The execution role you provide must allow AWS EventBridge Scheduler to assume the role". The trust policy conditioned aws:SourceArn on a schedule ARN, and Scheduler presents the schedule group when it assumes the role, so the condition could never match. CreateSchedule checks the role is assumable before it creates anything, which is why all twenty-seven failed rather than some. The condition now names the group. Both conditions stay: the account still pins the role to one account, and the group is as narrow as Scheduler allows. The group's name and ARN come from one local so they cannot drift. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RzTEVpxi5LHTXSZywnFjea
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The staging deploy of #60 failed on all twenty-seven schedules with
ValidationException: The execution role you provide must allow AWS EventBridge Scheduler to assume the role. My regression, from the last commit on that PR.The trust policy conditioned
aws:SourceArnon a schedule ARN. EventBridge Scheduler presents the schedule group when it assumes the execution role, so the condition could never match.CreateSchedulechecks the role is assumable before it creates anything, which is why every schedule failed rather than some.Confirmed against the account rather than inferred:
arn:aws:scheduler:us-east-2:654654381893:schedule/staging-clockwork-tasks/*arn:aws:scheduler:us-east-2:654654381893:schedule-group/staging-clockwork-tasksI also ruled out the other candidate: the role was created seventy-six seconds before the first
CreateSchedule, so this is not IAM propagation.Both conditions stay rather than being dropped. The account still pins the role to one account, and the group is as narrow as Scheduler permits. The group's name and ARN now come from a single local so the two cannot drift again.
Deliverables
deploy/app/schedules.tfTest plan
tofu validateandtofu fmton the prod workspaceaws scheduler get-schedule-groupfor the live staging group, character for characterStaging is serving normally in the meantime: the apply failed after the service rolled, so only the schedules are missing, and the group exists with none in it.
🤖 Generated with Claude Code
https://claude.ai/code/session_01RzTEVpxi5LHTXSZywnFjea