fix(aws service): Propagate FIPS endpoint setting to STS AssumeRole clients#25232
Open
hligit wants to merge 1 commit intovectordotdev:masterfrom
Open
fix(aws service): Propagate FIPS endpoint setting to STS AssumeRole clients#25232hligit wants to merge 1 commit intovectordotdev:masterfrom
hligit wants to merge 1 commit intovectordotdev:masterfrom
Conversation
5ad1f7d to
b80de18
Compare
…lients When AWS_USE_FIPS_ENDPOINT=true is configured, Vector now correctly uses FIPS endpoints for STS operations (e.g., sts-fips.<region>.amazonaws.com) in addition to the primary service client. Also bumps aws-config from 1.8.13 to 1.8.16. Fixes vectordotdev#18382
b80de18 to
5272843
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When
AWS_USE_FIPS_ENDPOINT=trueis set (oruse_fips_endpoint=truein an AWS config/profile file), Vector applies FIPS endpoints to the primary service client (e.g., S3, Kinesis) but does not propagate the setting to the STS client used forAssumeRolecredential operations. This causes STS calls to go tosts.<region>.amazonaws.cominstead ofsts-fips.<region>.amazonaws.com, breaking environments that require all AWS traffic to use FIPS-validated endpoints.Also bumps
aws-configfrom 1.8.13 to 1.8.16. This version bump is required for the fix:ProviderConfig::with_use_fips()waspub(crate)in 1.8.13 and was madepubin 1.8.16 via smithy-rs#4551, which is precisely what allows external consumers (like Vector) to propagate the FIPS setting to credential providers.Vector configuration
Run with:
AWS_USE_FIPS_ENDPOINT=true vector --config vector.yamlHow did you test this PR?
strace -f -e trace=networkwithAWS_USE_FIPS_ENDPOINT=true, verifying that STS DNS lookups resolvests-fips.us-east-1.amazonaws.cominstead ofsts.us-east-1.amazonaws.com.AWS_USE_FIPS_ENDPOINT=falseas a control, confirming regular STS endpoints are used.Change Type
Is this a breaking change?
Does this PR include user facing changes?
no-changeloglabel to this PR.References
Closes #18382
Notes
@vectordotdev/vectorto reach out to us regarding this PR.pre-pushhook, please see this template.make fmtmake check-clippy(if there are failures it's possible some of them can be fixed withmake clippy-fix)make testgit merge origin masterandgit push.Cargo.lock), pleaserun
make build-licensesto regenerate the license inventory and commit the changes (if any). More details on the dd-rust-license-tool.