Skip to content

fix(objectstore): pass ExternalId when assuming the S3 role (CSA-641) - #2800

Draft
ashish-atlan wants to merge 1 commit into
mainfrom
ashishdesai/csa-641
Draft

ashish-atlan wants to merge 1 commit into
mainfrom
ashishdesai/csa-641

Conversation

@ashish-atlan

Copy link
Copy Markdown
Collaborator

Summary

S3Sync assumed the customer's IAM role with only RoleArn and RoleSessionName. Any role whose trust policy has an sts:ExternalId condition rejects that call with a generic 403 AccessDenied. That blocks Asset Import and Asset Export from customer S3 buckets set up this way.

Changes:

  • S3Credential reads an optional aws_external_id from the credential's extra. This is the same key the Athena, Glue, SMUS and S3 crawler forms use, and the one used by the Generic Miner fix (atlan-generic-miner-app#10).
  • S3Sync takes an optional externalId and sets it on the AssumeRoleRequest only when it is not blank. Request building moved into S3Sync.buildAssumeRoleRequest so it can be unit-tested without calling STS.
  • All four S3Sync call sites in Utils pass it through: getInputFile, both getInputFiles branches, and uploadOutputFile.

Impact

  • Credentials without an External ID send exactly the same request as before.
  • Every package built on package-toolkit-runtime gets the new optional parameter. The value only reaches a tenant once that package's marketplace template points at a rebuilt image.
  • The UI field is added separately in marketplace-packages, in the shared csa-connectors-objectstore configmap.
  • 🔒 This touches credential handling. Please give it a security review. The External ID value is never logged.

Related

Test plan

  • New S3ExternalIdTest: 4 cases. The ID is parsed from the credential, it defaults to empty, it is set when provided, and it is left off when blank.
  • :package-toolkit:runtime:test: 83 tests pass.
  • asset-import and asset-export-basic compile.
  • Branch images built through the Merge workflow and tested on a staging tenant with a role that requires an External ID.

🤖 Generated with Claude Code

S3Sync assumed the customer's IAM role with only RoleArn and
RoleSessionName. Roles whose trust policy has an sts:ExternalId
condition rejected the call with a generic 403 AccessDenied, which
blocked Asset Import and Asset Export from customer S3 buckets.

S3Credential now reads an optional aws_external_id from the
credential's extra (same key as the Athena, Glue and Generic Miner
forms) and S3Sync sets it on the AssumeRoleRequest only when it is
non-blank. All four S3Sync call sites in Utils pass it through.
Credentials without an External ID behave exactly as before.

Refs: CSA-641, CSA-642, CSA-526

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: ashish-atlan <ashish.desai@atlan.com>
@linear

linear Bot commented Oct 1, 2026

Copy link
Copy Markdown

CSA-641

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant