Repository navigation
fix(objectstore): pass ExternalId when assuming the S3 role (CSA-641) - #2800
Draft
ashish-atlan wants to merge 1 commit into
Draft
ashish-atlan wants to merge 1 commit into
ashish-atlan wants to merge 1 commit into
Conversation
S3Sync assumed the customer's IAM role with only RoleArn and RoleSessionName. Roles whose trust policy has an sts:ExternalId condition rejected the call with a generic 403 AccessDenied, which blocked Asset Import and Asset Export from customer S3 buckets. S3Credential now reads an optional aws_external_id from the credential's extra (same key as the Athena, Glue and Generic Miner forms) and S3Sync sets it on the AssumeRoleRequest only when it is non-blank. All four S3Sync call sites in Utils pass it through. Credentials without an External ID behave exactly as before. Refs: CSA-641, CSA-642, CSA-526 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: ashish-atlan <ashish.desai@atlan.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
S3Syncassumed the customer's IAM role with onlyRoleArnandRoleSessionName. Any role whose trust policy has ansts:ExternalIdcondition rejects that call with a generic 403 AccessDenied. That blocks Asset Import and Asset Export from customer S3 buckets set up this way.Changes:
S3Credentialreads an optionalaws_external_idfrom the credential'sextra. This is the same key the Athena, Glue, SMUS and S3 crawler forms use, and the one used by the Generic Miner fix (atlan-generic-miner-app#10).S3Synctakes an optionalexternalIdand sets it on theAssumeRoleRequestonly when it is not blank. Request building moved intoS3Sync.buildAssumeRoleRequestso it can be unit-tested without calling STS.S3Synccall sites inUtilspass it through:getInputFile, bothgetInputFilesbranches, anduploadOutputFile.Impact
package-toolkit-runtimegets the new optional parameter. The value only reaches a tenant once that package's marketplace template points at a rebuilt image.marketplace-packages, in the sharedcsa-connectors-objectstoreconfigmap.Related
Test plan
S3ExternalIdTest: 4 cases. The ID is parsed from the credential, it defaults to empty, it is set when provided, and it is left off when blank.:package-toolkit:runtime:test: 83 tests pass.asset-importandasset-export-basiccompile.🤖 Generated with Claude Code