aws-cloudformation / aws-cloudformation/cloudformation-cli-python-plugin

OOTB generated python CF resource cannot be used with cfn test

Aberta
#247 2 comentários 1 reação 0 responsáveis Ver no GitHub
investigating
Linguagem predominante
Python
Estrelas
107
Forks
46
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

Repro:

- Install latest cloudformation-cli
- Install master branch of this repo
- Generate a new resource type - in my example I used `python3.9`
- run `cfn submit --dry-run`
- run `sam build`
- in new terminal run `sam local start-lambda`
- run just one contract test -`cfn test -- -k contract_create_delete`
- Error from cryptography library:
- `Unable to import module 'dd_dd_test1.handlers': cannot import name 'ObjectIdentifier' from 'cryptography.hazmat.bindings._rust' (unknown location)`

Environment:
- cfn version - `cfn 0.2.28`
- SAM version - `SAM CLI, version 1.66.0`
- Operating System - `macOS Monterey - 12.3.1`
- Architecture - Apple M1 Pro (arm64)
- plugin version - `cloudformation-cli-python-plugin @ git+https://github.com/aws-cloudformation/cloudformation-cli-python-plugin.git@fad3b0740a76c7bad0be18b08cb46f6e22973bde` (master as of 01/17/2023)
- requirements.txt (generated) - `cloudformation-cli-python-lib>=2.1.9`
- Resolved cryptography library - `cryptography 39.0.0`

Research:
- User having issues with python3.8 in lambda environment - https://stackoverflow.com/questions/75129142/aws-lambda-cannot-import-name-objectidentifier-from-cryptography-hazmat-b
- `aws-encryption-sdk` only [requires 3.4.0](https://github.com/aws/aws-encryption-sdk-python/blob/master/requirements.txt#L2) or above currently. This is used [here](https://github.com/aws-cloudformation/cloudformation-cli-python-plugin/blob/master/src/cloudformation_cli_python_lib/cipher.py#L4). And defined [here](https://github.com/aws-cloudformation/cloudformation-cli-python-plugin/blob/master/src/setup.py#L18)

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Reproduza a falha seguindo as etapas listadas para cloudformation-cli, SAM, macOS arm64 e o recurso gerado, terminando com cfn test -- -k contract_create_delete. Em seguida, inspecione src/cloudformation_cli_python_lib/cipher.py, src/setup.py e o requirements.txt gerado em relação às restrições de aws-encryption-sdk e cryptography. A tarefa estará concluída quando o recurso gerado puder executar o teste de contrato sem o erro de importação de ObjectIdentifier.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
aws, python
Domínio
testing, tooling
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
38/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.