Skip to content

fix(iam): keep SAML/OIDC providers unique and update CloudFormation providers in place - #2564

Merged
vieiralucas merged 2 commits into
mainfrom
fix/iam-partition-gaps
Sep 27, 2026
Merged

vieiralucas merged 2 commits into
mainfrom
fix/iam-partition-gaps

Conversation

@vieiralucas

@vieiralucas vieiralucas commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

Follow-up to #2556.

IAM API

  • CreateSAMLProvider had no duplicate check: a second create with a name in use silently replaced the existing provider's metadata, tags and creation date. It now fails with EntityAlreadyExists (declared in the model).
  • CreateOpenIDConnectProvider deduplicated by full ARN, which since fix(iam): derive every IAM ARN's partition from the region #2556 carries the request region's partition, so the same URL could be registered twice from aws and aws-cn regions. It now deduplicates by URL. The check (IamState::has_oidc_provider_for) and the scheme/query split (oidc_url_parts) are shared with CloudFormation.

CloudFormation (AWS::IAM::OIDCProvider, AWS::IAM::SAMLProvider)

  • Reject a duplicate URL/name instead of taking over a provider another stack or the API created (deleting the second stack used to remove the first owner's provider).
  • OIDC: store the URL without its scheme and build the ARN without the query string, as the API does. GetOpenIDConnectProvider on a stack-created provider now returns accounts.example.com, not https://accounts.example.com, matching the API path and AWS's documented response. The old e2e expectation is updated accordingly.
  • In-place updates: ClientIdList, ThumbprintList, SamlMetadataDocument and Tags update without replacement, as in CloudFormation. Previously every change went through delete-then-create, which under UpdateReplacePolicy: Retain would collide with the retained provider. A new Url, or a changed/removed Name, still replaces.
  • Template Tags are stored instead of dropped.
  • SAML provider, service-linked role and virtual MFA device ARNs use the stack region's partition.

Known, pre-existing and out of scope

  • Replacement is delete-then-create for every resource type, so changing a provider's Url/Name to one that already exists deletes the old provider before the create fails; real CloudFormation creates the replacement first.
  • The CFN OIDC provisioner doesn't run the API's input validation.

No surface changes: no new API, flag or SDK field; default-region output unchanged except the CFN OIDC Url shape above.

Test plan

  • Unit: oidc_provider_url_is_unique_across_partitions, saml_provider_name_is_unique (IAM); iam_entities_provisioned_in_china_region_use_aws_cn_partition, iam_oidc_provider_matches_api_shape_and_is_unique_per_url, iam_oidc_and_saml_providers_update_in_place (CFN, covers Retain, in-place, Url/Name replacement, query-string URL refresh). Verified failing on main.
  • cargo test -p fakecloud-iam (558), -p fakecloud-cloudformation (465), -p fakecloud-core (331).
  • e2e: iam, multi_account, cloudformation_iam, cloudformation_iam_extras.
  • Conformance: IAM SAML/OIDC tests 4/4.
  • cargo clippy --workspace --all-targets -- -D warnings clean.

Summary by cubic

Makes IAM SAML/OIDC providers unique per account and aligns CloudFormation provisioning with the IAM API.

Behavior changes

  • CreateSAMLProvider now fails with EntityAlreadyExists instead of silently replacing an existing provider's metadata. CreateOpenIDConnectProvider now deduplicates by URL instead of ARN, so the same URL can no longer be registered from both aws and aws-cn partitions.
  • AWS::IAM::OIDCProvider and AWS::IAM::SAMLProvider reject duplicate URLs/names instead of taking over providers another stack or the API created.
  • OIDC providers store the URL without its scheme and derive the ARN without the query string, matching the API. GetOpenIDConnectProvider now returns accounts.example.com for stack-created providers, not https://accounts.example.com.
  • ClientIdList, ThumbprintList, SamlMetadataDocument, and Tags update in place; a new URL or a changed/removed name still triggers replacement. Previously all changes went through delete-then-create, which collided with retained providers under UpdateReplacePolicy: Retain. Template tags are now stored instead of dropped.
  • SAML provider, service-linked role, and virtual MFA device ARNs use the stack region's partition.

Known pre-existing limitation: replacement is delete-then-create, so changing a provider to an already-used URL/name deletes the old provider before create fails.

Written for commit af979a2. Summary will update on new commits.

Review in cubic

…account

CreateSAMLProvider had no duplicate check: a second create with a name
already in use silently replaced the existing provider's metadata, tags
and creation date. It now fails with EntityAlreadyExists, which the model
declares for the operation.

CreateOpenIDConnectProvider checked for a duplicate by full ARN. Since
ARNs carry the request region's partition, the same URL could be
registered twice from regions in different partitions. It now checks the
URL. The check and the scheme/query splitting live in
IamState::has_oidc_provider_for and oidc_url_parts so CloudFormation
shares them.
…pdate them in place

- AWS::IAM::OIDCProvider and AWS::IAM::SAMLProvider reject a duplicate URL
  or name instead of taking over a provider another stack or the API
  created (deleting that stack then removed the other owner's provider).
- OIDC providers store the URL without its scheme and build the ARN
  without the query string, as CreateOpenIDConnectProvider does, so a
  stack-created provider reads back the same as an API-created one.
- Both update in place: ClientIdList, ThumbprintList, SamlMetadataDocument
  and Tags change without replacement, as in CloudFormation. Previously
  every change went through delete-then-create, which under
  UpdateReplacePolicy Retain collides with the retained provider. A new
  Url, or a changed or removed Name, still replaces.
- Both creates store the template's Tags instead of dropping them.
- SAML provider, service-linked role and virtual MFA device ARNs take the
  stack region's partition like the other IAM resources.
@vieiralucas
vieiralucas requested a lite review from Copilot September 25, 2026 20:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@vieiralucas
vieiralucas merged commit 6b0237f into main Sep 27, 2026
157 checks passed
@vieiralucas
vieiralucas deleted the fix/iam-partition-gaps branch September 27, 2026 22:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants