Skip to content

Conversation

@gmarciani
Copy link
Contributor

@gmarciani gmarciani commented Jan 9, 2026

Description of changes

Prevent duplicate security group rules in shared storage security group.

The deduplication is needed because when duplicate rules are requested, the CFN handler responsible for their creation goes into a path that is more susceptible to eventual consistency issue.
When such issue occur, cluster creation fail.

Tests

SUCCEEDED integration tests:

  • test_fsx_lustre.py::test_multiple_fsx
  • test_fsx_lustre.py::test_fsx_lustre_dra
  • test_fsx_lustre.py::test_file_cache
  • test_efs.py::test_multiple_efs
  • test_internal_efs.py::test_internal_efs

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch 3 times, most recently from 6bf3fa5 to 1101295 Compare January 9, 2026 23:28
@gmarciani gmarciani changed the title [Networking] Prevent duplicate security group rules in shared storage security group [Networking] Prevent duplicate security group rules in shared storage security group + scope down SG rules for EFS and FSx Jan 12, 2026
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch 2 times, most recently from da9b12e to 87e066c Compare January 12, 2026 17:16
@gmarciani gmarciani marked this pull request as ready for review January 12, 2026 17:16
@gmarciani gmarciani requested review from a team as code owners January 12, 2026 17:16
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch from 87e066c to 6c5bbcb Compare January 12, 2026 18:19
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch from 6c5bbcb to 32f3dc0 Compare January 12, 2026 18:53
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch 3 times, most recently from 699565c to 683e857 Compare January 12, 2026 21:42
@gmarciani gmarciani changed the title [Networking] Prevent duplicate security group rules in shared storage security group + scope down SG rules for EFS and FSx [Networking] Prevent duplicate security group rules in shared storage security group Jan 12, 2026
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch 2 times, most recently from 6db4d39 to 99ab06b Compare January 12, 2026 22:19
… security group.

The deduplication is needed because when duplicate rules are requested,
the CFN handler responsible for their creation goes into a path
that is more susceptible to eventual consistency issue.
When such issue occur, cluster creation may fail.
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch from 99ab06b to 1c356ea Compare January 12, 2026 22:21
@gmarciani gmarciani merged commit 92c5b0b into aws:develop Jan 12, 2026
24 checks passed
@gmarciani gmarciani deleted the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch January 12, 2026 23:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants