Skip to content

[nodejs_lambda] Remove any calls to public.ecr.aws on critical path for nodejs lambda - #7859

Open
CarlesDD wants to merge 8 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-remove-ecr-calls
Open

CarlesDD wants to merge 8 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-remove-ecr-calls

Conversation

@CarlesDD

Copy link
Copy Markdown
Contributor

Motivation

Same rationale as #7838 (which did this for python_lambda): the nodejs_lambda weblog Dockerfiles call public.ecr.aws/lambda/nodejs and public.ecr.aws/datadog/lambda-extension directly, on the critical path of every build. This applies the same fix to the Node.js weblogs.

Changes

  • New utils/build/docker/nodejs_lambda/runtime.base.Dockerfile: extracts the shared preamble (base runtime image + Datadog Extension) out of the five per-trigger Dockerfiles into one image, built once and mirrored like every other base image in this repo instead of pulled from public.ecr.aws on every build.
  • New utils/build/docker/nodejs_lambda/docker-bake.hcl: bake file for that base image, following the same pattern as python_lambda's.
  • nodejs-alb.Dockerfile, nodejs-alb-multi.Dockerfile, nodejs-apigw-http.Dockerfile, nodejs-apigw-rest.Dockerfile, nodejs-function-url.Dockerfile: replaced their public.ecr.aws preamble with FROM system_tests_base_nodejs_lambda_nodejs_lambda_runtime.

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Tests, manifest, weblog are modified -> you'll need a review from system-tests-reviewers: ask to one of youre co-worker familiar with the tested feature.
    • Framework is modified, or non obvious usage of it -> get a review from system-tests-core (slack)

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

utils/build/docker/nodejs_lambda/docker-bake.hcl                        @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/runtime.base.Dockerfile                @DataDog/system-tests-reviewers
.github/workflows/update-lambda-extension.yml                           @DataDog/system-tests-core
mirror_images.lock.yaml                                                 @DataDog/system-tests-core
mirror_images.yaml                                                      @DataDog/system-tests-core
utils/build/docker/base-images.lock.json                                @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/install_datadog_lambda.sh              @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-alb-multi.Dockerfile            @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-alb.Dockerfile                  @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-http.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-rest.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-function-url.Dockerfile         @DataDog/system-tests-reviewers
utils/scripts/update_lambda_extension_version.py                        @DataDog/system-tests-core

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 15 Pipeline jobs failed

Testing the test | System Tests (ruby, dev) / End-to-end #1 / rails52 1 — ❌ 15 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag.test_ai_guard_event[rails52] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f5554852ab0>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f5554852ab0>

    def test_ai_guard_event(self):
        """Test AI Guard sets ai_guard.event:true tag in the local root span of the trace."""
>       assert self.r.status_code == 200
E       assert 500 == 200
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone.test_standalone_keeps_ai_guard_trace[rails52] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7f2c30592ea0>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7f2c30592ea0>

    def test_standalone_keeps_ai_guard_trace(self):
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker.test_all_spans_have_apm_disabled_marker[rails52] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7f2c30592d50>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7f2c30592d50>

    def test_all_spans_have_apm_disabled_marker(self) -> None:
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
↳ and 12 more — View all
Testing the test | System Tests (ruby, dev) / End-to-end #1 / rails61 1 — ❌ 15 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag.test_ai_guard_event[rails61] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f69b581c5c0>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f69b581c5c0>

    def test_ai_guard_event(self):
        """Test AI Guard sets ai_guard.event:true tag in the local root span of the trace."""
>       assert self.r.status_code == 200
E       assert 500 == 200
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone.test_standalone_keeps_ai_guard_trace[rails61] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7f0dd88f8ef0>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7f0dd88f8ef0>

    def test_standalone_keeps_ai_guard_trace(self):
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker.test_all_spans_have_apm_disabled_marker[rails61] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7f0dd88f8e60>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7f0dd88f8e60>

    def test_all_spans_have_apm_disabled_marker(self) -> None:
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'X-Frame-Options': 'SAMEORIGIN', 'X-XSS-Protection': '1; mode=block', 'X-Conten...'Transfer-Encoding': 'chunked'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
↳ and 12 more — View all
Testing the test | System Tests (ruby, dev) / End-to-end #1 / rails72 1 — ❌ 15 tests failed · 🔧 Needs a code fix, caused by this PR

View more details · View in GitHub Actions

❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag.test_ai_guard_event[rails72] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...01573', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...01573', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f67d7c21bb0>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardEvent_Tag object at 0x7f67d7c21bb0>

    def test_ai_guard_event(self):
        """Test AI Guard sets ai_guard.event:true tag in the local root span of the trace."""
>       assert self.r.status_code == 200
E       assert 500 == 200
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone.test_standalone_keeps_ai_guard_trace[rails72] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...02505', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...02505', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7ffbee66b140>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone object at 0x7ffbee66b140>

    def test_standalone_keeps_ai_guard_trace(self):
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...02505', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
❌ tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker.test_all_spans_have_apm_disabled_marker[rails72] from system_tests_suite
assert 500 == 200
 +  where 500 = HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...01072', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
 +    where HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...01072', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}) = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7ffbee66a870>.r

self = <tests.ai_guard.test_ai_guard_sdk.Test_AIGuardStandalone_APMDisabledMarker object at 0x7ffbee66a870>

    def test_all_spans_have_apm_disabled_marker(self) -> None:
>       assert self.r.status_code == 200
E       assert 500 == 200
E        +  where 500 = HttpResponse(status_code:500, headers:{'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '0', 'x-content-type-optio...01072', 'Content-Length': '80'}, text:{"error":"unknown keywords: :id, :tool_name, :arguments","type":"ArgumentError"}).status_code
...
↳ and 12 more — View all

View all 15 failed jobs.

ℹ️ Info

No other issues found (see more)

❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 94ce0fd | Docs | View more details | Give us feedback!

@CarlesDD
CarlesDD marked this pull request as ready for review October 1, 2026 06:14
@CarlesDD
CarlesDD requested review from a team as code owners October 1, 2026 06:14
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T06:20:17.178545Z 90fb68e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 90fb68e570

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread utils/build/docker/nodejs_lambda/docker-bake.hcl

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant