Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions changes/unreleased/Added-20260913-120000.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
kind: Added
body: 'The 226 AWS services DevCloud does not register now have their Smithy models
vendored, so codegen covers all 420 models. No service is registered yet and every
published coverage figure is unchanged'
Issue: "160"
24 changes: 17 additions & 7 deletions internal/codegen/gen_aliases_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -178,24 +178,34 @@ func TestBuildAliasesOverTheFleet(t *testing.T) {

table, collisions := BuildAliases(models)

// Ten, and every one is a name no claimant carries as its own ID. The cases
// where a claimant does — dynamodb, rds, ses, sagemaker, bedrock, forecast,
// personalize, transcribe — are settled by selfNamedClaimant and
// deliberately absent here. That rule is also why onboarding the demand set
// added only two entries: api-gateway, elastic-load-balancing and
// kinesis-analytics each publish their contested name as their own service
// ID, so the generator settles them without a human.
// Twenty, and every one is a name no claimant carries as its own ID. The
// cases where a claimant does — dynamodb, rds, ses, sagemaker, bedrock,
// forecast, personalize, transcribe — are settled by selfNamedClaimant and
// deliberately absent here. That rule is also why vendoring the remaining 226
// models added only ten entries: a newly vendored model that publishes its
// contested name as its own service ID takes the alias with no collision at
// all, which is why sso and cloudhsm are pinned in the gateway instead.
assert.Equal(t, []string{
"amazonrdsv19", // rds, docdb, neptune
"aws-marketplace", // 7 marketplace* clients, 6 by ARN namespace
"awsevents", // cloudwatchevents, eventbridge
"awswaf", // waf, wafv2
"cassandra", // keyspaces, keyspacesstreams
"cognito", // cognitoidentity, cognitoidentityprovider
"ds", // directoryservice, directoryservicedata
"email", // ses, sesv2
"es", // elasticsearchservice, opensearch
"events", // cloudwatchevents, eventbridge
"execute-api", // apigatewaymanagementapi, connectparticipant
"lex", // 4 Lex services, none named "lex"
"mgh", // migrationhub, migrationhubconfig
"partnercentral", // 5 partnercentral* clients share the signing name
"runtime.sagemaker", // sagemakerruntime, sagemakerruntimehttp2
"simpleemailservice", // ses, sesv2
"sms-voice", // pinpointsmsvoice, pinpointsmsvoicev2
"timestream", // timestreamquery, timestreamwrite
"timestream_20181101", // same pair: identical shape name AND version
"wisdomservice", // qconnect, wisdom
}, collisions, "a new collision is a routing decision that needs a human")

// Spot-check aliases the hand-written switch used to carry, now derived.
Expand Down
8 changes: 8 additions & 0 deletions internal/gateway/aliases_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -120,6 +120,14 @@ var goldenAliases = []struct{ alias, service string }{
{"email", "ses"},
{"s3", "s3"},
{"lambda", "lambda"},

// Below: neither of the above. The old switch never named cloudhsm, and it
// did not fall through either — the derived table answered cloudhsmv2 for it
// while no cloudhsm model existed. Vendoring that model made the alias
// self-named, so selfNamedClaimant handed it to a service with no provider,
// with no collision for TestServiceIDOverridesResolveEveryCollision to
// catch. Pinned to the answer it gave before, by the Group 3 override.
{"cloudhsm", "cloudhsmv2"},
}

// TestNormalizeServiceIDPreservesEveryKnownAlias is the regression lock for
Expand Down
42 changes: 33 additions & 9 deletions internal/gateway/protocol.go
Original file line number Diff line number Diff line change
Expand Up @@ -202,6 +202,31 @@ var serviceIDOverrides = map[string]string{
// hand-written provider — then URL-path routing, as DetectProtocol already
// does for opensearch, becomes worth the code.
"lex": "",
// EventBridge is CloudWatch Events renamed, and the retired name has its own
// model now. Both aliases keep meaning the service DevCloud registers.
"events": "eventbridge",
"awsevents": "eventbridge",
// Directory Service's data plane signs with the control plane's name.
"ds": "directoryservice",
// apigatewaymanagementapi publishes execute-api as its endpoint prefix and is
// the registered claimant; connectparticipant only signs with it. A REST API
// invoke signs as execute-api too and lands here, which is where it already
// landed: DevCloud registers no invoke data plane for it to reach instead.
"execute-api": "apigatewaymanagementapi",
// Keyspaces Streams is the split-out; the control plane owns "cassandra".
"cassandra": "keyspaces",
// migrationhub-config is the split-out.
"mgh": "migrationhub",
// Wisdom was renamed Q Connect and both still publish "WisdomService".
"wisdomservice": "qconnect",
// Pinpoint SMS Voice v1 and v2 share every identifier and, unlike SES, no
// protocol difference separates them. No basis to pick.
"sms-voice": "",
// Seven Marketplace clients publish "aws-marketplace": six as their ARN
// namespace, marketplace-agreement as its signing name.
"aws-marketplace": "",
// Five Partner Central clients share the signing name.
"partnercentral": "",

// --- Group 2: legacy identifiers no model publishes ---
"amazonkinesis": "kinesis",
Expand Down Expand Up @@ -235,15 +260,14 @@ var serviceIDOverrides = map[string]string{

// --- Group 3: substitutions for services DevCloud does not register ---
//
// Only one entry left, and the reason the others went is worth keeping.
// "apigateway" resolves to apigatewayv2 and "sso" to ssoadmin without any
// help here, because those services publish those names and the service
// that would contest them is not modelled. That is a substitution the
// models happen to make, not one anybody chose — and it stops being silent
// the moment the missing model is added, because the alias becomes a
// collision and TestServiceIDOverridesResolveEveryCollision fails until
// somebody decides. Deliberately not pinned here: pinning it would make
// that decision now, invisibly, for a service that does not exist yet.
// sso and cloudhsm have in-tree models now, and each names itself — so
// selfNamedClaimant awards the alias to a service no provider is registered
// for, with no collision reported and nothing but goldenAliases to notice.
// Pinned to the answer they gave before the models arrived. Delete both when
// internal/services/{sso,cloudhsm} exist; leaving them would then send those
// services' traffic to the neighbour that used to stand in for them.
"sso": "ssoadmin",
"cloudhsm": "cloudhsmv2",
// Timestream Query and Timestream Write share the shape name
// Timestream_20181101 and the version 2018-11-01, so neither the alias nor
// the protocol separates them. Pinned to write, which is where these
Expand Down
168 changes: 168 additions & 0 deletions internal/generated/accessanalyzer/base_provider.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading