Skip to content

Latest commit

ย 

History

3,034 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

AWSops Dashboard

GitHub stars GitHub forks GitHub issues License Version Last commit PR Review

English Korean

AWS + Kubernetes operations dashboard with real-time monitoring, a private CloudFront/Fargate edge, Aurora Serverless v2 state, and AI-powered diagnosis via Amazon Bedrock AgentCore. | ๋น„๊ณต๊ฐœ CloudFront/Fargate ์—ฃ์ง€, Aurora Serverless v2 ์ƒํƒœ ์ €์žฅ, Amazon Bedrock AgentCore ๊ธฐ๋ฐ˜ AI ์ง„๋‹จ์„ ๊ฐ–์ถ˜ ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง AWS + Kubernetes ์šด์˜ ๋Œ€์‹œ๋ณด๋“œ์ž…๋‹ˆ๋‹ค.


English

Overview

AWSops v2 is a single-pane operations dashboard for AWS and Kubernetes, rebuilt as a Terraform-based MSA: a private edge (CloudFront VPC Origin โ†’ internal ALB โ†’ ECS Fargate), Cognito + Lambda@Edge auth, Aurora Serverless v2 persistent state, AgentCore section agents for live AWS queries, and an OOM-safe async worker tier. The previous v1 architecture (single EC2, CDK, embedded Steampipe) is being decommissioned per ADR-016 โ€” per ADR-016 (decision records are maintained in the private upstream repository).

AWSops v2 Architecture

Internet -> CloudFront (TLS, Lambda@Edge Cognito auth) -> VPC Origin (https-only) -> internal ALB (HTTPS)
  -> ECS Fargate: Next.js 15 thin-BFF :3000 (arm64, no basePath) -> Aurora Serverless v2 (PG 17.9, node-pg)
  -> Amazon Bedrock AgentCore: Runtime (Strands) + 9 section Gateways + Memory + Code Interpreter
  -> async workers: POST /api/jobs -> SQS -> Step Functions -> Lambda or Fargate worker

Stats: 41 pages, 99 API routes, 110 components (web/), 21 consolidated ADRs, Terraform-managed (terraform/foundation, no CDK).

No public ALB. The edge is fully private โ€” CloudFront reaches the ALB only through a VPC Origin, and the ALB only accepts traffic from CloudFront's managed security group. v2's posture is a read-only ops dashboard + AI diagnosis: AWS-resource mutation and autonomous remediation are FROZEN by design (ADR-005) โ€” infra changes stay with the operator's own IaC/Change Manager, with one narrowly-scoped exception for self-healing service restarts (ADR-015). (ADR-019's SG-rules Athena role is a separate, ordinary GATED feature โ€” ADR-019 concludes it sits inside the existing read-only invariant and is not an ADR-005 exception.)

Features

  • Resource inventory -- EC2, EKS, Lambda, ECS clusters/tasks, ECR, storage/DB, network, and security groupings, derived from Aurora-persisted inventory snapshots (with an optional flag-gated Steampipe sync layer).
  • AI assistant -- Bedrock AgentCore Runtime (Strands agent) routes each question to 1-3 of 9 section gateways in parallel and synthesizes the result, with SSE streaming, AgentCore Memory (conversation history), and a Python Code Interpreter.
  • CIS compliance -- Powerpipe benchmark runs with history (compliance_runs/compliance_results), flag-gated.
  • Cost and FinOps -- Cost Explorer, Bedrock usage/spend tracking, and 14-day resource-trend charts on the dashboard.
  • Async diagnosis and jobs -- long-running work (AI diagnosis reports via POST /api/diagnosis, compliance scans via POST /api/compliance/run) is enqueued to the same SQS + Step Functions + Lambda/Fargate worker tier as the generic POST /api/jobs route โ€” the web tier never blocks on OOM-risk work. /api/jobs itself only accepts noop/noop-heavy job types (diagnosis/compliance compute requestedBy server-side and reject attacker-controlled report/run ids); GET /api/jobs and GET /api/jobs/[id] enforce owner-or-admin visibility.
  • EKS onboarding -- configure.mjs provides host-account Terraform onboarding. Enabled member clusters register through the web UI using the registered member role for discovery and default Kubernetes authentication; that role needs its own Access Entry/read policy. Explicit SA-token and same-member AssumeRole authentication are supported.

AI Gateways (Amazon Bedrock AgentCore)

9 section gateways are defined in Terraform (ai.tf); each is provisioned idempotently and routes to Lambda-backed MCP tools. All 9 gateways hold READY MCP targets โ€” the fleet (local.agent_lambdas, 30 slices: 21 gated on agentcore_enabled, 9 on integrations_enabled) is deployed; the table below reflects the live shape.

Gateway Capabilities Status
network VPC, ENI, reachability, flow logs, TGW, VPN, firewall โœ… live
security IAM users/roles/policies + policy simulation (14 tools, iam-mcp) โœ… live
container EKS, ECS, Istio, Kubernetes โœ… live
data DynamoDB, RDS/Aurora, ElastiCache, MSK, OpenSearch โœ… live
cost Cost Explorer, forecast, budgets, container cost โœ… live
monitoring CloudWatch, CloudTrail โœ… live
iac CloudFormation, CDK, Terraform โœ… live
ops Aurora-backed inventory/topology reads + AWS docs/CLI suggestions (no live Steampipe) โœ… live
external-obs External observability & integrations (Prometheus, ClickHouse, Notion) โœ… live

All 9 rows are gated behind agentcore_enabled/integrations_enabled (default false in a fresh clone/deploy โ€” plan = No changes, $0); "live" here describes this project's actual running deployment, which has both flags on.

Models: Claude Sonnet 5 (default), Opus 4.8 (deep analysis), Haiku 4.5 (fast/low-cost).

Prerequisites

  • Terraform >= 1.15 (S3 native state locking via use_lockfile)
  • Node.js >= 18 (configurator TUI, migration scripts)
  • Docker with buildx (arm64 image builds)
  • AWS CLI configured with credentials for the target account
  • kubectl and a kubeconfig, if onboarding EKS clusters

Installation

# Clone the repository
git clone https://github.com/Atom-oh/awsops.git
cd awsops

# Interactive TUI: choose new/existing VPC, domain, bucket, EKS clusters
make configure          # -> terraform.tfvars + backend.hcl

# Provision the foundation stack
terraform -chdir=terraform/foundation init -backend-config=backend.hcl
terraform -chdir=terraform/foundation plan -out tfplan
terraform -chdir=terraform/foundation apply tfplan

# New, verified-empty DB only, from an approved host with private Aurora connectivity:
INITIALIZE_EMPTY_DB=1 make migrate
# For an existing ledger use make migrate; INTEGER ledgers need the separate BOOTSTRAP gate.
# See terraform/foundation/migrations/README.md for runtime image/env/IAM/TLS and recovery.

# Build + push web, roll ECS and wait for /api/health (reruns migrate first; any failure blocks deploy)
make deploy

# After migrations: build/push the agent image and run the idempotent provisioner.
# make agentcore does not create the reader role or sync its password.
# See docs/runbooks/agent-sql-reader.md.
make agentcore

# After apply with workers_enabled=true: build/push the worker image
make workers

Usage

make help              # list all available targets
make migrate-status    # offline: app version + each on-disk migration's release
make backfill-owner-sub # PLAN the legacy email-keyed requested_by -> Cognito sub rewrite (changes
                        # nothing). Review the plan, delete entries you cannot vouch for, then
                        # `node scripts/v2/backfill-owner-sub.mjs --apply <plan.json>`. Quiesce the
                        # schedule dispatcher first โ€” the plan output prints the exact commands. Step 2
                        # of ADR-009's Ownership Amendment; step 3 is legacy_email_owner_match=false.
DRY_RUN=1 make migrate  # preview pending DB migrations before applying
make upgrade            # safe release upgrade: RDS snapshot -> migrate -> deploy

Configuration

Runtime configuration is flag-gated in the Terraform foundation root (variables.tf, ai.tf, and ci-migrations.tf). The feature gates below all default false, so their gated resources are absent from a fresh plan. Four operational switches deliberately do NOT: legacy_email_owner_match (default true โ€” accepts the legacy email-keyed ownership match at every matchesIdentity() gate โ€” reads and report PATCH/DELETE via canMutateReport(), not reads alone; flip to false only after a successful --apply leaves zero legacy email-keyed rows, or a plan that finds none at all โ€” a clean plan over rows that still need rewriting is not enough, make backfill-owner-sub only plans; see ADR-009's Ownership Amendment), the pre-existing create_network / allow_vpc_db_access, and publish_service_dns:

publish_service_dns defaults to true; false removes service A aliases from the desired configuration, but does not disable certificate validation CNAMEs. The nullable existing_cf_certificate_arn / existing_alb_certificate_arn inputs default to null (Terraform-managed certificates). External certificates must already be issued and trusted; CloudFront's must be in us-east-1, and the ALB's in the stack Region. For DNS-free deployment, an explicit dispatch preserves existing managed certificate ownership and service aliases. External certificates require operator-selected ARNs or already-attached external certificates; CI never scans the account to choose one. allow_dns_changes is a dispatch input (default false), separate from publish_service_dns; it prohibits private Cloud Map changes too. Routine CI cannot externalize a managed certificate or retire/replace its validation CNAMEs even when DNS is allowed. PR/push plans are advisory and cannot be applied; dev preserves ownership from state without live certificate/SAN checks. Dev repo variables override domain/zone consistently in console and plan, with CERTIFICATE_MODE_DEV=preserve|managed. Explicit domain_rollout=true on each dev/full domain-stage plan pins scoped DNS checks in saved metadata; its default false retains ordinary DNS behavior only with explicit permission. Apply cannot toggle that saved scope. See the unpublished/same-domain rollout runbook, edge reference and deployment runbook ยง5.

Flag Gates
agentcore_enabled 21 of the AgentCore Lambda slices
ci_readiness_enabled Default-off bounded billed deployment probe. Dedicated CI_READINESS_ENABLED_DEV=true/false overrides the dev value; unset preserves explicit tfvars/default false. The runtime profile alone does not enable it. Before the mandatory dev Deploy Web gate, apply steampipe_enabled=true, agentcore_enabled=true, workers_enabled=true and readiness, deploy the inventory/worker images, ensure worker dispatch is enabled, and provision AgentCore as described in runtime activation, which requires post-marker success with known counts and zero unknown attributes for every current catalog type plus runtime and worker proof; health-only verification cannot bypass it. Public CI permits enabled readiness only on dev. Apply requires AgentCore for the verifier group and create_demo_user=true for managed-demo membership. Each activated dev release invokes collection, a billed model probe and two real worker jobs. No admin/IAM grant.
integrations_enabled remaining 6 AgentCore Lambda slices
workers_enabled the async worker tier (SQS/SFN/Lambda/Fargate)
ci_migrations_enabled Default-off operator capability: private migration task template, exact-secret task role/policy and 14-day logs. Private dev CI migration: manual dispatch or the guarded current-source Deploy Web path; no service or scheduler. Disabling deletes the log group/history.
steampipe_enabled the Steampipe inventory-sync data layer
inventory_host_only Default-off collector scope: require exactly one enabled host and omit collector AssumeRole. Agent MCP grants stay unchanged; dev requires profile-bound host verification. See runtime activation and ADR-011 onboarding.
finops_baseline_enabled the FinOps baseline-recommendations engine (ADR-020): a daily Fargate rule batch (unattached EBS volumes; EC2/RDS rightsizing via Compute Optimizer) writing to finops_findings, read-only, rendered on /cost. Requires workers_enabled only at the Terraform level โ€” but the EBS rule additionally needs a fresh steampipe_enabled=true inventory sync at runtime; without it, that rule honestly reports partial (EC2/RDS rightsizing still work)
official_mcp_enabled ADR-017 curated official-vendor MCP presets โ€” the 3 vendor-hosted ones (DatadogยทDynatraceยทNew Relic) as external-obs mcpServer targets. (The runtime fail-closed tool allowlist is NOT gated by this flag โ€” it is written on every provisioner run and enforced unconditionally; that unconditionality is the fail-closed property.) Operator notes: Dynatrace ships with a deliberately EMPTY allowlist (zero tools until its hosted tool list is transcribed into catalog.py); make agentcore waits for runtime READY (default 300s, AGENTCORE_RUNTIME_READY_TIMEOUT) and a failed/slow rollout temporarily retires eligible live targets until the next successful run.
graph_querygen_enabled LLM fallback for the ONE ClickHouse trace_spans graph query (ADR-018). Note it does NOT carry the diag-signal path's identifier sanitising, relevance gate, weekly budget or read-side gate โ€” ADR-018 ยงC
diag_signal_querygen_enabled LLM fallback for ONE Explore diag-signal chip, only when a kind's deterministic catalog yields zero ready rows (a partial match is not topped up), and only for the chips โ€” the diagnosis report never uses generated rows, and a flag-off read excludes them too. Separate from graph_querygen_enabled; both need datasource_diagnosis_enabled; graph_querygen_enabled ALSO requires agentcore_enabled (it provisions the Code Interpreter session IAM)
sg_rule_activity_enabled the SG Rules Athena-based traffic-evidence pipeline (/network/security-groups/rules) โ€” the Athena/Glue broker Lambda, the daily sg_rule_scan worker job, and their Terraform (sg-rules.tf)
network_path_check_enabled the Network Path Check page/worker (network-path.tf) โ€” fetch_live_topology() is now real (cache-only, from Aurora's synced topology), but a full live AWS/Kubernetes re-read at run time is still deliberately unimplemented, so POST .../runs still 503s unimplemented even with this flag on; see the Network Path Check changelog entry. A pod/node source's live identity confirmation additionally needs an EKS Access Entry โ€” for the worker task role on a host-account cluster (this feature's _default_k8s_get() uses that role's own credentials directly when the source's account is the host account), or for the target account's AWSopsReadOnlyRole on a member-account cluster (the K8s GET is authenticated via that assumed session instead, so registering the worker task role there is a no-op and every GET 403s) โ€” see docs/runbooks/network-path-eks-access.md + scripts/v2/eks/register-network-path-access.sh (ROLE_ARN=... overrides the principal for the member-account case)

Runtime IAM narrowing is independent of these opt-in flags: the next apply changes permissions on already-enabled stacks, including main (three web SSM parameters, runtime discovery/token actions, own-cluster task control and Claude-only models). Known regions include future opt-ins; this is not live-access proof.

One more ADR-017 gate is not a terraform flag: CLICKHOUSE_OFFICIAL_MCP is an AgentCore runtime env recorded by the provisioner (CLICKHOUSE_OFFICIAL_MCP=true make agentcore) that embeds the official mcp-clickhouse as a stdio subprocess in the runtime container. It is FROZEN / do-not-enable: the stdio path has no replacement for the in-house lambda's table-function SSRF guard, so unfreezing requires both the technical precondition and a new ADR + multi-AI panel + dated owner-override (ADR-017 ยงStatus, BASELINE ยง2).

Two companion maps (not booleans, both default {}) configure ADR-017 per preset โ€” official_mcp_endpoints (map(string), preset_key -> https:// endpoint) and official_mcp_read_only_ack (map(string), preset_key -> the exact endpoint URL the operator reviewed, echoed verbatim โ€” not true). A preset provisions only when its ack equals its current endpoint; anything else is a fail-closed SKIP that retires any live target:

official_mcp_endpoints     = { datadog = "https://mcp.datadoghq.com/v1/mcp" }
official_mcp_read_only_ack = { datadog = "https://mcp.datadoghq.com/v1/mcp" }

AgentCore's own config (runtime ARN, Memory ID, Code Interpreter ID) is written to SSM (/ops/awsops-v2/agentcore/*) by the provisioner and read by the web BFF at runtime โ€” never passed via task-def valueFrom (avoids a startup race).

Project Structure

awsops/
  web/                    # Next.js 15 thin-BFF: 41 pages, 99 API routes, 110 components
  agent/                  # Strands Agent (Runtime source) + MCP Lambda tool sources
  terraform/foundation/  # single Terraform root: network, edge, auth, data, workload, ai, workers, eks
  scripts/v2/             # configure/deploy/migrate/agentcore/workers tooling (all Node.js/Python)
  tests/                  # repo-wide hook/structure tests + PR-review/Steampipe/ExternalId wiring checks
  docs/                   # guides, runbooks, implementation references (ADR bodies remain private)
  docs-site/              # Docusaurus user guide (deployed separately)

Testing

Install the dependencies listed in merge verification. Docker and prepared AWSOPS_REVIEW_CODEC_STATE are also required; use the sandbox setup.

Image fixtures, including the panel-prompt structure check in tests/run-all.sh, require Python 3.12 on Linux ARM64/x86-64 and a separate hash-pinned Pillow install: python3 -m pip install --require-hashes --only-binary=:all: -r scripts/pr-review/image-requirements.txt. Do not combine this command with the unhashed requirements install. Private migration tests require npm ci --prefix scripts/v2 --ignore-scripts --no-audit --no-fund (pg + AWS SDK), OpenSSL and a reachable Docker daemon for postgres:17. The required migration, web connection-phase and agent tool-policy history PostgreSQL suites fail if Docker is missing; they use bare docker on PATH (the documented exceptions to optional legacy itests). The web connection and policy suites also require npm ci --prefix web for the locked driver and TypeScript. These suites and their offline companion use no AWS credentials. Authenticated deployment smoke tests require curl, OpenSSL, Python 3 with PyYAML and Terraform 1.15.7; their offline variable fixture needs no providers. Terraform mock tests require 1.15.7 and installed/cached providers; the helper copies only tracked working-tree files, runs init -backend=false, validates and tests without a real backend. Missing deployment-suite prerequisites fail the shared runner; only its final fmt/validate diagnostics are informational. The required test_ci_web_read.py and test_ci_web_deploy.py suites use Python 3.12 on Linux with /proc, POSIX process groups and os.geteuid; provider boundaries are simulated and those two suites do not invoke AWS CLI, gh, curl or jq. The required test_ci_web_workflow.py suite additionally needs PyYAML and Bash. Deploy Web uses the controller and forces automatic SQL admission for web-driven migrations; see docs/runbooks/release-safety-primitives.md. The offline web image provenance helper tests also require jq, Linux /proc, and curl on /usr/local/bin:/usr/bin:/bin. Deploy Web proves the image before private migrations, calls guarded promotion for that digest, then requires exact ECS/image verification and the full dev runtime gate including login/DB; the guide defines receipts and recovery. The release safety primitives describe the controller and migration policy. See web release for standalone bootstrap or unsupported SQL โ†’ successful migration/reader sync โ†’ fresh web dispatch, and legacy image recovery for images without receipts.

bash scripts/v2/merge-verify.sh   # required Python, web and deployment tests
node --test scripts/v2/ci/*.test.mjs # offline private migration runtime fixtures (CI required)
node --test scripts/v2/ci/migration.itest.mjs scripts/v2/ci/web-db-connection.itest.mjs scripts/v2/ci/agent-tool-policy.itest.mjs # real PG migration + web connections + agent policy regressions (CI required)
bash scripts/v2/terraform-test.sh # isolated, backend-disabled Terraform mock tests (also required in CI)
# Also CI-required when docs-site/ or .github/workflows/merge-verify.yml changes:
(cd docs-site && npm ci && npm run typecheck && npm run build &&
  bash scripts/verify-deck.sh static/presentation/awsops-intro/awsops-intro.pptx)
node --test scripts/v2/deployment-smoke.test.mjs # offline health/auth/credential preparation and workflow checks
bash tests/run-all.sh             # repo-wide hook/structure tests + agent Python unittests
(cd web && npx vitest run)        # web unit tests only

The private migration fixture command includes runtime, controller, workflow and mocked-plan checks. Controller/workflow checks also require Python 3 with PyYAML, boto3/botocore (pip install -r agent/requirements.txt) and Terraform 1.15.7. See merge verification for the complete CI scope, including the conditional documentation build and full presentation archive check.

API Documentation

The 99 API routes live under web/app/api/. Key routes: health (public), stream (SSE chat), db (Aurora ping), jobs (+/[id], async job submission/status), security, compliance, auth/login. See the docs site for user-facing guidance.

Contributing

  1. Fork the repository
  2. Create your branch (git checkout -b feat/amazing-feature)
  3. Commit your changes (git commit -m 'feat: add amazing feature')
  4. Push to the branch (git push origin feat/amazing-feature)
  5. Open a Pull Request

Target dev. Fork contributions are integrated through a maintainer-owned internal PR after patch inspection and full AI/CI review; fork tests alone do not satisfy the AI gate. See the contribution branch flow.

License

Licensed under the MIT License. See LICENSE for details.

Contact


ํ•œ๊ตญ์–ด

๊ฐœ์š”

AWSops v2๋Š” AWS์™€ Kubernetes๋ฅผ ์œ„ํ•œ ๋‹จ์ผ ํ™”๋ฉด ์šด์˜ ๋Œ€์‹œ๋ณด๋“œ๋กœ, Terraform ๊ธฐ๋ฐ˜ MSA๋กœ ์žฌ๊ตฌ์ถ•๋˜์—ˆ์Šต๋‹ˆ๋‹ค: ๋น„๊ณต๊ฐœ ์—ฃ์ง€(CloudFront VPC Origin โ†’ ๋‚ด๋ถ€ ALB โ†’ ECS Fargate), Cognito + Lambda@Edge ์ธ์ฆ, Aurora Serverless v2 ์˜์† ์ƒํƒœ, ๋ผ์ด๋ธŒ AWS ์กฐํšŒ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” AgentCore ์„น์…˜ ์—์ด์ „ํŠธ, OOM-์•ˆ์ „ ๋น„๋™๊ธฐ ์›Œ์ปค ๊ณ„์ธต์œผ๋กœ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค. ์ด์ „ v1 ์•„ํ‚คํ…์ฒ˜(๋‹จ์ผ EC2, CDK, ๋‚ด์žฅ Steampipe)๋Š” ADR-016์— ๋”ฐ๋ผ ํ๊ธฐ ์ง„ํ–‰ ์ค‘์ž…๋‹ˆ๋‹ค โ€” (๊ฒฐ์ • ๊ธฐ๋ก์€ ๋น„๊ณต๊ฐœ upstream ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ๊ด€๋ฆฌ๋ฉ๋‹ˆ๋‹ค).

AWSops v2 Architecture

Internet -> CloudFront (TLS, Lambda@Edge Cognito ์ธ์ฆ) -> VPC Origin (https-only) -> ๋‚ด๋ถ€ ALB (HTTPS)
  -> ECS Fargate: Next.js 15 thin-BFF :3000 (arm64, basePath ์—†์Œ) -> Aurora Serverless v2 (PG 17.9, node-pg)
  -> Amazon Bedrock AgentCore: Runtime (Strands) + 9 ์„น์…˜ Gateway + Memory + Code Interpreter
  -> ๋น„๋™๊ธฐ ์›Œ์ปค: POST /api/jobs -> SQS -> Step Functions -> Lambda ๋˜๋Š” Fargate ์›Œ์ปค

ํ˜„ํ™ฉ: 41 ํŽ˜์ด์ง€, 99 API ๋ผ์šฐํŠธ, 110 ์ปดํฌ๋„ŒํŠธ(web/), 21๊ฐœ ํ†ตํ•ฉ ADR, Terraform ๊ด€๋ฆฌ(terraform/foundation, CDK ์—†์Œ).

๊ณต๊ฐœ ALB ์—†์Œ. ์—ฃ์ง€๋Š” ์™„์ „ํžˆ ๋น„๊ณต๊ฐœ์ž…๋‹ˆ๋‹ค โ€” CloudFront๋Š” VPC Origin์„ ํ†ตํ•ด์„œ๋งŒ ALB์— ๋„๋‹ฌํ•˜๊ณ , ALB๋Š” CloudFront ๊ด€๋ฆฌํ˜• ๋ณด์•ˆ ๊ทธ๋ฃน์˜ ํŠธ๋ž˜ํ”ฝ๋งŒ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. v2์˜ ์ž์„ธ๋Š” read-only ์šด์˜ ๋Œ€์‹œ๋ณด๋“œ + AI ์ง„๋‹จ์ž…๋‹ˆ๋‹ค: AWS ๋ฆฌ์†Œ์Šค ๋ณ€๊ฒฝยท์ž์œจ ์กฐ์น˜๋Š” ์„ค๊ณ„์ƒ FROZEN(ADR-005) โ€” ์ธํ”„๋ผ ๋ณ€๊ฒฝ์€ ์šด์˜์ž ์ž์‹ ์˜ IaC/Change Manager๊ฐ€ ๋‹ด๋‹นํ•˜๋ฉฐ, ์ž๊ฐ€์น˜์œ  ์„œ๋น„์Šค ์žฌ์‹œ์ž‘ ํ•˜๋‚˜๋งŒ ์ข๊ฒŒ ์˜ˆ์™ธ ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค(ADR-015). (ADR-019์˜ SG-rules Athena role์€ ๋ณ„๊ฐœ์˜ ์ผ๋ฐ˜ GATED ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค โ€” ADR-019๋Š” ์ด๊ฒƒ์ด ๊ธฐ์กด read-only ๋ถˆ๋ณ€์‹ ๋‚ด๋ถ€์— ์žˆ๋‹ค๊ณ  ๊ฒฐ๋ก  ๋‚ด๋ฆฌ๋ฉฐ, ADR-005 ์˜ˆ์™ธ๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค.)

์ฃผ์š” ๊ธฐ๋Šฅ

  • ๋ฆฌ์†Œ์Šค ์ธ๋ฒคํ† ๋ฆฌ -- EC2, EKS, Lambda, ECS ํด๋Ÿฌ์Šคํ„ฐ/ํƒœ์Šคํฌ, ECR, ์Šคํ† ๋ฆฌ์ง€/DB, ๋„คํŠธ์›Œํฌ, ๋ณด์•ˆ ๊ทธ๋ฃนํ•‘์„ Aurora์— ์ €์žฅ๋œ ์ธ๋ฒคํ† ๋ฆฌ ์Šค๋ƒ…์ƒท ๊ธฐ๋ฐ˜์œผ๋กœ ์ œ๊ณต(์„ ํƒ์  flag-gated Steampipe sync ๊ณ„์ธต ํฌํ•จ).
  • AI ์–ด์‹œ์Šคํ„ดํŠธ -- Bedrock AgentCore Runtime(Strands ์—์ด์ „ํŠธ)์ด ๊ฐ ์งˆ๋ฌธ์„ 9๊ฐœ ์„น์…˜ ๊ฒŒ์ดํŠธ์›จ์ด ์ค‘ 1~3๊ฐœ๋กœ ๋ณ‘๋ ฌ ๋ผ์šฐํŒ…ํ•œ ๋’ค ๊ฒฐ๊ณผ๋ฅผ ํ†ตํ•ฉํ•˜๋ฉฐ, SSE ์ŠคํŠธ๋ฆฌ๋ฐยทAgentCore Memory(๋Œ€ํ™” ํžˆ์Šคํ† ๋ฆฌ)ยทPython Code Interpreter๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
  • CIS ์ปดํ”Œ๋ผ์ด์–ธ์Šค -- Powerpipe ๋ฒค์น˜๋งˆํฌ ์‹คํ–‰ ์ด๋ ฅ ๊ด€๋ฆฌ(compliance_runs/compliance_results), flag-gated.
  • ๋น„์šฉ ๋ฐ FinOps -- Cost Explorer, Bedrock ์‚ฌ์šฉ๋Ÿ‰/๋น„์šฉ ์ถ”์ , ๋Œ€์‹œ๋ณด๋“œ์˜ 14์ผ ๋ฆฌ์†Œ์Šค ํŠธ๋ Œ๋“œ ์ฐจํŠธ.
  • ๋น„๋™๊ธฐ ์ง„๋‹จยท์ž‘์—… -- AI ์ง„๋‹จ ๋ฆฌํฌํŠธ(POST /api/diagnosis)ยท์ปดํ”Œ๋ผ์ด์–ธ์Šค ์Šค์บ”(POST /api/compliance/run) ๋“ฑ ์žฅ์‹œ๊ฐ„ ์ž‘์—…์€ ๋ฒ”์šฉ POST /api/jobs์™€ ๋™์ผํ•œ SQS + Step Functions + Lambda/Fargate ์›Œ์ปค ๊ณ„์ธต์— ํ์ž‰ โ€” ์›น ํ‹ฐ์–ด๋Š” OOM ์œ„ํ—˜ ์ž‘์—…์„ ์ ˆ๋Œ€ ์ง์ ‘ ์‹คํ–‰ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. /api/jobs ์ž์ฒด๋Š” noop/noop-heavy ํƒ€์ž…๋งŒ ํ—ˆ์šฉํ•˜๋ฉฐ(์ง„๋‹จ/์ปดํ”Œ๋ผ์ด์–ธ์Šค๋Š” requestedBy๋ฅผ ์„œ๋ฒ„ ์ธก์—์„œ ๊ณ„์‚ฐํ•ด report/run id ์œ„์กฐ๋ฅผ ๋ง‰์Œ), GET /api/jobsยทGET /api/jobs/[id]๋Š” ์†Œ์œ ์ž-๋˜๋Š”-๊ด€๋ฆฌ์ž ๊ฐ€์‹œ์„ฑ์„ ๊ฐ•์ œํ•ฉ๋‹ˆ๋‹ค.
  • EKS ์˜จ๋ณด๋”ฉ -- configure.mjs๋Š” ํ˜ธ์ŠคํŠธ ๊ณ„์ •์˜ Terraform ์˜จ๋ณด๋”ฉ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ํ™œ์„ฑํ™”๋œ ๋ฉค๋ฒ„ ํด๋Ÿฌ์Šคํ„ฐ๋Š” ์›น UI์—์„œ ๋“ฑ๋กํ•˜๋ฉฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ์กฐํšŒ์™€ ๊ธฐ๋ณธ Kubernetes ์ธ์ฆ์— ๋“ฑ๋ก๋œ ๋ฉค๋ฒ„ ์—ญํ• ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ํ•ด๋‹น ์—ญํ• ์˜ Access Entryยท์ฝ๊ธฐ ์ •์ฑ…์ด ํ•„์š”ํ•˜๊ณ , ๋ช…์‹œ์  SA ํ† ํฐ๊ณผ ๋™์ผ ๋ฉค๋ฒ„ ๊ณ„์ •์˜ AssumeRole ์ธ์ฆ๋„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

AI ๊ฒŒ์ดํŠธ์›จ์ด (Amazon Bedrock AgentCore)

Terraform(ai.tf)์— 9๊ฐœ ์„น์…˜ ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์ •์˜๋˜์–ด ์žˆ์œผ๋ฉฐ, ๊ฐ๊ฐ ๋ฉฑ๋“ฑํ•˜๊ฒŒ ํ”„๋กœ๋น„์ €๋‹๋˜์–ด Lambda ๊ธฐ๋ฐ˜ MCP ๋„๊ตฌ๋กœ ๋ผ์šฐํŒ…๋ฉ๋‹ˆ๋‹ค. 9๊ฐœ ๊ฒŒ์ดํŠธ์›จ์ด ์ „๋ถ€ READY MCP ํƒ€๊นƒ์„ ๋ณด์œ ํ•ฉ๋‹ˆ๋‹ค โ€” ํ•จ๋Œ€(local.agent_lambdas, ์Šฌ๋ผ์ด์Šค 30๊ฐœ: 21๊ฐœ agentcore_enabled + 9๊ฐœ integrations_enabled ๊ฒŒ์ดํŠธ)๊ฐ€ ๋ฐฐํฌ๋˜์–ด ์žˆ์œผ๋ฉฐ, ์•„๋ž˜ ํ‘œ๋Š” ์‹ค์ œ live ์ƒํƒœ๋ฅผ ๋ฐ˜์˜ํ•ฉ๋‹ˆ๋‹ค.

Gateway ์ฃผ์š” ๊ธฐ๋Šฅ ์ƒํƒœ
network VPC, ENI, reachability, flow logs, TGW, VPN, firewall โœ… live
security IAM ์‚ฌ์šฉ์ž/์—ญํ• /์ •์ฑ… + ์ •์ฑ… ์‹œ๋ฎฌ๋ ˆ์ด์…˜ (14๊ฐœ ๋„๊ตฌ, iam-mcp) โœ… live
container EKS, ECS, Istio, Kubernetes โœ… live
data DynamoDB, RDS/Aurora, ElastiCache, MSK, OpenSearch โœ… live
cost Cost Explorer, forecast, budgets, ์ปจํ…Œ์ด๋„ˆ ๋น„์šฉ โœ… live
monitoring CloudWatch, CloudTrail โœ… live
iac CloudFormation, CDK, Terraform โœ… live
ops Aurora ๊ธฐ๋ฐ˜ ์ธ๋ฒคํ† ๋ฆฌ/ํ† ํด๋กœ์ง€ ์กฐํšŒ + AWS ๋ฌธ์„œ/CLI ์ œ์•ˆ(๋ผ์ด๋ธŒ Steampipe ์—†์Œ) โœ… live
external-obs ์™ธ๋ถ€ ์˜ต์ €๋ฒ„๋นŒ๋ฆฌํ‹ฐ & ์—ฐ๋™(Prometheus, ClickHouse, Notion) โœ… live

9๊ฐœ ํ–‰ ๋ชจ๋‘ agentcore_enabled/integrations_enabled ๋’ค์— ๊ฒŒ์ดํŠธ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค(์ƒˆ๋กœ ํด๋ก ยท๋ฐฐํฌ ์‹œ ๊ธฐ๋ณธ๊ฐ’์€ false โ€” plan = No changes, $0). ์—ฌ๊ธฐ์„œ "live"๋Š” ์ด ํ”„๋กœ์ ํŠธ์˜ ์‹ค์ œ ์šด์˜ ๋ฐฐํฌ ๊ธฐ์ค€์ด๋ฉฐ, ๊ทธ ๋ฐฐํฌ๋Š” ๋‘ ํ”Œ๋ž˜๊ทธ ๋ชจ๋‘ ์ผœ์ ธ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋ธ: Claude Sonnet 5(๊ธฐ๋ณธ), Opus 4.8(์‹ฌ์ธต ๋ถ„์„), Haiku 4.5(๋น ๋ฅด๊ณ  ์ €๋ ด).

์‚ฌ์ „ ์š”๊ตฌ ์‚ฌํ•ญ

  • Terraform >= 1.15 (S3 native state locking, use_lockfile)
  • Node.js >= 18 (๊ตฌ์„ฑ TUI, ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์Šคํฌ๋ฆฝํŠธ)
  • Docker with buildx (arm64 ์ด๋ฏธ์ง€ ๋นŒ๋“œ)
  • ๋Œ€์ƒ ๊ณ„์ • ์ž๊ฒฉ ์ฆ๋ช…์ด ์„ค์ •๋œ AWS CLI
  • EKS ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ์˜จ๋ณด๋”ฉํ•œ๋‹ค๋ฉด kubectl ๋ฐ kubeconfig

์„ค์น˜ ๋ฐฉ๋ฒ•

# ์ €์žฅ์†Œ ๋ณต์ œ
git clone https://github.com/Atom-oh/awsops.git
cd awsops

# ๋Œ€ํ™”ํ˜• TUI: VPC/๋„๋ฉ”์ธ/๋ฒ„ํ‚ท/EKS ํด๋Ÿฌ์Šคํ„ฐ ์„ ํƒ
make configure          # -> terraform.tfvars + backend.hcl

# foundation ์Šคํƒ ํ”„๋กœ๋น„์ €๋‹
terraform -chdir=terraform/foundation init -backend-config=backend.hcl
terraform -chdir=terraform/foundation plan -out tfplan
terraform -chdir=terraform/foundation apply tfplan

# Aurora ์‚ฌ์„ค ์—ฐ๊ฒฐ์ด ๊ฐ€๋Šฅํ•œ ์Šน์ธ๋œ ํ˜ธ์ŠคํŠธ์—์„œ ์ƒˆ ๋นˆ DB์— ํ•œํ•ด์„œ๋งŒ:
INITIALIZE_EMPTY_DB=1 make migrate
# ๊ธฐ์กด ์›์žฅ์ด ์žˆ์œผ๋ฉด make migrate; INTEGER ์›์žฅ์€ ๋ณ„๋„ BOOTSTRAP gate ํ•„์š”.
# runtime ์ด๋ฏธ์ง€/env/IAM/TLS/๋ณต๊ตฌ: terraform/foundation/migrations/README.md

# web ๋นŒ๋“œ+ํ‘ธ์‹œ, ECS ๋กค๋ง, /api/health ๋Œ€๊ธฐ (migrate ์žฌ์‹คํ–‰, ์‹คํŒจ ์‹œ deploy ์ค‘๋‹จ)
make deploy

# ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ดํ›„ agent ์ด๋ฏธ์ง€ ๋นŒ๋“œ+ํ‘ธ์‹œ, ๋ฉฑ๋“ฑ provisioner ์‹คํ–‰.
# make agentcore๋Š” reader ๋กค ์ƒ์„ฑ/๋น„๋ฐ€๋ฒˆํ˜ธ ๋™๊ธฐํ™”๋ฅผ ํ•˜์ง€ ์•Š๋Š”๋‹ค.
# docs/runbooks/agent-sql-reader.md ์ฐธ์กฐ.
make agentcore

# workers_enabled=true๋กœ apply ์ดํ›„: worker ์ด๋ฏธ์ง€ ๋นŒ๋“œ+ํ‘ธ์‹œ
make workers

์‚ฌ์šฉ๋ฒ•

make help               # ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ „์ฒด ํƒ€๊ฒŸ ๋ชฉ๋ก
make migrate-status     # ์˜คํ”„๋ผ์ธ: ์•ฑ ๋ฒ„์ „ + ๋””์Šคํฌ์— ์žˆ๋Š” ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜๋ณ„ release
make backfill-owner-sub # legacy email-keyed requested_by -> Cognito sub ์žฌ์ž‘์„ฑ '๊ณ„ํš'๋งŒ ์ƒ์„ฑ(๋ณ€๊ฒฝ ์—†์Œ).
                        # ๊ณ„ํš์„ ๊ฒ€ํ† ํ•ด ํ™•์‹  ๋ชป ํ•˜๋Š” ํ•ญ๋ชฉ์„ ์ง€์šด ๋’ค
                        # `node scripts/v2/backfill-owner-sub.mjs --apply <plan.json>`.
                        # apply ์ „์— schedule dispatcher ๋ฅผ ์ •์ง€ํ•œ๋‹ค(๋ช…๋ น์€ plan ์ถœ๋ ฅ์— ์žˆ์Œ).
                        # ADR-009 ์†Œ์œ ๊ถŒ Amendment 2๋‹จ๊ณ„; 3๋‹จ๊ณ„๋Š” legacy_email_owner_match=false.
DRY_RUN=1 make migrate  # DB ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ ์šฉ ์ „ ๋ฏธ๋ฆฌ๋ณด๊ธฐ
make upgrade             # ์•ˆ์ „ํ•œ ๋ฆด๋ฆฌ์Šค ์—…๊ทธ๋ ˆ์ด๋“œ: RDS ์Šค๋ƒ…์ƒท -> migrate -> deploy

ํ™˜๊ฒฝ ์„ค์ •

๋Ÿฐํƒ€์ž„ ์„ค์ •์€ Terraform foundation ๋ฃจํŠธ์—์„œ flag-gated(variables.tf, ai.tf, ci-migrations.tf)์ž…๋‹ˆ๋‹ค. ์•„๋ž˜ ํ‘œ์˜ feature gate ๋Š” ๋ชจ๋‘ ๊ธฐ๋ณธ๊ฐ’ false๋ผ ์ƒˆ ๊ณ„ํš์—์„œ ํ•ด๋‹น ๋ฆฌ์†Œ์Šค๋ฅผ ์ƒ์„ฑํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋‹ค๋งŒ ์˜๋„์ ์œผ๋กœ ๊ทธ๋ ‡์ง€ ์•Š์€ ์šด์˜ ์Šค์œ„์น˜๊ฐ€ ๋„ท ์žˆ์Šต๋‹ˆ๋‹ค: legacy_email_owner_match(๊ธฐ๋ณธ true โ€” legacy email-keyed ์†Œ์œ ๊ถŒ ๋งค์นญ์„ matchesIdentity() ๋ฅผ ๊ฑฐ์น˜๋Š” ๋ชจ๋“  ๊ฒŒ์ดํŠธ์—์„œ ๊ณ„์† ์ˆ˜์šฉํ•ฉ๋‹ˆ๋‹ค โ€” ์ฝ๊ธฐ๋ฟ ์•„๋‹ˆ๋ผ canMutateReport()(๋ฆฌํฌํŠธ PATCH/DELETE)๋„ ํฌํ•จ์ž…๋‹ˆ๋‹ค. make backfill-owner-sub ๋Š” ๊ณ„ํš๋งŒ ๋งŒ๋“ค๋ฏ€๋กœ ์žฌ์ž‘์„ฑ์ด ๋‚จ์€ ์ƒํƒœ์˜ clean plan ๋งŒ์œผ๋กœ๋Š” ๋ถ€์กฑํ•ฉ๋‹ˆ๋‹ค โ€” --apply ๊ฐ€ ์„ฑ๊ณตํ•˜๊ณ  ์ž”์—ฌ legacy row ๊ฐ€ 0 ์ธ ๊ฒƒ์„ ํ™•์ธํ•œ ๋’ค(๋˜๋Š” ์• ์ดˆ์— legacy ํ–‰์ด ์—†์–ด plan ์ด zero-row ์ธ ๊ฒฝ์šฐ)์—๋งŒ false ๋กœ ๋‚ด๋ฆฌ์„ธ์š”. ADR-009 ์†Œ์œ ๊ถŒ Amendment ์ฐธ์กฐ)์™€, ๊ธฐ์กด๋ถ€ํ„ฐ ์žˆ๋˜ create_network / allow_vpc_db_access, ๊ทธ๋ฆฌ๊ณ  publish_service_dns์ž…๋‹ˆ๋‹ค.

publish_service_dns๋Š” ๊ธฐ๋ณธ true์ด๋ฉฐ false๋Š” ์„œ๋น„์Šค A ๋ณ„์นญ์„ ์›ํ•˜๋Š” ๊ตฌ์„ฑ์—์„œ ์ œ์™ธํ•˜์ง€๋งŒ ์ธ์ฆ์„œ ๊ฒ€์ฆ CNAME๊นŒ์ง€ ๊ธˆ์ง€ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. existing_cf_certificate_arn / existing_alb_certificate_arn์€ ๊ธฐ๋ณธ null(Terraform ๊ด€๋ฆฌ ์ธ์ฆ์„œ)์ž…๋‹ˆ๋‹ค. ์™ธ๋ถ€ ์ธ์ฆ์„œ๋Š” ์ด๋ฏธ ๋ฐœ๊ธ‰๋˜๊ณ  ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•˜๋ฉฐ CloudFront์šฉ์€ us-east-1, ALB์šฉ์€ ์Šคํƒ ๋ฆฌ์ „์— ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. DNS ๊ธˆ์ง€ ๋ฐฐํฌ๋Š” ๋ช…์‹œ์  dispatch์—์„œ ๊ธฐ์กด ๊ด€๋ฆฌ ์ธ์ฆ์„œ ์†Œ์œ ๊ถŒ๊ณผ ์„œ๋น„์Šค ๋ณ„์นญ์„ ๋ณด์กดํ•ฉ๋‹ˆ๋‹ค. ์™ธ๋ถ€ ์ธ์ฆ์„œ๋Š” ์šด์˜์ž๊ฐ€ ARN์„ ์ง€์ •ํ•˜๊ฑฐ๋‚˜ ์ด๋ฏธ ์—ฐ๊ฒฐ๋œ ์™ธ๋ถ€ ์ธ์ฆ์„œ๋งŒ ์žฌ์‚ฌ์šฉํ•˜๋ฉฐ ๊ณ„์ • ์ „์ฒด ๊ฒ€์ƒ‰์€ ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ณ„๋„ dispatch ์ž…๋ ฅ์ธ allow_dns_changes๋Š” ๊ธฐ๋ณธ false๋กœ ์‚ฌ์„ค Cloud Map DNS๋„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค. DNS๋ฅผ ํ—ˆ์šฉํ•ด๋„ ์ผ๋ฐ˜ CI์—์„œ ๊ด€๋ฆฌ ์ธ์ฆ์„œ๋ฅผ ์™ธ๋ถ€ํ™”ํ•˜๊ฑฐ๋‚˜ ๊ฒ€์ฆ CNAME์„ ์‚ญ์ œยท๊ต์ฒดํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. PR/push ๊ณ„ํš์€ ์ฐธ๊ณ ์šฉ์ด๋ฉฐ ์ ์šฉํ•  ์ˆ˜ ์—†๊ณ  dev๋Š” ์‹ค์‹œ๊ฐ„ ์ธ์ฆ์„œ/SAN ๊ฒ€์ฆ ์—†์ด ์ƒํƒœ ์†Œ์œ ๊ถŒ์„ ๋ณด์กดํ•ฉ๋‹ˆ๋‹ค. dev ์ €์žฅ์†Œ ์ด๋ฆ„/์กด ๋ณ€์ˆ˜์™€ CERTIFICATE_MODE_DEV=preserve|managed๋Š” console๊ณผ plan์— ์ผ๊ด€๋˜๊ฒŒ ๋ฐ˜์˜๋ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  dev/full ๋„๋ฉ”์ธ ๋‹จ๊ณ„ plan์˜ domain_rollout=true๋Š” ์ €์žฅ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋กœ DNS ๋ฒ”์œ„๋ฅผ ์ œํ•œํ•˜๋ฉฐ apply์—์„œ ๋ฐ”๊ฟ€ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ false์ธ ์ผ๋ฐ˜ full ๊ณ„ํš๋„ DNS ๋ณ€๊ฒฝ์—๋Š” ๋ช…์‹œ์  ์Šน์ธ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋ฏธ๊ฒŒ์‹œ/๋™์ผ ๋„๋ฉ”์ธ ์ „ํ™˜ ๋Ÿฐ๋ถ, ์—ฃ์ง€ ์ฐธ์กฐ์™€ ๋ฐฐํฌ ๋Ÿฐ๋ถ ยง5๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Flag ๊ฒŒ์ดํŠธ ๋Œ€์ƒ
agentcore_enabled AgentCore Lambda ์Šฌ๋ผ์ด์Šค 21๊ฐœ
ci_readiness_enabled ๊ธฐ๋ณธ ๋น„ํ™œ์„ฑ ์œ ๋ฃŒ ๋ฐฐํฌ ๊ฒ€์ฆ. ์ „์šฉ CI_READINESS_ENABLED_DEV=true/false๊ฐ€ dev ๊ฐ’์„ ๋ฎ์–ด์“ฐ๋ฉฐ ๋ฏธ์„ค์ •์€ ๋ช…์‹œ์  tfvarsยท๊ธฐ๋ณธ false๋ฅผ ์œ ์ง€ํ•œ๋‹ค. ๋Ÿฐํƒ€์ž„ ํ”„๋กœํ•„๋งŒ์œผ๋กœ ํ™œ์„ฑํ™”ํ•˜์ง€ ์•Š๋Š”๋‹ค. ํ•„์ˆ˜ dev Deploy Web ๊ฒ€์ฆ ์ „์— steampipe_enabled=true, agentcore_enabled=true, workers_enabled=true์™€ readiness๋ฅผ ์ ์šฉํ•˜๊ณ  ์ˆ˜์ง‘ยท์›Œ์ปค ์ด๋ฏธ์ง€๋ฅผ ๋ฐฐํฌํ•˜๋ฉฐ dispatch ํ™œ์„ฑ ์ƒํƒœ๋ฅผ ํ™•์ธํ•œ ๋’ค AgentCore๋ฅผ ํ”„๋กœ๋น„์ €๋‹ํ•ด์•ผ ํ•œ๋‹ค. ๋Ÿฐํƒ€์ž„ ํ™œ์„ฑํ™” ์ ˆ์ฐจ๋ฅผ ๋”ฐ๋ฅธ๋‹ค. ๋ชจ๋“  ํ˜„์žฌ ์นดํƒˆ๋กœ๊ทธ ํƒ€์ž…์˜ ๊ธฐ์ค€ ์‹œ๊ฐ ์ดํ›„ ์„ฑ๊ณตยทํ™•์ธ๋œ ๊ฐœ์ˆ˜ยท๋ฏธํ™•์ธ ์†์„ฑ 0๊ฐœ์™€ ๋Ÿฐํƒ€์ž„ยท์›Œ์ปค ์ฆ๊ฑฐ๋ฅผ ์š”๊ตฌํ•˜๋ฉฐ health ๊ฒ€์‚ฌ๋งŒ์œผ๋กœ ์šฐํšŒํ•˜์ง€ ์•Š๋Š”๋‹ค. ๊ณต๊ฐœ CI์—์„œ๋Š” dev๋งŒ ํ—ˆ์šฉํ•œ๋‹ค. ์ ์šฉ ์‹œ verifier ๊ทธ๋ฃน์—๋Š” AgentCore๊ฐ€, ๊ด€๋ฆฌ demo ๋ฉค๋ฒ„์‹ญ์—๋Š” create_demo_user=true๋„ ํ•„์š”ํ•˜๋‹ค. ํ™œ์„ฑํ™”๋œ ๊ฐ dev ๋ฐฐํฌ๋Š” ์ˆ˜์ง‘ยท์œ ๋ฃŒ ๋ชจ๋ธ ๊ฒ€์ฆยท์‹ค์ œ ์›Œ์ปค ์ž‘์—… ๋‘ ๊ฐœ๋ฅผ ์‹คํ–‰ํ•œ๋‹ค. ๊ด€๋ฆฌ์žยทIAM ๊ถŒํ•œ์€ ๋ถ€์—ฌํ•˜์ง€ ์•Š๋Š”๋‹ค.
integrations_enabled ๋‚˜๋จธ์ง€ AgentCore Lambda ์Šฌ๋ผ์ด์Šค 6๊ฐœ
workers_enabled ๋น„๋™๊ธฐ ์›Œ์ปค ๊ณ„์ธต(SQS/SFN/Lambda/Fargate)
ci_migrations_enabled ๊ธฐ๋ณธ ๋น„ํ™œ์„ฑ ์šด์˜ ๊ธฐ๋Šฅ: ์‚ฌ์„ค migration ํƒœ์Šคํฌ ํ…œํ”Œ๋ฆฟยท์ •ํ™•ํ•œ ์‹œํฌ๋ฆฟ ์ฝ๊ธฐ ์—ญํ• /์ •์ฑ…ยท14์ผ ๋กœ๊ทธ. dev ์ˆ˜๋™ ์‹คํ–‰ ๋˜๋Š” ํ˜„์žฌ ์†Œ์Šค Deploy Web์˜ ๋ณดํ˜ธ๋œ migration ๊ฒฝ๋กœ์—์„œ ์‚ฌ์šฉํ•˜๋ฉฐ ์„œ๋น„์Šคยท์Šค์ผ€์ค„๋Ÿฌ๋Š” ์—†๋‹ค. ๋น„ํ™œ์„ฑํ™”ํ•˜๋ฉด ๋กœ๊ทธ ๊ทธ๋ฃน/์ด๋ ฅ์ด ์‚ญ์ œ๋œ๋‹ค.
steampipe_enabled Steampipe ์ธ๋ฒคํ† ๋ฆฌ sync ๋ฐ์ดํ„ฐ ๊ณ„์ธต
inventory_host_only ๊ธฐ๋ณธ ๋น„ํ™œ์„ฑ: ํ™œ์„ฑ ํ˜ธ์ŠคํŠธ ํ•˜๋‚˜๋งŒ ํ—ˆ์šฉํ•˜๊ณ  ์ˆ˜์ง‘๊ธฐ AssumeRole์„ ์ œ์™ธํ•ฉ๋‹ˆ๋‹ค. Agent MCP ๊ถŒํ•œ์€ ์œ ์ง€ํ•˜๋ฉฐ dev ํ™œ์„ฑํ™”์—๋Š” ํ”„๋กœํ•„ ๊ธฐ๋ฐ˜ ํ˜ธ์ŠคํŠธ ๊ฒ€์ฆ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋Ÿฐํƒ€์ž„ ์ ˆ์ฐจ์™€ ADR-011 ์ฐธ๊ณ .
finops_baseline_enabled FinOps ๊ธฐ๋ณธ ๊ถŒ์žฅ ์—”์ง„(ADR-020): ์ผ๋ณ„ Fargate ๋ฃฐ ๋ฐฐ์น˜(๋ฏธ์‚ฌ์šฉ EBS ๋ณผ๋ฅจ; Compute Optimizer ๊ธฐ๋ฐ˜ EC2/RDS rightsizing)๊ฐ€ finops_findings์— ์ ์žฌ, read-only, /cost์— ๋ Œ๋”. terraform ๋ ˆ๋ฒจ๋กœ๋Š” workers_enabled๋งŒ ์„ ํ–‰ โ€” ๋‹จ EBS ๋ฃฐ์€ ๋Ÿฐํƒ€์ž„์— steampipe_enabled=true์˜ ์ตœ์‹  ๋™๊ธฐํ™”๊ฐ€ ์žˆ์–ด์•ผ ๋™์ž‘ํ•˜๊ณ , ์—†์œผ๋ฉด ๊ทธ ๋ฃฐ๋งŒ ์ •์งํ•˜๊ฒŒ partial๋กœ ํ‘œ๋ฉดํ™”(EC2/RDS๋Š” ๋ฌด๊ด€ํ•˜๊ฒŒ ๋™์ž‘)
official_mcp_enabled ADR-017 ํ๋ ˆ์ด์…˜ ๊ณต์‹ ๋ฒค๋” MCP ํ”„๋ฆฌ์…‹ โ€” ๋ฒค๋” ํ˜ธ์ŠคํŒ… 3์ข…(DatadogยทDynatraceยทNew Relic)์„ external-obs mcpServer target์œผ๋กœ ๋“ฑ๋ก. (๋Ÿฐํƒ€์ž„ fail-closed ํˆด allowlist๋Š” ์ด ํ”Œ๋ž˜๊ทธ์™€ ๋ฌด๊ด€ํ•˜๊ฒŒ ๋งค provisioner run์— ๊ธฐ๋กยท๋ฌด์กฐ๊ฑด ๊ฐ•์ œ๋œ๋‹ค โ€” ๊ทธ ๋ฌด์กฐ๊ฑด์„ฑ์ด fail-closed์˜ ๋ณธ์ฒด) ์šด์˜ ์ฃผ์˜: Dynatrace๋Š” hosted ํˆด ๋ชฉ๋ก ์ „์‚ฌ ์ „๊นŒ์ง€ ์˜๋„์ ์œผ๋กœ ํˆด 0๊ฐœ; make agentcore๋Š” ๋Ÿฐํƒ€์ž„ READY๋ฅผ ๋Œ€๊ธฐ(๊ธฐ๋ณธ 300s, AGENTCORE_RUNTIME_READY_TIMEOUT)ํ•˜๋ฉฐ ๋กค์•„์›ƒ ์‹คํŒจ/์ง€์—ฐ ์‹œ ์ž๊ฒฉ์„ ๊ฐ–์ถ˜ live target์„ ๋‹ค์Œ ์„ฑ๊ณต run๊นŒ์ง€ ์ผ์‹œ ํšŒ์ˆ˜ํ•œ๋‹ค
graph_querygen_enabled ClickHouse trace_spans ๊ทธ๋ž˜ํ”„ ์ฟผ๋ฆฌ 1๊ฑด์— ๋Œ€ํ•œ LLM ํด๋ฐฑ (ADR-018). diag-signal ๊ฒฝ๋กœ์˜ ์‹๋ณ„์ž ์ •ํ™”ยท๊ด€๋ จ์„ฑ ๊ฒŒ์ดํŠธยท์ฃผ๊ฐ„ ์˜ˆ์‚ฐยท์ฝ๊ธฐ ๊ฒŒ์ดํŠธ๋Š” ์—†๋‹ค โ€” ADR-018 ยงC
diag_signal_querygen_enabled Explore diag-signal ์นฉ 1๊ฐœ์˜ LLM ํด๋ฐฑ โ€” ๊ทธ kind์˜ ๊ฒฐ์ •๋ก  ์นดํƒˆ๋กœ๊ทธ๊ฐ€ ready 0ํ–‰์ผ ๋•Œ๋งŒ ๋ฐœ๋™(๋ถ€๋ถ„ ๋งค์นญ์€ ๋ณด์ถฉํ•˜์ง€ ์•Š์Œ), ์ƒ์„ฑ ํ–‰์€ ์นฉ ์ „์šฉ(์ง„๋‹จ ๋ฆฌํฌํŠธ ๋ฏธ์‚ฌ์šฉ, ํ”Œ๋ž˜๊ทธ OFF ๋ฉด ์ฝ๊ธฐ์—์„œ๋„ ์ œ์™ธ). graph_querygen_enabled์™€ ๋ณ„๊ฐœ, ๋‘˜ ๋‹ค datasource_diagnosis_enabled ์„ ํ–‰. graph_querygen_enabled๋Š” ์ถ”๊ฐ€๋กœ agentcore_enabled๋„ ์„ ํ–‰(Code Interpreter ์„ธ์…˜ IAM ํ”„๋กœ๋น„์ €๋‹ ๋•Œ๋ฌธ)
sg_rule_activity_enabled SG Rules Athena ๊ธฐ๋ฐ˜ ํŠธ๋ž˜ํ”ฝ ๊ทผ๊ฑฐ ํŒŒ์ดํ”„๋ผ์ธ(/network/security-groups/rules) โ€” Athena/Glue ๋ธŒ๋กœ์ปค Lambda, ์ผ์ผ sg_rule_scan ์›Œ์ปค job, ๊ด€๋ จ Terraform(sg-rules.tf)
network_path_check_enabled Network Path Check ํŽ˜์ด์ง€/์›Œ์ปค(network-path.tf) โ€” fetch_live_topology()๋Š” ์ด์ œ ์‹ค์ œ ๊ตฌํ˜„์ด๋‹ค(์บ์‹œ๋œ Aurora ํ† ํด๋กœ์ง€ ๊ธฐ๋ฐ˜), ๋‹ค๋งŒ run ์‹œ์ ์˜ ์‹ค์‹œ๊ฐ„ AWS/Kubernetes ์žฌ์กฐํšŒ๋Š” ์—ฌ์ „ํžˆ ์˜๋„์ ์œผ๋กœ ๋ฏธ๊ตฌํ˜„์ด๋ผ ์ด ํ”Œ๋ž˜๊ทธ๊ฐ€ ์ผœ์ ธ ์žˆ์–ด๋„ POST .../runs๋Š” ์—ฌ์ „ํžˆ 503 unimplemented๋ฅผ ๋ฐ˜ํ™˜ํ•œ๋‹ค; Network Path Check CHANGELOG ํ•ญ๋ชฉ ์ฐธ๊ณ . pod/node ์†Œ์Šค์˜ live identity ํ™•์ธ์—๋Š” EKS Access Entry๊ฐ€ ์ถ”๊ฐ€๋กœ ํ•„์š”ํ•˜๋‹ค โ€” ์†Œ์Šค ๊ณ„์ •์ด ํ˜ธ์ŠคํŠธ ๊ณ„์ •์ด๋ฉด ์›Œ์ปค task role์šฉ(์ด ๊ฒฝ์šฐ _default_k8s_get()์ด ๊ทธ role ์ž์‹ ์˜ ์ž๊ฒฉ์ฆ๋ช…์„ ์ง์ ‘ ์‚ฌ์šฉ), ๋ฉค๋ฒ„ ๊ณ„์ •์ด๋ฉด ๋Œ€์ƒ ๊ณ„์ •์˜ **AWSopsReadOnlyRole**์šฉ(๊ทธ assume๋œ ์„ธ์…˜์œผ๋กœ K8s GET์„ ์ธ์ฆํ•˜๋ฏ€๋กœ, ์›Œ์ปค task role์„ ๋“ฑ๋กํ•ด๋„ ์•„๋ฌด ํšจ๊ณผ๊ฐ€ ์—†๊ณ  ๋ชจ๋“  GET์ด 403๋œ๋‹ค) โ€” docs/runbooks/network-path-eks-access.md + scripts/v2/eks/register-network-path-access.sh(๋ฉค๋ฒ„ ๊ณ„์ •์˜ ๊ฒฝ์šฐ ROLE_ARN=...๋กœ principal ์˜ค๋ฒ„๋ผ์ด๋“œ) ์ฐธ๊ณ 

๋Ÿฐํƒ€์ž„ IAM ์ถ•์†Œ๋Š” ์œ„ ์„ ํƒ ํ”Œ๋ž˜๊ทธ์™€ ๋ฌด๊ด€ํ•˜๋ฉฐ main ๋“ฑ ๊ธฐ์กด ํ™œ์„ฑ ์Šคํƒ์˜ ๋‹ค์Œ apply์— ์ ์šฉ๋ฉ๋‹ˆ๋‹ค(์›น SSM ์„ธ ํŒŒ๋ผ๋ฏธํ„ฐยท๋Ÿฐํƒ€์ž„ ์กฐํšŒ/ํ† ํฐ ๋™์ž‘ยท์ž์ฒด ํด๋Ÿฌ์Šคํ„ฐ ํƒœ์Šคํฌ ์ œ์–ดยทClaude ๋ชจ๋ธ). ์•Œ๋ ค์ง„ ๋ฆฌ์ „์—๋Š” ์ดํ›„ opt-in ๋ฆฌ์ „๋„ ํฌํ•จ๋˜๋ฉฐ ์‹ค์ œ ์ ‘๊ทผ ์„ฑ๊ณต์˜ ์ฆ๊ฑฐ๋Š” ์•„๋‹™๋‹ˆ๋‹ค.

ADR-017์—๋Š” terraform flag๊ฐ€ ์•„๋‹Œ ๊ฒŒ์ดํŠธ๊ฐ€ ํ•˜๋‚˜ ๋” ์žˆ์Šต๋‹ˆ๋‹ค: CLICKHOUSE_OFFICIAL_MCP โ€” provisioner๊ฐ€ ๊ธฐ๋กํ•˜๋Š” AgentCore ๋Ÿฐํƒ€์ž„ env(CLICKHOUSE_OFFICIAL_MCP=true make agentcore)๋กœ, ๊ณต์‹ mcp-clickhouse๋ฅผ ๋Ÿฐํƒ€์ž„ ์ปจํ…Œ์ด๋„ˆ์— stdio ์„œ๋ธŒํ”„๋กœ์„ธ์Šค๋กœ ๋‚ด์žฅํ•ฉ๋‹ˆ๋‹ค. FROZEN / do-not-enable์ž…๋‹ˆ๋‹ค: ์ž์ฒด ๋žŒ๋‹ค์˜ ํ…Œ์ด๋ธ” ํ•จ์ˆ˜ SSRF ๊ฐ€๋“œ์— ๋Œ€์‘ํ•˜๋Š” ๋ฐฉ์–ด๊ฐ€ stdio ๊ฒฝ๋กœ์— ์—†์–ด, ํ•ด์ œ์—๋Š” ๊ธฐ์ˆ  ์„ ๊ฒฐ์กฐ๊ฑด๊ณผ ์ƒˆ ADR + ๋ฉ€ํ‹ฐ-AI ํŒจ๋„ + ๋‚ ์งœ๋ฐ•ํžŒ owner-override๊ฐ€ ๋ชจ๋‘ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค(ADR-017 ยงStatus, BASELINE ยง2).

ADR-017์€ ํ”„๋ฆฌ์…‹๋ณ„ ์„ค์ •์šฉ ๋งต ๋ณ€์ˆ˜ 2๊ฐœ(๋ถˆ๋ฆฌ์–ธ ์•„๋‹˜, ๋‘˜ ๋‹ค ๊ธฐ๋ณธ {})๋ฅผ ํ•จ๊ป˜ ์”๋‹ˆ๋‹ค โ€” official_mcp_endpoints(map(string), preset_key -> https:// ์—”๋“œํฌ์ธํŠธ)์™€ official_mcp_read_only_ack(map(string), preset_key -> ์šด์˜์ž๊ฐ€ ๊ฒ€ํ† ํ•œ ์—”๋“œํฌ์ธํŠธ URL ๊ทธ๋Œ€๋กœ. true๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค). ack ๊ฐ’์ด ํ˜„์žฌ ์—”๋“œํฌ์ธํŠธ์™€ ์ •ํ™•ํžˆ ๊ฐ™์„ ๋•Œ๋งŒ provisioning๋˜๊ณ , ๊ทธ ๋ฐ–์˜ ๋ชจ๋“  ๊ฒฝ์šฐ๋Š” fail-closed SKIP(๊ธฐ์กด target ํšŒ์ˆ˜)์ž…๋‹ˆ๋‹ค:

official_mcp_endpoints     = { datadog = "https://mcp.datadoghq.com/v1/mcp" }
official_mcp_read_only_ack = { datadog = "https://mcp.datadoghq.com/v1/mcp" }

AgentCore ์ž์ฒด ์„ค์ •(runtime ARN, Memory ID, Code Interpreter ID)์€ provisioner๊ฐ€ SSM(/ops/awsops-v2/agentcore/*)์— ๊ธฐ๋กํ•˜๊ณ  web BFF๊ฐ€ ๋Ÿฐํƒ€์ž„์— ์ฝ์Šต๋‹ˆ๋‹ค โ€” ์‹œ์ž‘ ์‹œ ๋ ˆ์ด์Šค๋ฅผ ํ”ผํ•˜๊ธฐ ์œ„ํ•ด task-def valueFrom์œผ๋กœ๋Š” ์ ˆ๋Œ€ ์ „๋‹ฌํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

ํ”„๋กœ์ ํŠธ ๊ตฌ์กฐ

awsops/
  web/                      # Next.js 15 thin-BFF: 41 ํŽ˜์ด์ง€, 99 API ๋ผ์šฐํŠธ, 110 ์ปดํฌ๋„ŒํŠธ
  agent/                    # Strands Agent(Runtime ์†Œ์Šค) + MCP Lambda ๋„๊ตฌ ์†Œ์Šค
  terraform/foundation/  # ๋‹จ์ผ Terraform ๋ฃจํŠธ: network, edge, auth, data, workload, ai, workers, eks
  scripts/v2/               # configure/deploy/migrate/agentcore/workers ๋„๊ตฌ(์ „๋ถ€ Node.js/Python)
  tests/                    # repo ์ „๋ฐ˜์˜ hook/structure ํ…Œ์ŠคํŠธ + PR-review/Steampipe/ExternalId ๋ฐฐ์„  ์ฒดํฌ
  docs/                     # ๊ฐ€์ด๋“œ, ๋Ÿฐ๋ถ, ๊ตฌํ˜„ ์ฐธ์กฐ ๋ฌธ์„œ(ADR ๋ณธ๋ฌธ์€ ๋น„๊ณต๊ฐœ upstream์—์„œ ๊ด€๋ฆฌ)
  docs-site/                # Docusaurus ์‚ฌ์šฉ์ž ๊ฐ€์ด๋“œ(๋ณ„๋„ ๋ฐฐํฌ)

ํ…Œ์ŠคํŠธ

๋จธ์ง€ ๊ฒ€์ฆ์˜ ์˜์กด์„ฑ์„ ๋จผ์ € ์„ค์น˜ํ•˜์„ธ์š”. Docker์™€ ์ค€๋น„๋œ AWSOPS_REVIEW_CODEC_STATE๋„ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ƒŒ๋“œ๋ฐ•์Šค ์ค€๋น„ ์ ˆ์ฐจ๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

tests/run-all.sh์˜ panel-prompt ๊ตฌ์กฐ ๊ฒ€์‚ฌ๋ฅผ ํฌํ•จํ•œ ์ด๋ฏธ์ง€ fixture์—๋Š” Linux ARM64/x86-64์˜ Python 3.12์™€ ํ•ด์‹œ๊ฐ€ ๊ณ ์ •๋œ Pillow๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ช…๋ น์„ ํ•ด์‹œ ์—†๋Š” requirements ์„ค์น˜์™€ ํ•ฉ์น˜์ง€ ๋ง๊ณ  ๋ณ„๋„๋กœ ์‹คํ–‰ํ•˜์„ธ์š”: python3 -m pip install --require-hashes --only-binary=:all: -r scripts/pr-review/image-requirements.txt. Private migration ํ…Œ์ŠคํŠธ๋Š” npm ci --prefix scripts/v2 --ignore-scripts --no-audit --no-fund๋กœ pgยทAWS SDK๋ฅผ ์„ค์น˜ํ•˜๋ฉฐ PostgreSQL ํ…Œ์ŠคํŠธ์—๋Š” OpenSSLยท์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ Dockerยทpostgres:17์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ํ•„์ˆ˜ migrationยท์›น ์—ฐ๊ฒฐ ๋‹จ๊ณ„ยท์—์ด์ „ํŠธ ๋„๊ตฌ ์ •์ฑ… ์ด๋ ฅ PostgreSQL ํ…Œ์ŠคํŠธ๋Š” ๋ ˆ๊ฑฐ์‹œ ์„ ํƒ์  itest์™€ ๋‹ฌ๋ฆฌ Docker ๋ถ€์žฌ ์‹œ gate๊ฐ€ ์‹คํŒจํ•˜๊ณ  PATH์˜ docker๋ฅผ ์ง์ ‘ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์›น ์—ฐ๊ฒฐยท์ •์ฑ… ํ…Œ์ŠคํŠธ๋Š” ์ž ๊ธด ๋“œ๋ผ์ด๋ฒ„์™€ TypeScript๋ฅผ ์œ„ํ•ด npm ci --prefix web๋„ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ด ํ…Œ์ŠคํŠธ๋“ค๊ณผ ์˜คํ”„๋ผ์ธ companion์€ AWS ์ž๊ฒฉ์ฆ๋ช…์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ธ์ฆ ๋ฐฐํฌ smoke ํ…Œ์ŠคํŠธ๋Š” curlยทOpenSSLยทPython 3ยทPyYAMLยทTerraform 1.15.7์„ ํ•„์ˆ˜๋กœ ์š”๊ตฌํ•˜๋ฉฐ, ๋ˆ„๋ฝ ์‹œ ๊ณตํ†ต ๋Ÿฌ๋„ˆ๋„ ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค. ์˜คํ”„๋ผ์ธ ๋ณ€์ˆ˜ fixture์—๋Š” provider๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋งˆ์ง€๋ง‰ fmt/validate ์ง„๋‹จ๋งŒ ์ฐธ๊ณ ์šฉ์ž…๋‹ˆ๋‹ค. Terraform mock ํ…Œ์ŠคํŠธ์—๋Š” 1.15.7๊ณผ ์„ค์น˜/์บ์‹œ๋œ provider๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋„์šฐ๋ฏธ๋Š” ์ถ”์ ๋œ ์ž‘์—… ํŒŒ์ผ๋งŒ ๋ณต์‚ฌํ•ด init -backend=false, validate, test๋ฅผ ์‹คํ–‰ํ•˜๋ฉฐ ์‹ค์ œ backend๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•„์ˆ˜ test_ci_web_read.pyยทtest_ci_web_deploy.py ํ…Œ์ŠคํŠธ๋Š” Python 3.12์™€ Linux /proc, POSIX ํ”„๋กœ์„ธ์Šค ๊ทธ๋ฃน, os.geteuid๊ฐ€ ํ•„์š”ํ•˜๋ฉฐ ์™ธ๋ถ€ provider๋ฅผ ๋ชจ์˜ํ•˜๋ฏ€๋กœ AWS CLIยทghยทcurlยทjq๋ฅผ ์‹คํ–‰ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•„์ˆ˜ test_ci_web_workflow.py ํ…Œ์ŠคํŠธ์—๋Š” PyYAML๊ณผ Bash๋„ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. Deploy Web์€ ์ปจํŠธ๋กค๋Ÿฌ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์›น ๋ฐฐํฌ๊ฐ€ ํ˜ธ์ถœํ•˜๋Š” ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜์— ์ž๋™ SQL ๊ฒ€์‚ฌ๋ฅผ ๊ฐ•์ œํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ docs/runbooks/release-safety-primitives.md๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”. ์˜คํ”„๋ผ์ธ ์›น ์ด๋ฏธ์ง€ ์ถœ์ฒ˜ ๊ฒ€์ฆ ๋„์šฐ๋ฏธ ํ…Œ์ŠคํŠธ์—๋Š” jq, Linux /proc, /usr/local/bin:/usr/bin:/bin์˜ curl๋„ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. Deploy Web์€ ์‚ฌ์„ค ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ „์— ์ด๋ฏธ์ง€๋ฅผ ๊ฒ€์ฆํ•˜๊ณ  ํ•ด๋‹น ๋‹ค์ด์ œ์ŠคํŠธ๋ฅผ ๋ณดํ˜ธ๋œ ์ง„์ž…์ ์œผ๋กœ ์Šน๊ฒฉํ•œ ๋’ค, ์ •ํ™•ํ•œ ECSยท์ด๋ฏธ์ง€์™€ ๋กœ๊ทธ์ธยทDB๋ฅผ ํฌํ•จํ•œ ์ „์ฒด dev ๋Ÿฐํƒ€์ž„ ๊ฒ€์ฆ์„ ํ•„์ˆ˜๋กœ ์ˆ˜ํ–‰ํ•˜๋ฉฐ ๊ฐ€์ด๋“œ์—์„œ ์˜์ˆ˜์ฆยท๋ณต๊ตฌ ๊ณ„์•ฝ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. ๋ฐฐํฌ ์•ˆ์ „ ๋„๊ตฌ์—์„œ ์ปจํŠธ๋กค๋Ÿฌ์™€ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ์ •์ฑ…์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ์›น ๋ฐฐํฌ์—์„œ ์ดˆ๊ธฐํ™”ยท์ž๋™ ๊ฒ€์‚ฌ ๋ฏธ์ง€์› SQL์˜ ์ˆ˜๋™ migration/reader ๋™๊ธฐํ™” ์„ฑ๊ณต ํ›„ ์ƒˆ ์›น ๋ฐฐํฌ๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ ˆ์ฐจ๋ฅผ, ๋ ˆ๊ฑฐ์‹œ ์ด๋ฏธ์ง€ ๋ณต๊ตฌ์—์„œ ์˜์ˆ˜์ฆ ์—†๋Š” ์ด๋ฏธ์ง€ ๋ณต๊ตฌ๋ฅผ ํ™•์ธํ•˜์„ธ์š”.

bash scripts/v2/merge-verify.sh   # ํ•„์ˆ˜ Pythonยท์›นยท๋ฐฐํฌ ํ…Œ์ŠคํŠธ
node --test scripts/v2/ci/*.test.mjs # private migration runtime ์˜คํ”„๋ผ์ธ fixture (CI ํ•„์ˆ˜)
node --test scripts/v2/ci/migration.itest.mjs scripts/v2/ci/web-db-connection.itest.mjs scripts/v2/ci/agent-tool-policy.itest.mjs # ์‹ค์ œ PG migrationยท์›น ์—ฐ๊ฒฐยท์—์ด์ „ํŠธ ์ •์ฑ… ํšŒ๊ท€ ํ…Œ์ŠคํŠธ (CI ํ•„์ˆ˜)
bash scripts/v2/terraform-test.sh # ๋ณ„๋„ ๋ณต์‚ฌ๋ณธยทbackend ๋น„ํ™œ์„ฑ Terraform mock ํ…Œ์ŠคํŠธ (CI ํ•„์ˆ˜)
# docs-site/ ๋˜๋Š” .github/workflows/merge-verify.yml ๋ณ€๊ฒฝ ์‹œ ์•„๋ž˜๋„ CI ํ•„์ˆ˜:
(cd docs-site && npm ci && npm run typecheck && npm run build &&
  bash scripts/verify-deck.sh static/presentation/awsops-intro/awsops-intro.pptx)
node --test scripts/v2/deployment-smoke.test.mjs # ์˜คํ”„๋ผ์ธ healthยท์ธ์ฆยท์ž๊ฒฉ์ฆ๋ช… ์ค€๋น„ยท์›Œํฌํ”Œ๋กœ ๊ฒ€์‚ฌ
bash tests/run-all.sh             # repo ์ „๋ฐ˜ hook/structure ํ…Œ์ŠคํŠธ + agent Python unittest
(cd web && npx vitest run)        # web ์œ ๋‹› ํ…Œ์ŠคํŠธ๋งŒ

์œ„ private migration fixture ๋ช…๋ น์€ runtimeยทcontrollerยทworkflowยท๋ชจ์˜ ๊ณ„ํš ๊ฒ€์‚ฌ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. controller/workflow ๊ฒ€์‚ฌ์—๋Š” Python 3ยทPyYAMLยทboto3/botocore (pip install -r agent/requirements.txt)ยทTerraform 1.15.7๋„ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์กฐ๊ฑด๋ถ€ ๋ฌธ์„œ ๋นŒ๋“œ์™€ ํ”„๋ ˆ์  ํ…Œ์ด์…˜ ์ „์ฒด ์•„์นด์ด๋ธŒ ๊ฒ€์ฆ์„ ํฌํ•จํ•œ CI ๋ฒ”์œ„๋Š” ๋จธ์ง€ ๊ฒ€์ฆ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

API ๋ฌธ์„œ

99๊ฐœ API ๋ผ์šฐํŠธ๊ฐ€ web/app/api/์— ์žˆ์Šต๋‹ˆ๋‹ค. ์ฃผ์š” ๋ผ์šฐํŠธ: health(๊ณต๊ฐœ), stream(SSE ์ฑ„ํŒ…), db(Aurora ping), jobs(+/[id], ๋น„๋™๊ธฐ ์ž‘์—… ์ œ์ถœ/์ƒํƒœ), security, compliance, auth/login. ์‚ฌ์šฉ์ž ๊ฐ€์ด๋“œ๋Š” docs site๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

๊ธฐ์—ฌ ๋ฐฉ๋ฒ•

  1. ์ €์žฅ์†Œ๋ฅผ Fork ํ•ฉ๋‹ˆ๋‹ค
  2. ๋ธŒ๋žœ์น˜๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค (git checkout -b feat/amazing-feature)
  3. ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ปค๋ฐ‹ํ•ฉ๋‹ˆ๋‹ค (git commit -m 'feat: add amazing feature')
  4. ๋ธŒ๋žœ์น˜์— Push ํ•ฉ๋‹ˆ๋‹ค (git push origin feat/amazing-feature)
  5. Pull Request๋ฅผ ์—ฝ๋‹ˆ๋‹ค

๋Œ€์ƒ ๋ธŒ๋žœ์น˜๋Š” dev์ž…๋‹ˆ๋‹ค. Fork ๊ธฐ์—ฌ๋Š” ์œ ์ง€๊ด€๋ฆฌ์ž๊ฐ€ ํŒจ์น˜๋ฅผ ํ™•์ธํ•œ ๋’ค ๋‚ด๋ถ€ PR๋กœ ๊ฐ€์ ธ์™€ ์ „์ฒด AIยทCI ๊ฒ€์‚ฌ๋ฅผ ๊ฑฐ์ณ ํ†ตํ•ฉํ•ฉ๋‹ˆ๋‹ค. Fork ํ…Œ์ŠคํŠธ ํ†ต๊ณผ๋งŒ์œผ๋กœ AI ๊ฒ€์‚ฌ๋ฅผ ๋Œ€์‹ ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ธฐ์—ฌ ๋ธŒ๋žœ์น˜ ํ๋ฆ„์„ ์ฐธ๊ณ ํ•˜์„ธ์š”.

๋ผ์ด์„ ์Šค

MIT License๋กœ ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ LICENSE๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

์—ฐ๋ฝ์ฒ˜

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages