Skip to content

검증 환경 CloudWatch canary gate 및 Pod drain 개선 - #23

Open
masondev1024 wants to merge 2 commits into
mainfrom
fix/live-lab-20261001
Open

masondev1024 wants to merge 2 commits into
mainfrom
fix/live-lab-20261001

Conversation

@masondev1024

@masondev1024 masondev1024 commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

변경 내용

  • Argo Rollouts canary 분석에 CloudWatch ALB ELB/target 5xx 및 target p95 gate를 추가하고, canary별 애플리케이션 지표와 분리했습니다.
  • Argo Rollouts 전용 IRSA 읽기 권한과 세션 ALB/WAF 연결을 검증하는 operator helper를 추가했습니다. Load Balancer Controller의 WAF 권한은 제거했습니다.
  • live-lab overlay에만 graceful termination/drain 설정을 적용하고, Terraform node group 정리 순서와 Secrets Manager 잔존 리소스 확인을 보완했습니다.
  • 부하 계획 기본 요청 수와 README/acceptance 기록을 현재 계획에 맞췄습니다.

변경 이유

이전 pod 삭제 실험에서 요청 오류가 관측됐고, canary gate는 앱 지표만 확인해 ALB가 생성한 오류를 구분하지 못했습니다. 배포 판단에 외부 ALB 신호를 포함하고, 종료·정리 경로를 검증 가능한 범위로 보강합니다.

데이터·실행 영향

  • 이 PR만으로 AWS 인프라를 생성하거나 서비스를 배포하지 않습니다. AWS 자원 생성은 유효한 인증과 별도 세션 실행이 필요합니다.
  • 기본 3시간·102,000 요청 계획은 예비비 포함 USD 5.0966으로 추산됩니다. USD 5.50은 사전 계획 한도이지 AWS 청구 하드캡이나 실제 비용이 아닙니다.
  • CloudWatch ALB 지표는 전용 세션 ALB 전체를 보는 보수적 guardrail이며, canary 자체 오류·outbox 정합성은 Prometheus가 판단합니다.
  • 개인 E2E 기록, 보안 리뷰, 계획 산출물은 로컬 전용으로 유지했습니다.

기존 로컬 검증 보고

아래 로컬 결과는 기존 PR 작성자의 보고이며, AC 4 본문 점검에서 재실행한 결과가 아닙니다. CI 및 실제 AWS 검증과 별개입니다.

  • 전체 Python 테스트: 664 passed, 3 skipped. 기존 Flask-Babel deprecation warning 1건.
  • Terraform fmt/validate, live-lab 및 prod/validation/v1/v2 Kustomize 렌더링 통과.
  • 영향받은 shell 스크립트 bash -n 및 git diff --check 통과.
  • 실제 AWS 검증은 UNVERIFIED입니다. 임시 환경은 삭제되었으며 새 AWS 리소스를 생성하지 않았습니다. 청구 금액은 확정되지 않았습니다. CloudWatch IRSA, WAF 연결, canary rollback 및 pod 삭제 결과는 검증되지 않았습니다.
  • 원격 CI 결과는 이 PR의 checks에서 확인합니다.

되돌리기

  • 코드 변경은 이 PR을 revert해 복구합니다. 실환경 자원이 생성된 경우에는 정확한 계정·리전·Session/Approval 범위를 확인해 해당 세션 teardown으로 정리합니다.

Verification scope and live AWS disclosure

Live AWS validation: UNVERIFIED — ephemeral environment destroyed; no new AWS resources created.

  • Implementation and reported local test results above do not establish live AWS behavior. This disclosure check retrieves the published PR body only; it does not rerun application, telemetry, shutdown, or data-flow checks.
  • CI verification is separate: at the AC 4 inspection, Container vulnerability gate reported FAILURE and other checks were still running. CI acceptance is not established; consult the current PR checks for subsequent results.
  • Telemetry contract resolution and its acceptance remain separate prerequisites; the implementation description does not establish an authoritative telemetry decision or successful canary acceptance.
  • Live AWS validation remains unverified. Additional billable resources require renewed approval. Merge and release remain pending explicit approval.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant