Summary
parseServices maps each --services name through a lookup table and, on a miss, logs one warning to stderr and drops the name. The run then proceeds with the remaining services. Only a run where every name is unrecognised reaches the "No valid services specified" fatal. External input is not parsed into the enum at the boundary with an error on unknown, which is the project's standing rule.
Location
cmd/main.go:219 at 3c0f8ac
cmd/multi_service.go:94-96 (the only guard, reached when the result is empty)
Failure scenario
cudly --services rds,elasticahe --purchase (typo). ElastiCache is dropped with one log line amid the wizard's decorated stdout, and the run purchases for RDS alone. The operator believes both services were covered.
Evidence
if service, ok := serviceMap[key]; ok {
add(service)
} else {
log.Printf("Warning: Unknown service '%s', skipping", name)
}
Suggested fix
Return an error from parseServices naming the unrecognised value and the valid set, and call it from validateFlags so the run never starts.
Found by the 2026-09-02 codebase audit, finding A10-012, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
parseServices maps each --services name through a lookup table and, on a miss, logs one warning to stderr and drops the name. The run then proceeds with the remaining services. Only a run where every name is unrecognised reaches the "No valid services specified" fatal. External input is not parsed into the enum at the boundary with an error on unknown, which is the project's standing rule.
Location
cmd/main.go:219at 3c0f8accmd/multi_service.go:94-96(the only guard, reached when the result is empty)Failure scenario
cudly --services rds,elasticahe --purchase(typo). ElastiCache is dropped with one log line amid the wizard's decorated stdout, and the run purchases for RDS alone. The operator believes both services were covered.Evidence
Suggested fix
Return an error from parseServices naming the unrecognised value and the valid set, and call it from validateFlags so the run never starts.
Found by the 2026-09-02 codebase audit, finding
A10-012, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.