Skip to content

[nodejs_lambda] Remove any calls to public.ecr.aws on critical path for nodejs lambda - #7859

Merged
CarlesDD merged 10 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-remove-ecr-calls
Oct 5, 2026
Merged

CarlesDD merged 10 commits into
mainfrom
ccapell/APPSEC-68818/nodejs-lambda-remove-ecr-calls

Conversation

@CarlesDD

Copy link
Copy Markdown
Contributor

Motivation

Same rationale as #7838 (which did this for python_lambda): the nodejs_lambda weblog Dockerfiles call public.ecr.aws/lambda/nodejs and public.ecr.aws/datadog/lambda-extension directly, on the critical path of every build. This applies the same fix to the Node.js weblogs.

Changes

  • New utils/build/docker/nodejs_lambda/runtime.base.Dockerfile: extracts the shared preamble (base runtime image + Datadog Extension) out of the five per-trigger Dockerfiles into one image, built once and mirrored like every other base image in this repo instead of pulled from public.ecr.aws on every build.
  • New utils/build/docker/nodejs_lambda/docker-bake.hcl: bake file for that base image, following the same pattern as python_lambda's.
  • nodejs-alb.Dockerfile, nodejs-alb-multi.Dockerfile, nodejs-apigw-http.Dockerfile, nodejs-apigw-rest.Dockerfile, nodejs-function-url.Dockerfile: replaced their public.ecr.aws preamble with FROM system_tests_base_nodejs_lambda_nodejs_lambda_runtime.

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Tests, manifest, weblog are modified -> you'll need a review from system-tests-reviewers: ask to one of youre co-worker familiar with the tested feature.
    • Framework is modified, or non obvious usage of it -> get a review from system-tests-core (slack)

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

utils/build/docker/nodejs_lambda/docker-bake.hcl                        @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/runtime.base.Dockerfile                @DataDog/system-tests-reviewers
.github/workflows/update-lambda-extension.yml                           @DataDog/system-tests-core
mirror_images.lock.yaml                                                 @DataDog/system-tests-core
mirror_images.yaml                                                      @DataDog/system-tests-core
utils/build/docker/base-images.lock.json                                @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/install_datadog_lambda.sh              @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-alb-multi.Dockerfile            @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-alb.Dockerfile                  @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-http.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-apigw-rest.Dockerfile           @DataDog/system-tests-reviewers
utils/build/docker/nodejs_lambda/nodejs-function-url.Dockerfile         @DataDog/system-tests-reviewers
utils/scripts/update_lambda_extension_version.py                        @DataDog/system-tests-core

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 492132d | Docs | View more details | Give us feedback!

@CarlesDD
CarlesDD marked this pull request as ready for review October 1, 2026 06:14
@CarlesDD
CarlesDD requested review from a team as code owners October 1, 2026 06:14
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T06:20:17.178545Z 90fb68e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 90fb68e570

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread utils/build/docker/nodejs_lambda/docker-bake.hcl
@CarlesDD
CarlesDD enabled auto-merge (squash) October 5, 2026 19:48
@CarlesDD
CarlesDD merged commit 0758a49 into main Oct 5, 2026
5202 of 5207 checks passed
@CarlesDD
CarlesDD deleted the ccapell/APPSEC-68818/nodejs-lambda-remove-ecr-calls branch October 5, 2026 21:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants