Skip to content

Conversation

@gmarciani
Copy link
Contributor

Description of changes

Prevent duplicate security group rules in shared storage security group.

The deduplication is beneficial because when duplicate rules are requested, the CFN handler responsible for their creation goes into a path that is more susceptible to eventual consistency issue.
When such issue occur, cluster creation may fail.

As part of this change, we also applied the same network access scope down we had for login nodes to also head node and compute node.
Extending the scope down made the deduplication change easier and it is also beneficial in terms of security posture.

Tests

THIS IS A DRAFT UNDER TESTING

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch 2 times, most recently from 5a56e10 to 6bf3fa5 Compare January 9, 2026 23:20
… security group.

The deduplication is beneficial because when duplicate rules are requested,
the CFN handler responsible for their creation goes into a path
that is more susceptible to eventual consistency issue.
When such issue occur, cluster creation may fail.

As part of this change, we also applied the same network access
scope down we had for login nodes to also head node and compute node.
Extending the scope down made the deduplication change easier
and it is also beneficial in terms of security posture.
@gmarciani gmarciani force-pushed the wip/mgiacomo/3150/fix-duplicate-sg-rule-0109-1 branch from 6bf3fa5 to 1101295 Compare January 9, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant