Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hotfix prod: Index dcp42 in prod and make dcp41 default (#6556, #6558) #6567

Merged
merged 2 commits into from
Sep 13, 2024

Conversation

achave11-ucsc
Copy link
Member

@achave11-ucsc achave11-ucsc commented Sep 13, 2024

Connected issue: #6558, #6556

Notes

  • Manually deindex the dcp40 and dcp40-it catalogs from the prod deployment
  • Perform a targeted index of the dcp42 catalog

Checklist

Author

  • Target branch is prod
  • Name of PR branch matches hotfixes/<GitHub handle of author>/<issue#>-<slug>-prod
  • On ZenHub, PR is connected to the issue it hotfixes
  • PR description links to connected issue
  • PR title is Hotfix prod: followed by title of connected issue
  • PR title references the connected issue

Author (hotfixes)

  • Added h tag to commit title or this PR does not include a temporary hotfix
  • Added H tag to commit title or this PR does not include a permanent hotfix
  • Added hotfix label to PR
  • This PR is labeled partial or represents a permanent hotfix

Author (before every review)

  • Rebased PR branch on prod, squashed old fixups
  • Ran make requirements_update or this PR does not modify requirements*.txt, common.mk, Makefile and Dockerfile
  • Added R tag to commit title or this PR does not modify requirements*.txt
  • This PR is labeled reqs or does not modify requirements*.txt

System administrator (after approval)

  • Actually approved the PR
  • Labeled PR as no sandbox
  • A comment to this PR details the completed security design review
  • PR title is appropriate as title of merge commit
  • Moved connected issue to Approved column
  • PR is assigned to only the operator

Operator (before pushing merge the commit)

  • Squashed PR branch and rebased onto prod
  • Sanity-checked history
  • Pushed PR branch to GitHub
  • The title of the merge commit starts with the title of this PR
  • Added PR # reference to merge commit title
  • Collected commit title tags in merge commit title but excluded any p tags
  • Moved connected issue to Merged stable column in ZenHub
  • Pushed merge commit to GitHub

Operator (after pushing the merge commit)

  • Pushed merge commit to GitLab prod
  • Build passes on GitLab prod
  • Reviewed build logs for anomalies on GitLab prod
  • Deleted PR branch from GitHub

Operator (reindex)

  • Deindexed all unreferenced catalogs in prod or this PR is neither labeled reindex:partial nor reindex:prod
  • Deindexed specific sources in prod or this PR is neither labeled reindex:partial nor reindex:prod
  • Indexed specific sources in prod or this PR is neither labeled reindex:partial nor reindex:prod
  • Started reindex in prod or neither this PR nor a failed, prior promotion requires it
  • Checked for, triaged and possibly requeued messages in both fail queues in prod or neither this PR nor a failed, prior promotion requires it
  • Emptied fail queues in prod or neither this PR nor a failed, prior promotion requires it
  • Created backport PR and linked to it in a comment on this PR

Operator

  • PR is assigned to no one

Shorthand for review comments

  • L line is too long
  • W line wrapping is wrong
  • Q bad quotes
  • F other formatting problem

@github-actions github-actions bot added the orange [process] Done by the Azul team label Sep 13, 2024
@achave11-ucsc achave11-ucsc added hotfix [process] An PR with an urgent fix for prod and removed orange [process] Done by the Azul team labels Sep 13, 2024
@achave11-ucsc achave11-ucsc force-pushed the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch from cdd5f02 to f87af7e Compare September 13, 2024 14:26
@github-actions github-actions bot added the orange [process] Done by the Azul team label Sep 13, 2024
@coveralls
Copy link

coveralls commented Sep 13, 2024

Coverage Status

coverage: 85.399%. remained the same
when pulling 5a23ace on hotfixes/achave11-ucsc/6558-dcp42-catalog-prod
into c7475dc on prod.

Copy link

codecov bot commented Sep 13, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 85.38%. Comparing base (c7475dc) to head (5a23ace).
Report is 3 commits behind head on prod.

Additional details and impacted files
@@           Coverage Diff           @@
##             prod    #6567   +/-   ##
=======================================
  Coverage   85.38%   85.38%           
=======================================
  Files         155      155           
  Lines       20735    20735           
=======================================
  Hits        17704    17704           
  Misses       3031     3031           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@achave11-ucsc achave11-ucsc force-pushed the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch 2 times, most recently from bd78acc to 6bf2f42 Compare September 13, 2024 16:14
Comment on lines 1175 to 1182
mksrc('bigquery', 'datarepo-db22b6c5', 'hca_prod_19037ec943a74823b93f9e59c694d17e__20240903_dcp2_20240904_dcp42', 16), # noqa E501
mksrc('bigquery', 'datarepo-8e43554a', 'hca_prod_35d5b0573daf4ccd8112196194598893__20240903_dcp2_20240905_dcp42', 303, ma), # noqa E501
mksrc('bigquery', 'datarepo-5b6ac433', 'hca_prod_5f1a1aee6c484dd4a2c4eb4ca6aadf74__20240903_dcp2_20240904_dcp42', 40), # noqa E501
mksrc('bigquery', 'datarepo-d5e4c41e', 'hca_prod_7c75f07c608d4c4aa1b7b13d11c0ad31__20220117_dcp2_20240904_dcp42', 80), # noqa E501
mksrc('bigquery', 'datarepo-eb6182b7', 'hca_prod_888f17664c8443bb8717b5f9d2046097__20240903_dcp2_20240904_dcp42', 111), # noqa E501
mksrc('bigquery', 'datarepo-b9e1d9ec', 'hca_prod_9dd91b6e7c6249d3a3d474f603deffdb__20240903_dcp2_20240904_dcp42', 135), # noqa E501
mksrc('bigquery', 'datarepo-582bf509', 'hca_prod_b176d75662d8493383a48b026380262f__20240903_dcp2_20240904_dcp42', 106), # noqa E501
mksrc('bigquery', 'datarepo-c85d293d', 'hca_prod_f598aee0d269403690e9d6d5b1c84429__20240903_dcp2_20240904_dcp42', 6) # noqa E501
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is over-indented.

@hannes-ucsc hannes-ucsc added the 1 review [process] Lead requested changes once label Sep 13, 2024
@hannes-ucsc hannes-ucsc removed their assignment Sep 13, 2024
@achave11-ucsc achave11-ucsc force-pushed the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch 2 times, most recently from 044e2ba to 32247b9 Compare September 13, 2024 20:31
@achave11-ucsc achave11-ucsc changed the title Hotfix prod: Index dcp42 in prod (#6558) Hotfix prod: Index dcp42 in prod and make dcp41 default (#6556, #6558) Sep 13, 2024
@achave11-ucsc achave11-ucsc force-pushed the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch from 76a5572 to 3b0d38a Compare September 13, 2024 20:37
@achave11-ucsc achave11-ucsc added reindex:prod [process] PR requires reindexing prod reindex:partial [process] PR allows for (de)indexing a specific source or catalog labels Sep 13, 2024
@hannes-ucsc hannes-ucsc force-pushed the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch from 3b0d38a to 5a23ace Compare September 13, 2024 21:28
Copy link
Member

@hannes-ucsc hannes-ucsc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One of the commits lacked the H tag. I added it and force-pushed.

@hannes-ucsc hannes-ucsc added the no sandbox [process] PR will not be tested in the sandbox label Sep 13, 2024
@hannes-ucsc
Copy link
Member

hannes-ucsc commented Sep 13, 2024

Security design review

  • Security design review completed; this PR does not
    • … affect authentication; for example:
      • OAuth 2.0 with the application (API or Swagger UI)
      • Authentication of developers with Google Cloud APIs
      • Authentication of developers with AWS APIs
      • Authentication with a GitLab instance in the system
      • Password and 2FA authentication with GitHub
      • API access token authentication with GitHub
      • Authentication with Terra
    • … affect the permissions of internal users like access to
      • Cloud resources on AWS and GCP
      • GitLab repositories, projects and groups, administration
      • an EC2 instance via SSH
      • GitHub issues, pull requests, commits, commit statuses, wikis, repositories, organizations
    • … affect the permissions of external users like access to
      • TDR snapshots
    • … affect permissions of service or bot accounts
      • Cloud resources on AWS and GCP
    • … affect audit logging in the system, like
      • adding, removing or changing a log message that represents an auditable event
      • changing the routing of log messages through the system
    • … affect monitoring of the system
    • … introduce a new software dependency like
      • Python packages on PYPI
      • Command-line utilities
      • Docker images
      • Terraform providers
    • add an interface that exposes sensitive or confidential data at the security boundary Hotfix prod: Index dcp42 in prod and make dcp41 default (#6556, #6558) #6567 (comment)
    • … affect the encryption of data at rest
    • … require persistence of sensitive or confidential data that might require encryption at rest
    • … require unencrypted transmission of data within the security boundary
    • … affect the network security layer; for example by
      • modifying, adding or removing firewall rules
      • modifying, adding or removing security groups
      • changing or adding a port a service, proxy or load balancer listens on
  • Documentation on any unchecked boxes is provided in comments below

@hannes-ucsc
Copy link
Member

Security design review: This change adds an managed-access snapshot for HCA production as requested and approved by HCA stakeholders. Only Google identities that are registered with Terra and that have been given access to that snapshot by the Terra team will be able to access Azul's copy of the metadata from that snapshot.

@achave11-ucsc achave11-ucsc merged commit a08f86c into prod Sep 13, 2024
9 checks passed
@achave11-ucsc achave11-ucsc deleted the hotfixes/achave11-ucsc/6558-dcp42-catalog-prod branch September 13, 2024 23:24
@achave11-ucsc
Copy link
Member Author

Backport PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1 review [process] Lead requested changes once hotfix [process] An PR with an urgent fix for prod no sandbox [process] PR will not be tested in the sandbox orange [process] Done by the Azul team reindex:partial [process] PR allows for (de)indexing a specific source or catalog reindex:prod [process] PR requires reindexing prod
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants