Skip to content

fix: Kinesis event-source region, EventBridge archive rule ARN, Logs group ARN form, cached Bedrock regexes - #2593

Merged
vieiralucas merged 4 commits into
mainfrom
fix/small-correctness-followups
Sep 30, 2026
Merged

vieiralucas merged 4 commits into
mainfrom
fix/small-correctness-followups

Conversation

@vieiralucas

@vieiralucas vieiralucas commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

Four independent correctness follow-ups found during the ARN partition campaign, one commit each:

  • fix(lambda): report the Kinesis stream's region in event-source records. The Kinesis -> Lambda poller hardcoded "awsRegion": "us-east-1"; records now carry the stream's region from its ARN.
  • fix(eventbridge): put the custom bus in an archive's managed rule ARN. CreateArchive built the managed rule ARN in the default-bus form even for a custom-bus archive; it now uses rule_arn with the source bus (rule/<bus>/Events-Archive-<name>), matching AWS.
  • fix(logs): store one log group ARN form across every creation path. CreateLogGroup stored ...:log-group:<name>:* while groups created by ingest and EventBridge delivery stored it without :*. Every path now stores the :* form; arn (with :*) and logGroupArn (without) render from it per the model. Also fixes stream ARNs like log-group:g:*:log-stream:s for CreateLogGroup-made groups, and suffixed logGroupIdentifier/syslog ARNs. Older snapshots (either form) still resolve.
  • perf(bedrock-agent-runtime): compile identifier regexes once. The helpers recompiled their regexes on every request despite the "Cached regexes" comment; they're LazyLock<Regex> now. Patterns byte-identical (they mirror the Smithy model's ECMA semantics).

No surface changes.

Test plan

  • New tests (each fails without its fix): event_record_carries_stream_region (eu-west-2 + cn-north-1), archive_rule_on_custom_bus_carries_bus_in_arn (custom + default bus), created_and_implicit_log_groups_describe_identically (+ EventBridge delivery assertions).
  • cargo check --workspace --all-targets; cargo test on cloudformation, logs, eventbridge, the server binary and bedrock-agent-runtime; clippy -D warnings; fmt.

Summary by cubic

Fixes four correctness issues found while auditing ARN handling across services.

Four independent fixes:

  • Kinesis event-source records: awsRegion was hardcoded to us-east-1; now taken from the stream ARN.
  • EventBridge archives: CreateArchive built the managed rule ARN in the default-bus form even for custom-bus archives; it now puts the source bus in the ARN, matching AWS.
  • CloudWatch Logs ARN forms: CreateLogGroup stored group ARNs with a trailing :*, while implicitly created groups stored them without. All creation paths now store the same :* form, and readers use the suffix-less form for logGroupArn/logGroupIdentifier and stream ARNs. Older snapshots in either form still resolve.
  • Bedrock agent runtime: Identifier regexes are now compiled once via LazyLock instead of on every request. Patterns unchanged.

Migration

  • No surface changes or migration steps; older snapshots continue to work.

Written for commit c130ba0. Summary will update on new commits.

Review in cubic

The Kinesis -> Lambda event source mapping poller hardcoded awsRegion to us-east-1 in every record it delivered, so a function reading from a stream in any other region saw the wrong region. Take it from the stream ARN, as the Pipes Kinesis source already does.
CreateArchive always minted the Events-Archive-<name> rule ARN in the default-bus form (rule/<name>), even when the archive's source was a custom bus. Rules on a custom bus are rule/<bus>/<name>, so DescribeRule/ListRules on that bus reported an ARN that named no rule. Build it with rule_arn and the resolved source bus.
CreateLogGroup stored the group ARN with the trailing :* while groups created implicitly (in-process ingest, EventBridge CloudWatch Logs targets) stored it without, and every reader compensated differently. The result was visible on the wire: log streams created by ingest in a CreateLogGroup group got an ARN of log-group:<g>:*:log-stream:<s>, ListSyslogConfigurations logGroupArn and GetTransformer/DescribeFieldIndexes logGroupIdentifier carried :* only for explicitly created groups, and a delivery-source match on the group ARN depended on how the group came to exist.

All creation paths now store the :* form (log_group_stored_arn), and LogGroup exposes log_group_arn()/wildcard_arn()/stream_arn() so DescribeLogGroups reports arn with :* and logGroupArn without (as the model documents), stream ARNs hang off the suffix-less ARN, and the logGroupArn/logGroupIdentifier fields use the suffix-less form. The accessors tolerate a stored ARN without the suffix, so snapshots written before this still describe correctly.
The re_* helpers sat under a "Cached regexes" comment but called Regex::new on every invocation, recompiling each identifier pattern on every request (Retrieve also compiled its knowledge-base pattern inline). Hold each pattern in a LazyLock<Regex> and hand out &'static Regex. The pattern strings are unchanged byte-for-byte.
@vieiralucas
vieiralucas merged commit 52ccbaf into main Sep 30, 2026
158 checks passed
@vieiralucas
vieiralucas deleted the fix/small-correctness-followups branch September 30, 2026 00:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant