Skip to content

Add per-ID native AWS store providers - #414

Draft
ChristianPavilonis wants to merge 3 commits into
docs/outbound-http-specfrom
issue-410-native-store-providers
Draft

ChristianPavilonis wants to merge 3 commits into
docs/outbound-http-specfrom
issue-410-native-store-providers

Conversation

@ChristianPavilonis

@ChristianPavilonis ChristianPavilonis commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Select local, supplied or built-in native stores independently per logical ID, without changing portable store traits or requiring Send setup futures.
  • Add default-off AppConfig Agent whole-document and Secrets Manager whole-value startup snapshots, shared quotas/deadlines and atomic registry preparation before the application initializer/listener.
  • Wire generated native features, SDK-free structural CLI validation and AWS-bound config-push refusal; prove the actual generated consumer against literal-loopback service fixtures.

First-version diagnostic limitation: EdgeZero-owned errors/debug output discard or redact provider details. AWS SDK/dependency DEBUG/TRACE output is not suppressed and can expose secret ARNs and credential-source metadata; LOG_SENSITIVE_BODIES=true can expose response details. Keep those dependency levels off unless operators have reviewed their logging configuration. Scoped suppression was rejected because it can permanently disable application tracing-to-log fallback. No application-wide logging/subscriber policy is installed by the provider.

Stack and scope

Created as a draft with gh stack; one new stack member based on docs/outbound-http-spec / #275 at ea66eff045512cccc60646d6ec339e83ff44fed7. The diff includes the compatible production startup/bounded-shutdown lifecycle bridge for #406 plus #410. Neither existing prerequisite PR was changed; they remain open, not accepted-main contracts.

Real AWS/IAM/deployment/image acceptance was explicitly declined and is excluded. No AWS service calls, image pulls or deployment were performed. Fixtures use dummy credentials, isolated profiles and literal-loopback endpoints.

Changes

Crate / File Change
edgezero-store-aws SDK-free strict settings; feature-gated shared preparation, private immutable snapshots, Agent transport and pinned Secrets Manager SDK
edgezero-adapter-axum Captured bindings/bootstrap, per-ID source planning, non-Send overrides, required startup and generated-entry integration
edgezero-cli / templates Shared Cargo feature normalization for exact native build/serve forms; custom shells unchanged; structural-only validation; selected AWS push refusal
Tests / CI / lockfiles Provider feature matrix, production failure atomicity, actual generated consumer, SDK graph isolation, preserved generated WASM builds
Guides / spec / plan Native setup, limits, restart/stale-secret semantics, IAM guidance and diagnostic/review limitations

The default 8 MiB retained-payload cap applies per shared preparation session, not process/RSS; opaque caller handles, independent sessions, SDK allocations and typed application state are excluded. Snapshots adopt remote changes only on restart. No live refresh, publishing, provisioning, secret mutation or provider registry is added.

Bindings validation deliberately reports structural-only / provider availability unknown. No unproven offline Cargo resolver or availability verdict is shipped. Agent image release/digest selection remains an operator review item; the guide contains no invented pin.

Closes

Closes #410

Test plan

Re-run after rebasing onto latest #275. All 24 coordinator gates passed at the checked source tree; logs, exact commands and stable input fingerprints retained locally in /tmp/native-store-integration/final-checks/.

  • cargo test --workspace --all-targets
  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo fmt --all -- --check
  • cargo check --workspace --all-targets --features "fastly cloudflare spin"
  • Fastly wasm32-wasip1, Spin wasm32-wasip2, Cloudflare wasm32-unknown-unknown
  • examples/app-demo workspace tests and lifecycle fixture tests
  • Docs lint, full formatting and build; strict all-feature public rustdoc
  • Agent-only, Secrets-only and both-service tests plus isolated Clippy; SDK-free CLI/default/Agent-only/WASM normal dependency graphs
  • Five production startup subprocess scenarios using the real SDK loopback request path, mixed local/AWS stores, nested secret failure, denial/no fallback and shared quota failure
  • Both ignored generated-project tests explicitly executed: actual CLI build/default-off/individual/both provider selections and gated HRTB startup; original host/strict-Clippy/core-tests/typed-CLI/three-WASM proof
  • Separate end-to-end generated edgezero serve invocation. Shared build/serve argument selection and action gating are unit/source-tested; generated build and production startup are executed.
  • Real AWS acceptance, intentionally excluded

Checklist

  • Follow CLAUDE.md conventions
  • No new Tokio dependency in core or adapter crates; native provider dependencies are feature/target gated
  • Brace route parameters and core application-facing types
  • Per-ID KvRegistry / ConfigRegistry / SecretRegistry wiring
  • New code has deterministic regression tests; no real credentials or secret values committed
  • Dependency diagnostic disclosure is prominent before review

@ChristianPavilonis ChristianPavilonis self-assigned this Oct 8, 2026
@ChristianPavilonis ChristianPavilonis changed the title issue 410 native store providers Add per-ID native AWS store providers Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant