• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

Logflare / logflare / 35025521771-1
83%

Build:
DEFAULT BRANCH: main
Ran 15 Sep 2026 09:38PM UTC
Jobs 1
Files 462
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Sep 2026 09:25PM UTC coverage: 82.613% (+0.1%) from 82.497%
35025521771-1

push

github

web-flow
feat(repo): authenticate PostgreSQL with AWS RDS IAM tokens (#3903)

* feat(repo): authenticate read replicas with RDS IAM tokens

A replica URI may now carry `auth=iam` instead of a password. Each connection
then authenticates with a freshly minted RDS IAM token.

Per connection is the whole point rather than an implementation detail. The
entry is parsed once at boot and a token lasts 15 minutes, so anything minted at
pool start would leave the pool unable to reconnect after that window.
DBConnection's `:configure` runs before every connect attempt, which is exactly
the hook that shape needs. Any inherited configure hook runs first so unrelated
dynamic connection options remain intact.

This is what an AWS endpoint requires when its database role holds `rds_iam`:
per AWS, that grant makes IAM authentication *replace* password authentication
for the role rather than supplement it, so no password can work.

The signing region comes from the AWS-issued
`*.<region>.rds.amazonaws.com` hostname. Aliases and tunnel endpoints are
rejected because AWS validates the signed host. Note ExAws is configured with
`:rds` while the SigV4 signing service is `rds-db` -- ExAws has no `rds-db`
service and raises trying to build a host for one; only the signing name needs
to be `rds-db`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(repo): harden RDS IAM replica connections

* docs(config): label read replica environment setting

* refactor(repo): share AWS IAM connection configuration

* fix(repo): start ExAws before IAM migrations

* fix(repo): preserve replica TLS options

* fix(repo): omit empty AWS session tokens

* fix(repo): inherit TLS for password replicas

* fix(repo): enforce IAM TLS after configure callbacks

* fix(repo): apply IAM auth to direct database clients

* fix(repo): align epgsql IAM connection identity

* fix(repo): preserve inherited replica TLS identity

* fix(repo): bound cluster strategy connection pool

* test(repo)... (continued)

126 of 143 new or added lines in 6 files covered. (88.11%)

1 existing line in 1 file now uncovered.

15090 of 18266 relevant lines covered (82.61%)

1673.18 hits per line

Uncovered Changes

Lines Coverage ∆ File
10
77.27
lib/logflare/repo/connection_options.ex
6
91.43
lib/logflare/repo/aws_iam.ex
1
94.37
11.03% lib/logflare/repo/replicas.ex

Coverage Regressions

Lines Coverage ∆ File
1
2.86
2.86% lib/logflare/cluster/postgres_strategy.ex
Jobs
ID Job ID Ran Files Coverage
1 35025521771-1.1 15 Sep 2026 09:38PM UTC 462
82.61
GitHub Action Run
Source Files on build 35025521771-1
  • Tree
  • List 462
  • Changed 6
  • Source Changed 4
  • Coverage Changed 6
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35025521...
  • d1a6054d on github
  • Prev Build on main (#34805346...)
  • Next Build on main (#35038795...)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc