Skip to main content
← Back to list
01Issue
BugOpenExtensionsPublic
AssigneesNone

Relationships

#2623 Codegen/AWS: create-only required fields block list/get/delete in generated AWS models

Opened by stack72 · 9/28/2026

Follow-up to swamp-club #2287, which fixed this for GCP in PR 341 (codegen/gcp/pipeline.ts nonCreatePathParams, and the create/update templates in codegen/gcp/extensionModelGenerator.ts).

swamp validates the whole GlobalArgsSchema whenever any global argument is set. This generator emits fields that only the create request needs as required there, so read-only methods fail unless callers pass placeholder create values.

Apply the same rule as #2287:

  • Keep required only what a non-create method reads from globalArgs, plus synthetic instance names.
  • Make create-only required fields optional in GlobalArgsSchema.
  • Enforce them with a generated check at the start of create that throws create requires global arguments: before any API call.
  • Where update fully replaces the resource (PUT), fill those fields from globalArgs, then from stored state, and throw before the API call if neither has them.
  • Regenerate the provider twice (the second run must produce zero diff) and update the provider's design doc.

Required-ness is decided in codegen/aws/pipeline.ts, which passes cfSchema.required to the shared codegen/shared/zodGenerator.ts (the top-level required list there is only a recursion pass-through, so the AWS caller can pass a reduced list without changing nested output).

Example: model/aws/ec2 route requires RouteTableId in GlobalArgsSchema, but its list method reads only credentials from globalArgs and takes the parent filter from the resourceModel argument.

Notes:

  • The synthetic name field stays required.
  • update and sync read identifiers from stored state.
  • update merges every defined globalArgs value into desiredState.
  • codegen/designs/aws.md (Required fields from cfSchema.required are non-optional) needs updating.
02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/28/2026, 9:07:01 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

stack72 commented 9/28/2026, 11:09:36 PM

Correction to the premise, found while fixing the Cloudflare sibling (#2645): swamp does not validate the whole GlobalArgsSchema on every method run. Method runs (direct and workflow steps) validate global args with .partial(). The full check happens in two places, and both are real failures: swamp model create with any --global-arg (libswamp/models/create.ts), and swamp workflow validate for steps that name a model type rather than a definition (libswamp/workflows/validate.ts adds every required global to the step). Reproduced on Cloudflare alerting/policies: model create with only account_id failed, and a type-based get step failed validate; get on an existing definition worked. The fix is the same, but verify against those two paths.

AWS update already merges global args over the live resource read via readResource, so the PUT fallback in the original list does not apply here.

Sign in to post a ripple.