feat(runner-providers): add Lambda MicroVM provider - #5255
Draft
edersonbrilhante wants to merge 13 commits into
Draft
feat(runner-providers): add Lambda MicroVM provider#5255edersonbrilhante wants to merge 13 commits into
edersonbrilhante wants to merge 13 commits into
Conversation
Contributor
Dependency ReviewThe following issues were found:
License Issueslambdas/libs/compute-providers/package.json
OpenSSF ScorecardScorecard details
Scanned Files
|
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
3 times, most recently
from
August 6, 2026 19:20
5209852 to
61e4aa2
Compare
edersonbrilhante
force-pushed
the
refactor-ec2-provider-isolation
branch
from
August 7, 2026 21:42
1fc78c4 to
b948b89
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 7, 2026 21:42
61e4aa2 to
a638a13
Compare
edersonbrilhante
force-pushed
the
refactor-ec2-provider-isolation
branch
4 times, most recently
from
August 12, 2026 22:42
6d3c6ba to
cefb18a
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 12, 2026 22:47
a638a13 to
2384430
Compare
edersonbrilhante
force-pushed
the
refactor-ec2-provider-isolation
branch
from
August 12, 2026 22:57
cefb18a to
6a5922a
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 12, 2026 23:21
2384430 to
7679346
Compare
edersonbrilhante
changed the base branch from
refactor-ec2-provider-isolation
to
experimental-multi-runner-config-v2-20260805
August 12, 2026 23:23
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 12, 2026 23:41
7679346 to
11c97de
Compare
edersonbrilhante
force-pushed
the
experimental-multi-runner-config-v2-20260805
branch
from
August 13, 2026 11:13
2aa54f7 to
4dd211d
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 13, 2026 11:13
11c97de to
fa2e601
Compare
edersonbrilhante
force-pushed
the
experimental-multi-runner-config-v2-20260805
branch
from
August 13, 2026 11:41
4dd211d to
ca56c4c
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
2 times, most recently
from
August 13, 2026 12:25
4f6c867 to
93bd091
Compare
This was referenced Aug 13, 2026
…dules (#5257) ## Description - Keep `modules/runners` and stable `multi_runner_config` dispatch unchanged. Stable configurations retain their historical `module.runners["configuration"]` addresses and flat `runners_map` fields. - Add explicit opt-in through `experimental.multi_runner_config_v2`. Stable and experimental configurations can coexist when their keys do not overlap; duplicate keys are rejected. - Normalize stable v1 once for shared queues, webhook matching, and runner-binary discovery while routing only v2 configurations through `modules/runner-stack`. - Make `runner-stack` the provider-neutral control plane for scale-up, scale-down, pool, job retry, SSM housekeeping, common Lambda IAM, and runner-role ownership. - Keep EC2-specific launch templates, instance profiles, security groups, AMI/bootstrap resources, runner log groups, IAM fragments, and Lambda environment fragments under `modules/compute-providers/ec2`. - Define provider-owned runner-role requirements in EC2 and attach them to the common runner role in `runner-stack`, allowing future compute providers to supply different policies without duplicating the role lifecycle. - Replace flat runner-stack inputs with ownership-based nested objects. Logging configuration is grouped under `observability.logs`, including `level`, retention, encryption, class, and tags. - Pass the canonical `compute_provider.ec2` object and nested `runner`, `github`, `ssm`, and `observability` objects directly into the EC2 resource and runner-role policy modules instead of expanding them back into prefixed scalar inputs. - Layer module, shared-resource, component, subcomponent, and EC2 runtime tags with documented precedence; provider-required EC2 bootstrap tags retain final precedence. - Group experimental v2 outputs by ownership: `runner.role`, `scale_up.{lambda,log_group,role}`, `scale_down.{lambda,log_group,role}`, nullable `pool.{lambda,log_group,role}`, and provider-specific resources under `provider.<type>`. - Use caller-known optional wrappers for external AMI parameters and KMS keys. The wrapper determines Terraform graph shape while its `arn` leaf may remain unknown until apply. - Generate runner-stack, pool, job-retry, and EC2 IAM policies with `aws_iam_policy_document` and retain provider-policy merge behavior. - Document the experimental boundary, ownership model, plan-time wrapper pattern, phased migration, and nested output contract under the internal module documentation path. This draft is stacked on #5251 because the provider boundary consumes the experimental v2 normalization introduced there. Lambda/TypeScript terminology changes are tracked separately in #5258. ## Test Plan - `pre-commit run --all-files` — Terraform fmt, TFLint, validation, and merge-conflict checks passed. - `terraform test` in `modules/runner-stack` — 11 passed. - `terraform test` in `modules/multi-runner` — 7 passed. - `terraform test` in `modules/compute-providers/ec2` — 4 passed. - `terraform test` in `modules/compute-providers/ec2/runner-role` — 3 passed. - `terraform test` in `modules/runner-stack/pool` — 1 passed. - `terraform test` in `modules/runner-stack/job-retry` — 1 passed. - `terraform validate` in `modules/lambda` — passed. - Verified `modules/runners` has no diff from `origin/main`, stable v1 still dispatches only to `module.runners`, and only the experimental map dispatches to `module.runner_stacks`. - Verified computed external role, profile, AMI-parameter, managed-policy, and KMS ARN inputs plan successfully through the real wrapper fixture. No live AWS apply was performed. Terraform tests use mocked providers, and state migration is intentionally deferred to the later migration phase. ## Related Issues Closes #5252 Depends on #5251 --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
edersonbrilhante
force-pushed
the
experimental-multi-runner-config-v2-20260805
branch
from
August 14, 2026 13:09
28d8007 to
8512ab0
Compare
edersonbrilhante
force-pushed
the
feat-microvm-runner-provider
branch
from
August 14, 2026 13:22
93bd091 to
dfdcdaf
Compare
edersonbrilhante
force-pushed
the
experimental-multi-runner-config-v2-20260805
branch
from
August 15, 2026 02:00
09f9f2e to
50ecc05
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds an AWS Lambda MicroVM runner provider to the control-plane and webhook provider registries.
@aws-sdk/client-lambda-microvms.awsDynamicLabelsPolicyto MicroVM overrides and prevents one provider from accepting another provider's override labels.This PR is stacked on #5254, which moves provider selection and provider-specific tests out of the Lambda function packages.
Test Plan
libs/runner-providers.Related Issues
Depends on #5254 and #5251.
Related to #5252.