feat(custom-resources): support external IDs when assuming a role with a custom resource#33965
Closed
crowecawcaw wants to merge 1 commit intoaws:mainfrom
Closed
feat(custom-resources): support external IDs when assuming a role with a custom resource#33965crowecawcaw wants to merge 1 commit intoaws:mainfrom
crowecawcaw wants to merge 1 commit intoaws:mainfrom
Conversation
aws-cdk-automation
previously requested changes
Mar 28, 2025
✅ Updated pull request passes all PRLinter validations. Dismissing previous PRLinter review.
Signed-off-by: Stephen Crowe <6042774+crowecawcaw@users.noreply.github.com>
be0c4d4 to
7201c02
Compare
aws-cdk-automation
requested changes
Apr 1, 2025
Collaborator
aws-cdk-automation
left a comment
There was a problem hiding this comment.
The pull request linter fails with the following errors:
❌ Features must contain a change to an integration test file and the resulting snapshot.
If you believe this pull request should receive an exemption, please comment and provide a justification. A comment requesting an exemption should contain the text Exemption Request. Additionally, if clarification is needed, add Clarification Request to a comment.
Collaborator
AWS CodeBuild CI Report
Powered by github-codebuild-logs, available on the AWS Serverless Application Repository |
Contributor
|
Comments on closed issues and PRs are hard for our team to see. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reason for this change
We want to use the
AwsCustomConstructfor making calls in another account while assuming a role. As a security mitigation, our cross account role requires an external ID. This change allows theAwsCustomConstructto optionally use external IDs.Description of changes
Add
assumedRoleExternalIdas an optionalAwsCustomConstructparameter and use it when making cross-account calls.Describe any new or updated permissions being added
None
Description of how you validated changes
Unit tests and snapshot comparisions.
Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license