Skip to main content

One post tagged with "reliability"

View All Tags

One panic shouldn't kill the scan: isolating rules with catch_unwind

· 5 min read
Founder, Dragon Fractal · ex-AWS engineer

Cloud Cost Analyzer runs 92 rules against your cloud account in a single scan. A rule is a real unit of work: it pulls a resource's config and metrics, evaluates them against a cost model, and maybe emits a finding. They're independent, and every one of them leans on libraries I don't control — cloud SDKs, response parsers, date and math crates.

Any of that can meet an input it didn't anticipate and panic: an unwrap() that couldn't fail until some resource shape I'd never seen, an index out of bounds deep in a dependency, an overflow on a field that's normally small. Usually it isn't "someone wrote bad code" — it's a library panicking on an edge case nobody dependency-audited for.

The question that matters isn't "will a rule panic." It's "when rule #57 panics, do I lose the other 91 and the whole scan?" A cost report that dies two-thirds through because one rule hit one weird EBS volume is worse than useless.