Skip to content

Reject dangling ${resources.*} refs at validate time - #6300

Draft
radakam wants to merge 1 commit into
mainfrom
fix-dangling-resource-refs
Draft

Reject dangling ${resources.*} refs at validate time#6300
radakam wants to merge 1 commit into
mainfrom
fix-dangling-resource-refs

Conversation

@radakam

@radakam radakam commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Changes

Add validate.DanglingResourceReferences in initialize so ${resources.*} refs to undefined resources fail at validate (and deploy) instead of later with an invalid dependency.

Why

bundle validate --strict accepted configs like group_name: ${resources.jobs.does_not_exist.id}. Direct deploy then failed with invalid dependency … no such node. Catch the misconfiguration at validate.

Found by fuzz testing.

Tests

  • Reproduced on dogfood against origin/main: validate OK, direct deploy → invalid dependency
  • Confirmed fix on dogfood: validate --strict / deploy both exit 1 with reference does not exist
  • Unit tests + acceptance bundle/validate/dangling_resource_refs (terraform & direct)

validate --strict previously accepted references to undefined
resources; deploy then failed with an invalid dependency. Fail early
during initialize with the same "reference does not exist" error.
// Identity is resources.<group>.<name>; trailing fields (.id, .permissions, …)
// are resolved at deploy time and are not required to exist in config.
resourceKey := p[:3]
v, err := dyn.GetByPath(b.Config.Value(), resourceKey)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This checks dynamic tree but references can be to things that are not in the config (remote references in direct and terraform-specific fields).

So it's too strict.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think once we remove terraform we can think about validating these but for now not worth it.

@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: 2b057b9

Run: 32119178364

Env 🟨​KNOWN 💚​RECOVERED 🙈​SKIP ✅​pass 🙈​skip Time
🟨​ aws linux 3 1 4 286 1151 6:21
🟨​ aws windows 3 1 4 288 1149 7:12
🟨​ azure linux 3 1 4 285 1151 6:57
🟨​ azure windows 3 1 4 287 1149 7:16
💚​ gcp linux 1 5 286 1151 6:00
💚​ gcp windows 1 5 288 1149 5:43
8 interesting tests: 4 SKIP, 3 KNOWN, 1 RECOVERED
Test Name aws linux aws windows azure linux azure windows gcp linux gcp windows
💚​ TestAccept 💚​R 💚​R 💚​R 💚​R 💚​R 💚​R
🙈​ TestAccept/bundle/invariant/no_drift 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/bundle/resources/vector_search_endpoints/drift/recreated_same_name 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/bundle/resources/vector_search_indexes/recreate/embedding_dimension 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🙈​ TestAccept/ssh/connection 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S 🙈​S
🟨​ TestFetchRepositoryInfoAPI_FromRepo 🟨​K 🟨​K 🟨​K 🟨​K 🙈​S 🙈​S
🟨​ TestFetchRepositoryInfoAPI_FromRepo/root 🟨​K 🟨​K 🟨​K 🟨​K
🟨​ TestFetchRepositoryInfoAPI_FromRepo/subdir 🟨​K 🟨​K 🟨​K 🟨​K
Top 6 slowest tests (at least 2 minutes):
duration env testname
5:43 aws windows TestAccept
5:36 gcp windows TestAccept
5:34 azure windows TestAccept
3:54 gcp linux TestAccept
3:46 azure linux TestAccept
3:44 aws linux TestAccept

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants