Skip to content

PMM-15389 Assume an IAM role for AWS RDS monitoring - #5944

Merged
4nte merged 37 commits into
mainfrom
PMM-15389-assume-role
Oct 8, 2026
Merged

4nte merged 37 commits into
mainfrom
PMM-15389-assume-role

Conversation

@4nte

@4nte 4nte commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Adds the ability to assume an AWS IAM role for RDS monitoring: supply a role ARN instead of static access keys, including a role in a different AWS account. PMM assumes the role with its ambient credentials and refreshes them automatically.

Stacked on #5943 (the instance_id delivery-surface fix); base branch is PMM-15389-rds-inventory-cli.

Adopts the original contributor's feature (#5804, fergalhk - preserved as author on the adopt commit) and adds four fixes on top:

  • Gate role ARN on pmm-agent 3.4.0 (older agents cannot assume a role).
  • Bound and validate the STS assume-role call in discovery (7s timeout, partition check).
  • Make clearing a role ARN an explicit change (warn about falling back to ambient credentials).
  • Allow a role ARN when the pmm-agent version has not been reported yet.

Verified end-to-end on real AWS (assume-role proven via CloudTrail + aws_rds_* / rdsosmetrics_* metrics).

Related

AddRemoteRDSNodeParams had no instance_id field and
`pmm-admin inventory add node remote-rds` had no flag for it, so every
remote-RDS node created through the inventory path stored an empty
identifier. rds_exporter then received `instance: ""`, logged
"No scraper for <region>/, skipping." and collected nothing while the
agent reported AGENT_STATUS_RUNNING.

PMM-13157 split address from instance_id but wired the new field through
the management API only; the inventory API and CLI were never updated.

This adds instance_id to AddRemoteRDSNodeParams and to the CLI, and
refuses the broken state at source: an empty identifier is rejected at
node creation (InvalidArgument), and attaching an rds_exporter to a
remote_rds node that lacks one is rejected at agent creation
(FailedPrecondition), which also covers rows created before this fix.

The stale "DB instance identifier" comment on the address field is
corrected in both RemoteRDSNode and AddRemoteRDSNodeParams.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@codecov

codecov Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 73.45679% with 43 lines in your changes missing coverage. Please review.
✅ Project coverage is 53.35%. Comparing base (31318c7) to head (dfd9ae1).
⚠️ Report is 266 commits behind head on main.

Files with missing lines Patch % Lines
managed/models/node_helpers.go 8.69% 21 Missing ⚠️
managed/services/agents/state.go 53.84% 6 Missing ⚠️
managed/services/management/rds.go 89.79% 5 Missing ⚠️
managed/services/agents/roster.go 83.33% 4 Missing ⚠️
managed/models/agent_helpers.go 90.90% 2 Missing ⚠️
managed/services/inventory/agents.go 60.00% 2 Missing ⚠️
admin/commands/inventory/add_agent_rds_exporter.go 0.00% 1 Missing ⚠️
...in/commands/inventory/change_agent_rds_exporter.go 85.71% 1 Missing ⚠️
managed/services/converters.go 0.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #5944      +/-   ##
==========================================
+ Coverage   43.59%   53.35%   +9.75%     
==========================================
  Files         415      559     +144     
  Lines       43134    43417     +283     
  Branches        0      587     +587     
==========================================
+ Hits        18804    23163    +4359     
+ Misses      22454    20247    -2207     
+ Partials     1876        7    -1869     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@4nte
4nte marked this pull request as ready for review September 14, 2026 11:29
@4nte
4nte requested a review from a team as a code owner September 14, 2026 11:29
@4nte
4nte requested review from JiriCtvrtka and ademidoff and removed request for a team September 14, 2026 11:29
4nte and others added 8 commits September 14, 2026 14:09
The help text already said it was required, but Kong accepted an omitted
value and sent an empty identifier the server then rejected. Enforce it
at parse time (CodeRabbit review on #5943).

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Adopt the assumed-role implementation from #5804 (by Fergal
Kearns) onto current main, squashed into one commit. PMM can assume an
AWS IAM role using its own ambient credentials instead of long-lived
access keys, for both RDS discovery (on PMM Server) and rds_exporter
scraping (on the pmm-agent host).

Adds aws_role_arn across the RDS API surface, mutually exclusive with the
access/secret key; assumes the role once per partition during discovery;
groups rds_exporter processes by credential identity; and exposes
--aws-role-arn on the pmm-admin RDS commands. AWS SDK bumped to the
versions already on main, with service/sts promoted to a direct
dependency.

Docs are intentionally excluded; they land via #5838.
Known defects from the #5804 review are fixed in follow-up commits on
this branch.

Original PR: #5804

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Fixes two defects in the DiscoverRDS assume-role path found reviewing
#5804.

The STS AssumeRole call ran on the raw request context, before the
awsDiscoverTimeout region-scan deadline was applied, and the HTTP client
had no timeout of its own. A slow or unreachable STS endpoint could hang
DiscoverRDS for minutes. The assume now runs under its own
awsDiscoverTimeout deadline and the HTTP client carries a matching
per-request ceiling.

The role ARN's partition was never checked against settings.AWSPartitions.
A role in a partition PMM is not configured to scan could assume
successfully and then fail every scanned region, or return nothing with no
error. The partition is now rejected up front with FailedPrecondition,
before any network call. stsRegionForRoleARN returns the partition for this
check.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
A pmm-agent older than 3.4.0 bundles an rds_exporter that assumes an IAM
role from empty static credentials rather than the ambient chain, so the
sts:AssumeRole is never signed and the exporter dies with
EmptyStaticCreds. Before this, a current server accepted --aws-role-arn
for such an agent, returned success, and left the exporter failing with
no server-side signal.

CreateAgent and ChangeAgent now reject a role-based rds_exporter whose
pmm-agent is below PMMAgentMinVersionForAWSRoleARN (3.4.0-0), with
FailedPrecondition. Static-key exporters are unaffected. An agent with no
reported version is treated as unsupported, which is the safe default.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Clearing the role ARN (--aws-role-arn="") without also supplying keys
leaves the exporter with empty AWS options, so rds_exporter falls back to
the pmm-agent host's ambient credentials - often a broader identity than
the role the operator deliberately chose. This transition was silent: the
CLI printed only "cleared AWS role ARN".

Ambient credentials are a legitimate mode, so this is not rejected;
instead it is made explicit. The pmm-admin change command now states that
the exporter will use the host's ambient credentials when the ARN is
cleared without keys, the flag help spells out the mutual-exclusion and
clear semantics, and ChangeRDSExporter logs a Warn covering the API and
UI callers that do not see the CLI message.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
The 3.4.0 role-ARN gate rejects a role-based rds_exporter whose pmm-agent
reports no version. TestRoster/GetFallbackHandlesRoleARN creates one on the
built-in pmm-server agent, which the test fixtures seed without a version,
so the gate refused it. Give that agent a supported version in the test, as
any running 3.4.0+ server would report once the built-in agent connects.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
The pmm-agent 3.4.0 gate rejected a role ARN whenever IsAgentSupported
returned any error, which includes the 'no version info' case for a
pmm-agent that has not connected yet. Reject only AgentNotSupportedError
(a pmm-agent known to be too old); an unreported version no longer
blocks storing the config and the gate re-checks once the agent
connects. This is what the api-test TestRDSExporter/WithRoleARN and the
feature's own intent expect.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
(cherry picked from commit 1ebc19b)
Shorten the change-agent role-ARN help to satisfy lll, drop the named
returns on stsRegionForRoleARN, and remove a redundant .Querier selector
in the roster test (golangci-lint --fix).

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@4nte
4nte force-pushed the PMM-15389-assume-role branch from 42619c1 to 1520890 Compare September 14, 2026 12:10
@4nte

4nte commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 60b3bd2a-5a65-4d49-9cbc-43d3600a9797
📥 Commits

Reviewing files that changed from the base of the PR and between 8556cda and dec3a56.

⛔ Files ignored due to path filters (5)
  • api/descriptor.bin is excluded by !**/*.bin
  • api/inventory/v1/agents.pb.go is excluded by !**/*.pb.go
  • api/inventory/v1/nodes.pb.go is excluded by !**/*.pb.go
  • api/management/v1/agent.pb.go is excluded by !**/*.pb.go
  • api/management/v1/rds.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (2)
  • managed/models/agent_helpers.go
  • managed/services/agents/roster.go
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review.


Walkthrough

The change adds AWS IAM role ARN support to RDS exporter agents and RDS discovery. API contracts validate role ARNs and reject combinations with static AWS keys. Agent models derive credential identities and check PMM Agent version support. Discovery assumes roles through STS and scans the role’s partition. Remote RDS node creation accepts an instance identifier, normalizes it, and checks uniqueness by region. API responses, CLI commands, exporter configuration, and grouping carry the new AWS options.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant DiscoverRDS
  participant STS
  participant RDS
  Client->>DiscoverRDS: Submit role ARN
  DiscoverRDS->>STS: Assume role
  STS-->>DiscoverRDS: Return temporary credentials
  DiscoverRDS->>RDS: Scan role partition regions
  RDS-->>DiscoverRDS: Return discovery results
  DiscoverRDS-->>Client: Return results
Loading

Priority: ➖ Normal

Merge Risk: 🟡 Moderate · up to dec3a

Remote RDS nodes may retain identifiers that cannot match an instance, and concurrent creation may produce duplicate instance records. Resolve or explicitly accept those risks before merging.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: assuming an IAM role for AWS RDS monitoring.
Description check ✅ Passed The description explains the feature, key implementation details, verification, and related work. It omits the template’s Feature build field and does not state whether the API Docs checkbox applies o…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: de5c0115-40d4-4a09-b055-06f29df8adbb

📥 Commits

Reviewing files that changed from the base of the PR and between 8125f2c and 1520890.

⛔ Files ignored due to path filters (3)
  • api/inventory/v1/agents.pb.go is excluded by !**/*.pb.go
  • api/management/v1/agent.pb.go is excluded by !**/*.pb.go
  • api/management/v1/rds.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (40)
  • admin/commands/inventory/add_agent_rds_exporter.go
  • admin/commands/inventory/change_agent_rds_exporter.go
  • admin/commands/inventory/change_agent_rds_exporter_test.go
  • api-tests/inventory/agents_rds_exporter_test.go
  • api-tests/management/rds_test.go
  • api/inventory/v1/agents.pb.validate.go
  • api/inventory/v1/agents.proto
  • api/inventory/v1/json/client/agents_service/add_agent_responses.go
  • api/inventory/v1/json/client/agents_service/change_agent_responses.go
  • api/inventory/v1/json/client/agents_service/get_agent_responses.go
  • api/inventory/v1/json/client/agents_service/list_agents_responses.go
  • api/inventory/v1/json/v1.json
  • api/management/v1/agent.pb.validate.go
  • api/management/v1/agent.proto
  • api/management/v1/json/client/management_service/add_service_responses.go
  • api/management/v1/json/client/management_service/discover_rds_responses.go
  • api/management/v1/json/client/management_service/list_agents_responses.go
  • api/management/v1/json/client/management_service/list_services_responses.go
  • api/management/v1/json/v1.json
  • api/management/v1/rds.pb.validate.go
  • api/management/v1/rds.proto
  • api/swagger/swagger-dev.json
  • api/swagger/swagger.json
  • go.mod
  • managed/models/agent_helpers.go
  • managed/models/agent_helpers_test.go
  • managed/models/agent_model.go
  • managed/models/agent_model_test.go
  • managed/models/agentversion.go
  • managed/services/agents/rds.go
  • managed/services/agents/rds_test.go
  • managed/services/agents/roster.go
  • managed/services/agents/roster_test.go
  • managed/services/agents/state.go
  • managed/services/agents/state_test.go
  • managed/services/converters.go
  • managed/services/inventory/agents.go
  • managed/services/management/agent.go
  • managed/services/management/rds.go
  • managed/services/management/rds_test.go
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • percona/pmm-qa (manual)
  • percona/pmm (manual)

Included review availability: Your plan provides up to 4 included reviews per hour; 1 remains after this review.

Comment thread managed/models/agent_helpers.go
Comment thread managed/services/management/rds.go Outdated
Address CodeRabbit review on #5944:

- The role-ARN gate allowed on any non-AgentNotSupportedError, so a
  present-but-malformed pmm-agent version (and, on the change path, a
  PMM Agent lookup error) silently persisted an unverifiable role ARN.
  Add an ErrAgentVersionNotReported sentinel and allow only that case;
  reject the rest.
- DiscoverRDS reported an STS timeout as FailedPrecondition; return
  DeadlineExceeded for context cancellation/deadline instead.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@4nte

4nte commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to GitHub limitations.

⚠️ Outside diff range comments (1)
managed/services/management/rds.go (1)

604-609: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Support aws-iso-b through the complete settings and discovery paths.

ValidateAWSPartitions rejects aws-iso-b, so UpdateSettings returns InvalidArgument before the partition is saved. listRegions also has no aws-iso-b entry, and stsRegionForRoleARN rejects its role ARNs before the STS call.

Add aws-iso-b to AWSPartitions(). Move us-isob-east-1 into an aws-iso-b RDS region set. Add the stsDefaultRegion mapping. Update the tests that currently expect aws-iso-b to be unsupported. The API schema already accepts generic strings, and the default partition remains aws.

Required fix
 func AWSPartitions() []string {
 	return []string{
 		"aws",
 		"aws-cn",
 		"aws-iso",
+		"aws-iso-b",
 		"aws-us-gov",
 	}
 }

 var stsDefaultRegion = map[string]string{
 	"aws":        "us-east-1",
 	"aws-cn":     "cn-north-1",
 	"aws-us-gov": "us-gov-west-1",
 	"aws-iso":    "us-iso-east-1",
+	"aws-iso-b":  "us-isob-east-1",
 }
 		"aws-iso": {
 			"rds": {
-				"us-iso-east-1", "us-iso-west-1", "us-isob-east-1",
+				"us-iso-east-1", "us-iso-west-1",
+			},
+		},
+		"aws-iso-b": {
+			"rds": {
+				"us-isob-east-1",
 			},
 		},

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5af51db9-4424-42a6-a409-014fc52e8c4b

📥 Commits

Reviewing files that changed from the base of the PR and between 1520890 and 074f21a.

📒 Files selected for processing (4)
  • managed/models/agent_helpers.go
  • managed/models/agent_helpers_test.go
  • managed/models/agentversion.go
  • managed/services/management/rds.go
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • percona/pmm-qa (manual)
  • percona/pmm (manual)

Included review availability: Your plan provides up to 4 included reviews per hour; 2 remain after this review.

4nte added a commit to Percona-Lab/pmm-submodules that referenced this pull request Sep 16, 2026
The FB pinned PMM-15389-rds-assume-iam-role, the single branch this work
started on. It was since split into a reviewable stack, percona/pmm#5943
for the instance_id fix with percona/pmm#5944 stacked on top, replayed
onto a newer main and given two further commits: golangci-lint fixes and
a tightened role-ARN version gate with an STS timeout.

Pin PMM-15389-assume-role instead, so the images carry what is actually
under review rather than the branch review moved off. It contains the
instance_id commits too, being stacked on that base, so one entry still
covers the whole stack.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@CLAassistant

CLAassistant commented Sep 16, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

Cover the required flag and the request body: parsing fails without
--instance-id, and the value reaches remote_rds.instance_id.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Nodes created before 3.4.0 or through the inventory API hold the
bare identifier in address, not the endpoint. Say so on both
messages, describe the instance_id fallback and lowercasing, and call
RemoteRDSNode.instance_id a DB instance identifier rather than an
AWS instance ID, which reads like an EC2 ID.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Add the instance_id field on AddRemoteRDSNodeParams to the buf
breaking baseline.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Migration 110 copied the address into instance_id as typed, and the
management API stores the identifier it is given, so existing remote
RDS nodes can carry a mixed-case identifier. AWS stores DB instance
identifiers in lowercase and rds_exporter matches them exactly, so
such a node passes the new guard and still scrapes nothing.

Lowercase existing identifiers and the backfilled bare addresses, the
same rule createNodeWithID now applies to new nodes.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
The file committed in bdbbe96 came from make -C api gen without the
formatting pass that make gen runs last, so CI's format check restored
the blank line gofumpt inserts before the depIdxs declaration.

Regenerated with make gen and make format in the devcontainer; that
blank line is the only change.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
…PMM-15389-assume-role

# Conflicts:
#	managed/models/agent_helpers_test.go
#	managed/services/agents/state_test.go
DiscoverRDS always assumed the IAM role against the partition's home
region (us-east-1 for commercial AWS), even when PMM Server had a
region configured. A server whose egress is limited to one region
could never reach that STS endpoint and failed with "Timed out
assuming role".

Assume the role in the region the AWS SDK resolved from AWS_REGION,
AWS_DEFAULT_REGION or the profile, and keep the partition default only
as the fallback for a server with no region configured. A configured
region outside the role's partition cannot issue its credentials, so
reject it up front with a FailedPrecondition that names the variable,
before any network call.

Only the STS call moves. Region scanning, the partition allow-list in
settings, and the discovery deadlines are unchanged.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
AWS_REGION and AWS_DEFAULT_REGION now steer which STS endpoint PMM
Server uses to assume an RDS role, so they are documented input rather
than unknown variables. Skip them in the environment parser alongside
the existing AWS_ACCESS_KEY and AWS_SECRET_KEY case instead of logging
"unknown environment variable" at startup.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Renumber the RDS instance_id backfill migration from 119 to 120, since
main's 119 clears unused environment variable names. Point its test at
the new number.

Keep the AWS options validation and role ARN version gate in
CreateAgent, and save through main's new insertAgent helper.

Take main's AWS SDK versions; sts becomes a direct dependency.
Regenerate api/descriptor.bin.

Switch the RDS role gate test from the removed models.ChangeAgent to
the changeAgent test helper.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
Extract the role assumption block of DiscoverRDS into assumeRDSRole
to fix the nestif lint finding. Behavior is unchanged.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@4nte
4nte requested review from a team and Nailya as code owners October 7, 2026 09:00
@4nte
4nte requested review from fabio-silva and matejkubinec and removed request for a team October 7, 2026 09:00
@4nte
4nte changed the base branch from PMM-15389-rds-inventory-cli to main October 7, 2026 09:05
@github-actions github-actions Bot added the documentation Documentation changes label Oct 7, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 94d9bc41-25fd-4276-ad3a-c188b79adc7f
📥 Commits

Reviewing files that changed from the base of the PR and between 074f21a and 7542128.

⛔ Files ignored due to path filters (3)
  • api/descriptor.bin is excluded by !**/*.bin
  • api/inventory/v1/agents.pb.go is excluded by !**/*.pb.go
  • api/inventory/v1/nodes.pb.go is excluded by !**/*.pb.go
📒 Files selected for processing (39)
  • admin/commands/inventory/add_node_remote_rds_test.go
  • admin/commands/inventory/change_agent_rds_exporter_test.go
  • api-tests/inventory/agents_rds_exporter_test.go
  • api/inventory/v1/agents.pb.validate.go
  • api/inventory/v1/agents.proto
  • api/inventory/v1/json/client/agents_service/change_agent_responses.go
  • api/inventory/v1/json/client/nodes_service/add_node_responses.go
  • api/inventory/v1/json/client/nodes_service/get_node_responses.go
  • api/inventory/v1/json/client/nodes_service/list_nodes_responses.go
  • api/inventory/v1/json/v1.json
  • api/inventory/v1/nodes.pb.validate.go
  • api/inventory/v1/nodes.proto
  • api/management/v1/json/client/management_service/add_service_responses.go
  • api/management/v1/json/v1.json
  • api/swagger/swagger-dev.json
  • api/swagger/swagger.json
  • go.mod
  • managed/models/agent_helpers.go
  • managed/models/agent_helpers_test.go
  • managed/models/agent_model.go
  • managed/models/agent_model_test.go
  • managed/models/agentversion.go
  • managed/models/database.go
  • managed/models/database_test.go
  • managed/models/node_helpers.go
  • managed/services/agents/rds.go
  • managed/services/agents/rds_test.go
  • managed/services/agents/state.go
  • managed/services/agents/state_test.go
  • managed/services/converters.go
  • managed/services/inventory/agents.go
  • managed/services/inventory/agents_test.go
  • managed/services/inventory/nodes.go
  • managed/services/inventory/nodes_test.go
  • managed/services/inventory/services_test.go
  • managed/services/management/rds.go
  • managed/services/management/rds_test.go
  • managed/utils/envvars/parser.go
  • managed/utils/envvars/parser_test.go
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.

Comment thread api/inventory/v1/nodes.proto
Comment thread managed/models/node_helpers.go
Comment thread managed/services/management/rds.go
A blank instance_id was stored as is and could never match an RDS
instance. Trim it, and treat a blank value like an omitted one.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
4nte and others added 2 commits October 7, 2026 12:30
Keep the branch's roster lookup in the conflict with main's encrypted
access key fix: findRDSExportersByCredentials already matches on the
decrypted credentials in Go, and covers role ARNs as well.

Signed-off-by: Ante Gulin <ante.gulin@percona.com>
@4nte
4nte enabled auto-merge (squash) October 8, 2026 07:06
@4nte
4nte merged commit d612657 into main Oct 8, 2026
30 checks passed
@4nte
4nte deleted the PMM-15389-assume-role branch October 8, 2026 07:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Documentation changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants