Skip to content

fix(toolkit-lib): classify create-only properties as non-hotswappable - #1967

Merged
mrgrain merged 2 commits into
aws:mainfrom
dedsec-terminal:fix/hotswap-create-only-properties
Sep 23, 2026
Merged

mrgrain merged 2 commits into
aws:mainfrom
dedsec-terminal:fix/hotswap-create-only-properties

Conversation

@dedsec-terminal

@dedsec-terminal dedsec-terminal commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

fixes #1965.

The generic Cloud Control hotswap handler passed every changed property to classifyChanges as a hotswap candidate without consulting the resource type's createOnlyProperties. A change like SQS QueueName was therefore PATCHed in place and hard-failed with NotUpdatableException under both --hotswap and --hotswap-fallback, and fallback never triggered because the change had been classified hotswappable.

The handler now reads createOnlyProperties from the registry schema via cloudformation DescribeType before classifying, and treats those properties as non-hotswappable up front through the existing classifyChanges path. --hotswap skips them like any other non-hotswappable change, and --hotswap-fallback falls back to a full CloudFormation deployment. When the schema cannot be retrieved the lookup returns empty and behavior is unchanged. A mixed change still hotswaps its mutable properties; only the create-only ones are held back.

Verified with two new unit tests in cloud-control-hotswap-deployments.test.ts (each running in both hotswap-only and fall-back modes): a create-only-only change sends no UpdateResource call, and a mixed change PATCHes only the mutable property. Both tests fail against the unfixed code. Full cloud-control suite passes (63 tests), tsc compiles, and eslint reports no new findings on the touched files (the no-literal-partition errors elsewhere in the package pre-exist on main).

  • Unit tests added/updated
  • Integration tests added/updated (not applicable, classification logic covered by unit tests)
  • No manual edits to generated files

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license

The generic Cloud Control hotswap handler passed every changed property to classifyChanges as a hotswap candidate without consulting the resource type's createOnlyProperties, so a change like SQS QueueName was PATCHed in place and hard-failed with NotUpdatableException under both --hotswap and --hotswap-fallback.

The handler now reads createOnlyProperties from the registry schema via DescribeType before classifying, and treats those properties as non-hotswappable up front, so --hotswap skips them and --hotswap-fallback falls back to a full deployment. Schema lookup failures keep the previous behavior.
Copilot AI lite review requested due to automatic review settings September 14, 2026 21:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@ShadowCat567 ShadowCat567 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution @dedsec-terminal! It looks good overall! One minor comment about variable names

@mrgrain
mrgrain added this pull request to the merge queue Sep 23, 2026

This branch was successfully deployed

3 active (1 outdated) deployments
integ-approval — bf29b6a7 Deployed Sep 16, 2026 by dedsec-terminal via prepare #6914
automation — aaf7842d Deployed Sep 14, 2026 by dedsec-terminal via Set AutoQueue on PR #1967 #3544
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

5 participants