Skip to content

feat(data-warehouse): implement the aws compute optimizer import source - #110795

Merged
trunk-io[bot] merged 4 commits into
masterfrom
tom/dwh-source-aws_compute_optimizer
Oct 2, 2026
Merged

trunk-io[bot] merged 4 commits into
masterfrom
tom/dwh-source-aws_compute_optimizer

Conversation

@Gilbert09

Copy link
Copy Markdown
Member

Problem

  • AWS Compute Optimizer customers cannot sync AWS Compute Optimizer data into the PostHog data warehouse. The source was a scaffolded stub, hidden from the catalog.

Changes

  • Users can now connect AWS Compute Optimizer with an IAM access key and sync these tables:
Table Sync
ec2_instance_recommendations Full refresh
auto_scaling_group_recommendations Full refresh
lambda_function_recommendations Full refresh
ecs_service_recommendations Full refresh
ebs_volume_recommendations Full refresh
recommendation_summaries Full refresh
  • Requests are SigV4-signed over the tracked HTTP session, following the existing aws_organizations source.
  • Pagination is resumable, so a sync picks up after the last written page.
  • API version pinned: 2019-11-01.
  • The source ships as alpha with unreleasedSource removed.
  • Mechanical: the generated config and the SOURCES.md row.

How did you test this code?

  • New parameterized unit tests cover request signing and targets, pagination including the last page, incremental and full refresh request shapes, and error mapping.
  • Not checked: live calls against a real AWS account. mypy runs in CI only.

Test rationale: the source is new, so no existing test covers its transport.

Release status

  • No feature flag controls this change
  • This change is behind a feature flag and is not available to users
  • This change makes a previously flagged feature available to everyone

Automatic notifications

  • Publish to changelog?

Docs update

  • A posthog.com page for this source is still needed.

@Gilbert09 Gilbert09 self-assigned this Oct 2, 2026
@trunk-io

trunk-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

😎 Merged successfully - details.

@Gilbert09 Gilbert09 added the stamphog Request AI approval (no full review) label Oct 2, 2026 — with Talyn App
@parameterai

parameterai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Risk: No findings

The only change since the last review moves the frozen test fixture dates in posthog/api/test/test_ingestion_warnings_v2.py from 2026 to 2099 so ClickHouse's wall-clock TTL cannot evict the wider-window row mid-test. It is test-only; no production code, auth, validation, or transport logic changed, and it introduces no security risk.

Sentinel reviewed 1ffc43a · Review settings

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Hey @Gilbert09! 👋

It looks like your git author email on this PR isn't your @posthog.com address (owerstom@gmail.com). Since you're on the PostHog team, it's worth pointing your local git author email at your @posthog.com address. Why it matters:

  • Consistent work identity in git history — internal tooling that attributes commits to team members keys off your @posthog.com address.
  • Keeps team contributions easy to tell apart from external community ones when scanning history.

You can fix it for this repo with:

git config user.email "you@posthog.com"

Or set it globally with git config --global user.email "you@posthog.com". No need to redo this PR — just a nudge for next time. 🙂

@pr-assigner-resolver-posthog
pr-assigner-resolver-posthog Bot requested a review from a team October 2, 2026 13:12
stamphog[bot]

This comment was marked as outdated.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🤖 CI report

⚠️ Trunk lane — backend Python lane

This PR is assigned to the backend Python lane. It runs backend Python tests and may merge in parallel with PRs in other lanes.

⚠️ Duplication (Python) — 3 new duplicated blocks (worst 137 tokens)

New Python code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

First copy Second copy Lines Tokens
products/warehouse_sources/backend/temporal/data_imports/sources/acculynx/source.py:18 products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/source.py:22 14 137
products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py:57 products/warehouse_sources/backend/temporal/data_imports/sources/aws_glue_data_catalog/aws_glue_data_catalog.py:70 11 84
products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py:109 products/warehouse_sources/backend/temporal/data_imports/sources/aws_glue_data_catalog/aws_glue_data_catalog.py:113 11 70
✅ Duplication (TypeScript) — clean

New TypeScript code duplication introduced by this branch. Fails at 70+ tokens in app code, or 150+ tokens when both copies live in test files. Advisory while the gate proves itself: extract a shared helper instead of copying.

⚠️ Backend coverage — 98.0% of changed backend lines covered — 7 uncovered

🧪 Backend test coverage

Patch coverage — changed backend lines (products + core): ████████████████████ 98.0% (353 / 360)

File Patch Uncovered changed lines
products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/source.py 88.5% 78, 83, 91
products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py 97.2% 60–61, 82, 131

🤖 Agents: add a test only if an uncovered line exposes a realistic regression that existing tests miss. Otherwise explain why no new test is needed under "How did you test this code?". Gap list: the patch-coverage artifact on this run (gh run download 54609947516370 -n patch-coverage), or the coverage-data block at the end of this comment.

Per-product line coverage (touched products)
Product Coverage Lines
demo ███████████░░░░░░░░░ 53.4% 1,445 / 2,707
batch_exports ████████████████░░░░ 81.3% 21,583 / 26,561
cdp ██████████████████░░ 88.3% 4,559 / 5,164
mcp_analytics ██████████████████░░ 89.2% 5,038 / 5,651
product_tours ██████████████████░░ 89.3% 1,340 / 1,500
dashboards ██████████████████░░ 89.6% 6,924 / 7,727
notebooks ██████████████████░░ 90.2% 15,514 / 17,207
signals ██████████████████░░ 90.4% 60,188 / 66,556
cohorts ██████████████████░░ 90.5% 8,534 / 9,434
data_warehouse ██████████████████░░ 90.6% 14,375 / 15,860
streamlit_apps ██████████████████░░ 90.8% 2,684 / 2,956
managed_warehouse ██████████████████░░ 91.0% 10,252 / 11,263
data_modeling ██████████████████░░ 91.2% 10,562 / 11,584
tasks ██████████████████░░ 91.3% 79,748 / 87,306
exports ██████████████████░░ 91.7% 9,684 / 10,566
business_knowledge ██████████████████░░ 92.0% 8,472 / 9,208
engineering_analytics ██████████████████░░ 92.2% 11,497 / 12,475
today ██████████████████░░ 92.3% 999 / 1,082
early_access_features ███████████████████░ 92.6% 1,339 / 1,446
conversations ███████████████████░ 92.6% 29,225 / 31,559
stamphog ███████████████████░ 92.8% 8,109 / 8,742
canvas ███████████████████░ 92.9% 7,155 / 7,703
approvals ███████████████████░ 93.0% 3,974 / 4,271
mcp_registry ███████████████████░ 93.1% 1,670 / 1,794
notifications ███████████████████░ 93.2% 1,144 / 1,228
error_tracking ███████████████████░ 93.3% 16,389 / 17,573
surveys ███████████████████░ 93.4% 6,644 / 7,113
autoresearch ███████████████████░ 93.4% 8,837 / 9,457
slack_app ███████████████████░ 93.7% 14,611 / 15,600
context_layer ███████████████████░ 93.8% 3,415 / 3,639
web_analytics ███████████████████░ 93.9% 23,680 / 25,229
billing_alerts ███████████████████░ 94.1% 2,094 / 2,226
mcp_store ███████████████████░ 94.3% 8,959 / 9,501
alerts ███████████████████░ 94.7% 9,319 / 9,844
wizard ███████████████████░ 94.7% 6,150 / 6,496
workflows ███████████████████░ 94.7% 15,187 / 16,034
ai_observability ███████████████████░ 94.7% 26,034 / 27,482
reminders ███████████████████░ 94.8% 760 / 802
review_hog ███████████████████░ 95.0% 11,750 / 12,362
annotations ███████████████████░ 95.1% 817 / 859
endpoints ███████████████████░ 95.1% 9,234 / 9,706
customer_analytics ███████████████████░ 95.2% 26,116 / 27,428
marketing_analytics ███████████████████░ 95.3% 19,450 / 20,413
posthog_ai ███████████████████░ 95.4% 2,530 / 2,653
actions ███████████████████░ 95.5% 756 / 792
logs ███████████████████░ 95.5% 15,468 / 16,200
experiments ███████████████████░ 95.5% 33,000 / 34,548
data_catalog ███████████████████░ 95.5% 4,401 / 4,606
tracing ███████████████████░ 95.6% 3,536 / 3,699
replay_vision ███████████████████░ 95.6% 29,389 / 30,727
growth ███████████████████░ 95.7% 11,381 / 11,888
skills ███████████████████░ 95.8% 6,972 / 7,274
messaging ███████████████████░ 95.9% 3,834 / 3,999
product_analytics ███████████████████░ 96.0% 28,521 / 29,696
revenue_analytics ███████████████████░ 96.4% 1,889 / 1,959
user_interviews ███████████████████░ 96.5% 2,870 / 2,974
feature_flags ███████████████████░ 96.6% 27,119 / 28,060
access_control ███████████████████░ 96.7% 7,739 / 8,007
warehouse_sources ███████████████████░ 97.3% 473,734 / 486,821
data_quality ████████████████████ 97.5% 7,701 / 7,895
metrics ████████████████████ 98.0% 4,252 / 4,338
analytics_platform ████████████████████ 98.3% 2,784 / 2,833
pulse ████████████████████ 98.5% 2,046 / 2,078
live_debugger ████████████████████ 99.2% 626 / 631

Report-only. Patch coverage = changed backend lines covered vs origin/master. Sorted lowest first.
Known gaps: lines covered only by Temporal tests show as uncovered; core line numbers may drift if master changed the same file.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
🧰 Additional context used
📚 Code guidelines (8)
.agents/security.md — configured
.agents/skills/sending-notifications/SKILL.md — configured
docs/published/handbook/engineering/type-system.md — configured
.agents/skills/writing-tests/SKILL.md — configured
docs/internal/person-data-access.md — configured
.agents/skills/adopting-generated-api-types/SKILL.md — configured
.claude/commands/conventions.md — configured
.agents/skills/writing-code-comments/SKILL.md — configured
📝 Walkthrough

Walkthrough

Adds an AWS Compute Optimizer source for six recommendation datasets. The source sends SigV4-signed requests, normalizes responses, validates credentials and enrollment, and supports resumable pagination with saved state. It also defines endpoint schemas and configuration fields, and adds request, pagination, and validation tests. Ingestion warning tests now use July 2099 timestamps and corresponding time bounds.

Priority: ➖ Normal

Merge Risk: 🟡 Moderate · up to 1ffc4

AWS Compute Optimizer connections in GovCloud will fail, and malformed service errors can cause unexpected import failures. Address these risks before merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1ffc4

The integration uses constrained AWS endpoints, signed requests, credential-redaction inputs and existing ingestion lifecycle controls. No introduced security flaw was established. Remaining uncertainty concerns credential handling beyond the connector and recovery under concurrent attempts or downstream failures.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The newly exercised authority is outbound AWS recommendation retrieval using supplied credentials and import into the associated warehouse pipeline. Effective upstream data exposure depends on those credentials' AWS permissions; the connector does not itself provision IAM authority.

Trust Boundaries and Controls

  • observed — User-configured region text must match a restricted region pattern. The destination uses a fixed Compute Optimizer HTTPS hostname under an AWS domain, rather than a user-supplied URL, and signed requests disable redirects.
  • observed — Account-level validation tolerates denial of GetEnrollmentStatus, but table-specific validation reports denied access. Subsequent data retrieval still calls the selected AWS operation with the supplied credentials; this validation fallback does not grant AWS permissions.
  • observed — The shared observer forwards credential-redaction values to sample capture and emits request metadata rather than request bodies in ordinary logs. Sample capture requires a job context; its complete masking implementation and access controls were not established in this review.

Resilience and Maintainability Implications

  • observed — Checkpoint keys include team and job identity, and the caller supplies the workflow run ID as job_id. Persisted checkpoints expire after 24 hours. This establishes the visible state partitioning, but does not establish fencing between overlapping attempts of the same run.
  • observed — The connector closes its HTTP client on pagination and validation exit paths. Completed-state cleanup is delegated to the pipeline completion callback rather than performed when the iterator closes, preserving recovery state during interrupted extraction.
🚥 Pre-merge checks | ✅ 1
✅ Passed checks (1 passed)
Check name Status Explanation
Description check ✅ Passed The description is complete and stand-alone. It explains the problem, user-visible changes, testing scope and limits, release status, notifications, and documentation follow-up. It does not mention th…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Quiet mode is enabled, so only the most important comments were posted inline. Other review comments are grouped below.

🟡 Other comments (1)
products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py-132-134 (1)

132-134: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Guard the shape of the errors element.

result["errors"][0] assumes the element is a dict. If AWS returns a non-dict element, error.get raises AttributeError. That error escapes the except (requests.RequestException, ValueError) handler in validate_credentials, and the user gets no actionable message. Check the type and fall back to PartialResponseError.

Proposed fix
-            error = result["errors"][0]
-            raise AwsComputeOptimizerError(str(error.get("code") or "PartialResponseError"))
+            errors = result["errors"]
+            error = errors[0] if isinstance(errors, list) and errors else None
+            code = error.get("code") if isinstance(error, dict) else None
+            raise AwsComputeOptimizerError(str(code or "PartialResponseError"))

Source: Learnings


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 16337112-b5ec-4a1c-a9fe-4eb4d2f5604b

📥 Commits

Reviewing files that changed from the base of the PR and between d8d5ba9 and 2a4855d.

📒 Files selected for processing (7)
  • products/warehouse_sources/backend/temporal/data_imports/sources/SOURCES.md
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/canonical_descriptions.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/settings.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/source.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/tests/test_aws_compute_optimizer.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/generated_configs/awscomputeoptimizer.py

Limit details: You’ve used all 12 included reviews currently available.

@trunk-io

trunk-io Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Static Badge   Static Badge   Static Badge

View Full Report ↗︎ ⋅ Docs

@stamphog
stamphog Bot dismissed their stale review October 2, 2026 13:57

A new stamphog review started for this PR — the fresh verdict replaces this approval.

stamphog[bot]

This comment was marked as outdated.

Copy link
Copy Markdown
Member Author

CI is fully green and there are no unresolved review threads or merge conflicts. The remaining merge gate is approval from Team Warehouse Sources; please review and approve when ready.

🦉 via talyn.dev

Rebase the AWS Compute Optimizer source onto master and preserve the source catalog changes from both branches.
@Gilbert09
Gilbert09 force-pushed the tom/dwh-source-aws_compute_optimizer branch from 6fe56eb to 14b73a1 Compare October 2, 2026 15:03
@stamphog
stamphog Bot dismissed their stale review October 2, 2026 15:03

A new stamphog review started for this PR — the fresh verdict replaces this approval.

stamphog[bot]

This comment was marked as outdated.

Re-run CI after the duplication lint job was cancelled without logs. Includes the conflict resolution that preserves both source catalog updates.
Retry CI after an unrelated ingestion warnings test failed with an inconsistent result count. The AWS Compute Optimizer source tree is unchanged.

Copy link
Copy Markdown
Member Author

CI retry note: the prior run failed only in posthog/api/test/test_ingestion_warnings_v2.py::TestIngestionWarningsV2API::test_time_range_bounds_results (assert 3 == 4). This PR does not add or edit that file; the retry produced no failing checks.

🦉 via talyn.dev

Copy link
Copy Markdown
Member Author

/trunk merge

Move the frozen ingestion-warning fixture dates far enough into the future that ClickHouse's wall-clock TTL cannot remove the wider-window row during the test run.
@stamphog
stamphog Bot dismissed their stale review October 2, 2026 15:58

A new stamphog review started for this PR — the fresh verdict replaces this approval.

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

Additive new warehouse source by an owning-team author, with thorough tests, region input validation, no redirects, and secrets redacted in the tracked session. The unrelated ingestion-warnings test date shift is test-only and harmless.

  • Author wrote 37% of the modified lines and has 104 merged PRs in these paths (familiarity MODERATE).
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 522L, 5F substantive, 889L/8F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1d-complex (889L, 8F, two-areas, feat)
stamphog 2.3.1 .stamphog/policy.yml @ 1ffc43a · reviewed head 1ffc43a

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to GitHub limitations.

⚠️ Outside diff range comments (1)

🟠 Major · Use the FIPS endpoint for GovCloud regions. · aws_compute_optimizer.py:76-105

products/warehouse_sources/backend/temporal/data_imports/sources/aws_compute_optimizer/aws_compute_optimizer.py:76-105
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Use the FIPS endpoint for GovCloud regions.

For us-gov-*, AWS exposes Compute Optimizer through compute-optimizer-fips.{region}.amazonaws.com. The client currently uses the non-FIPS hostname. Credential validation and recommendation syncs can fail for GovCloud users. Keep the SigV4 service and region unchanged.

Suggested fix
-        self.url = f"https://compute-optimizer.{self.region}.{suffix}/"
+        endpoint_prefix = "compute-optimizer-fips" if self.region.startswith("us-gov-") else "compute-optimizer"
+        self.url = f"https://{endpoint_prefix}.{self.region}.{suffix}/"

Update the GovCloud test expectation to use the same FIPS hostname.


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 264c39b3-4738-44fc-a5c2-a29aba8ad042

📥 Commits

Reviewing files that changed from the base of the PR and between 939b93d and 1ffc43a.

📒 Files selected for processing (1)
  • posthog/api/test/test_ingestion_warnings_v2.py

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 0 remain after this review.

Copy link
Copy Markdown
Member Author

Reviewed the latest automated concerns. GovCloud is already supported: us-gov-west-1 resolves to compute-optimizer.us-gov-west-1.amazonaws.com, is SigV4-signed for that region, and has explicit test coverage. The partial-error path follows AWS's modeled errors list and intentionally fails the page before checkpointing; handling arbitrary malformed nested shapes would be speculative and is not warranted here. The recurring ingestion-warning failure was caused by ClickHouse's wall-clock 90-day TTL expiring the frozen July 2026 fixture, so the fixture is now safely future-dated; the latest CI run is fully green.

🦉 via talyn.dev

Copy link
Copy Markdown
Member Author

/trunk merge

1 similar comment

Copy link
Copy Markdown
Member Author

/trunk merge

andrewm4894 added a commit that referenced this pull request Oct 2, 2026
…v2 api test

#110795, queued ahead of this PR, fixes the same TTL date bomb by moving the fixtures to 2099, and the earlier relative-date version here conflicted with it in the merge queue. Use the identical file contents so the two PRs merge cleanly in either order.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 7cd74fea-b97a-44c0-a272-3a41767003e2
@trunk-io
trunk-io Bot merged commit a92b32b into master Oct 2, 2026
271 checks passed
@trunk-io
trunk-io Bot deleted the tom/dwh-source-aws_compute_optimizer branch October 2, 2026 18:02
@deployment-status-posthog

Copy link
Copy Markdown

Deploy status

Environment Status Deployed At Workflow
dev ✅ Deployed 2026-10-02 18:25 UTC Run
prod-us ⏳ Pending
prod-eu ⏳ Pending

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stamphog Request AI approval (no full review)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant