Aws/adopt
Brownfield adoption of existing AWS infrastructure into swamp models. Discovers resources via native SDK calls, generates setup commands, and orchestrates import via a dependency-ordered workflow.
Authentication
Uses the default AWS credential chain. Requires appropriate IAM permissions for discovery (ReadOnly access to EC2, RDS, SecretsManager).
Quick Start
swamp extension pull @webframp/aws/adopt
swamp model create @webframp/aws/adopt my-discovery \
--global-arg region=us-east-1 --global-arg vpcId=vpc-xxx
swamp model method run my-discovery discover_all
# Follow the setup commands in the output, then:
swamp workflow run @webframp/adopt-stack --input vpcId=vpc-xxx2026.07.30.1
Added: Optional profile global argument for multi-account credential resolution.
When set, credentials resolve via fromIni (supports SSO token cache and shared-config
profiles). When omitted, the default credential chain applies as before. Fully backward
compatible — no changes required for existing instances.
| Argument | Type | Description |
|---|---|---|
| stackName | string | CloudFormation stack name (not ARN) |
| includeNested | boolean | Recurse into AWS::CloudFormation::Stack resources |
| maxDepth | number | Nested stack recursion limit |
| prefix | string | Prefix for generated swamp model names |
Resources
Orchestrate brownfield adoption of existing AWS infrastructure. Runs get and sync on pre-created swamp models in dependency order: networking first, then database, then secrets, then verification. Models must be pre-created from discover_all output before running this workflow. The workflow references models by deterministic names derived from the prefix and resource identifiers. Resources whose IDs cannot be derived from workflow inputs (subnets, route tables, security groups) should be impor
Adopt all resources defined in a CloudFormation stack into swamp typed data, comparing the stack's resource list against live AWS state. How it works: - Job 1 runs plan_stack_adoption to enumerate stack resources (recursively into nested stacks), map them to swamp types, and produce an adoption plan. - Job 2 iterates over the plan's mapped[] resources and runs `get` on each pre-existing swamp model to refresh its live state. Steps allow failure so missing models on the first run don't fai
Check for drift on all resources adopted from a CloudFormation stack. Re-runs the adoption plan to detect stack changes, then syncs each adopted model to refresh live state. The drift report compares the previous stored state against the fresh sync to surface differences. Usage: AWS_PROFILE=my-account/ReadOnlyPlus \ swamp workflow run @webframp/adopt-drift-check \ --input modelName=my-adopt \ --input stackName=my-prod-stack
Compares stored state vs live state for adopted CloudFormation stack resources and surfaces drift
Summarizes adoption workflow results with success/failure counts, per-job breakdown, and remediation guidance
2026.07.29.1
Fixed: Terminate upgrade chain at current version (extension was uninstallable due to broken upgrade chain).
2026.07.27.1
Changed: Bump @aws-sdk/* 3.1094.0 → 3.1096.0 (4 packages)
Changed: Bump @swamp/aws/ec2 2026.07.20.1 → 2026.07.27.1
Changed: Bump @swamp/aws/rds 2026.07.20.1 → 2026.07.27.1
Changed: Bump @swamp/aws/secretsmanager 2026.07.20.1 → 2026.07.27.1
2026.07.26.1
Fixed: Model failed to load because the upgrades array's last toVersion
("2026.07.18.2") did not match the model's current version ("2026.07.24.1").
Swamp's model loader enforces this invariant, causing the extension to be
rejected at load time before any AWS API calls could execute. This manifested
as silent failures in ECS Fargate environments where the error was not surfaced
to the operator.
Upgrade note: Users on 2026.07.24.1 can upgrade in place. The upgrade chain now covers all published versions (2026.07.18.2 → 2026.07.24.1 → 2026.07.26.1) with no schema changes at any step.
updated dependencies
2026.07.26.1
Fixed: Model failed to load because the upgrades array's last toVersion
("2026.07.18.2") did not match the model's current version ("2026.07.24.1").
Swamp's model loader enforces this invariant, causing the extension to be
rejected at load time before any AWS API calls could execute. This manifested
as silent failures in ECS Fargate environments where the error was not surfaced
to the operator.
Upgrade note: Users on 2026.07.24.1 can upgrade in place. The upgrade chain now covers all published versions (2026.07.18.2 → 2026.07.24.1 → 2026.07.26.1) with no schema changes at any step.
2026.07.24.1
Changed: Bump AWS SDK from 3.1091.0 to 3.1094.0 (patch-level update).
Changed: Bump dependency pins to latest published versions:
- @swamp/aws/ec2 2026.04.03.2 → 2026.07.20.1
- @swamp/aws/rds 2026.04.23.2 → 2026.07.20.1
- @swamp/aws/secretsmanager 2026.06.15.1 → 2026.07.20.1
updated dependencies
2026.07.21.1
Changed: Bumped AWS SDK dependencies to 3.1091.0 (from 3.1090.0).
Upgrade note: No behavioral changes. Routine dependency maintenance.
2026.07.18.2
Added: An upgrades array entry (no-op) to adopt.ts for proper typeVersion tracking on existing instances. No schema or behavior changes.
2026.07.18.1
Added: @module-level JSDoc documentation to adopt.ts.
Changed: Bumped @aws-sdk/client-cloudformation, @aws-sdk/client-ec2,
@aws-sdk/client-rds, and @aws-sdk/client-secrets-manager from 3.1069.0
to 3.1090.0 for dependency freshness. No behavior change.
2026.07.16.1
Fixed: The pinned dependency on @swamp/aws/secretsmanager@2026.05.18.1 no
longer resolved in the registry, which broke swamp extension pull for this
extension and for anything depending on it transitively (e.g.
@webframp/aws/drift-state). Bumped the pin to 2026.06.15.1, the current
published version. This extension only references the secretsmanager model
type name in generated setup commands — it doesn't call into the package's
code — so there's no behavior change beyond the pull now succeeding.
2026.07.18.1
Added: @module-level JSDoc documentation to adopt.ts.
Changed: Bumped @aws-sdk/client-cloudformation, @aws-sdk/client-ec2,
@aws-sdk/client-rds, and @aws-sdk/client-secrets-manager from 3.1069.0
to 3.1090.0 for dependency freshness. No behavior change.
2026.07.16.1
Fixed: The pinned dependency on @swamp/aws/secretsmanager@2026.05.18.1 no
longer resolved in the registry, which broke swamp extension pull for this
extension and for anything depending on it transitively (e.g.
@webframp/aws/drift-state). Bumped the pin to 2026.06.15.1, the current
published version. This extension only references the secretsmanager model
type name in generated setup commands — it doesn't call into the package's
code — so there's no behavior change beyond the pull now succeeding.
2026.07.16.1
Fixed: The pinned dependency on @swamp/aws/secretsmanager@2026.05.18.1 no
longer resolved in the registry, which broke swamp extension pull for this
extension and for anything depending on it transitively (e.g.
@webframp/aws/drift-state). Bumped the pin to 2026.06.15.1, the current
published version. This extension only references the secretsmanager model
type name in generated setup commands — it doesn't call into the package's
code — so there's no behavior change beyond the pull now succeeding.
updated dependencies
Modified 1 models. Added 2 workflows. Added 1 reports
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned