fix(iam): keep SAML/OIDC providers unique and update CloudFormation providers in place - #2564
Merged
Merged
Conversation
…account CreateSAMLProvider had no duplicate check: a second create with a name already in use silently replaced the existing provider's metadata, tags and creation date. It now fails with EntityAlreadyExists, which the model declares for the operation. CreateOpenIDConnectProvider checked for a duplicate by full ARN. Since ARNs carry the request region's partition, the same URL could be registered twice from regions in different partitions. It now checks the URL. The check and the scheme/query splitting live in IamState::has_oidc_provider_for and oidc_url_parts so CloudFormation shares them.
…pdate them in place - AWS::IAM::OIDCProvider and AWS::IAM::SAMLProvider reject a duplicate URL or name instead of taking over a provider another stack or the API created (deleting that stack then removed the other owner's provider). - OIDC providers store the URL without its scheme and build the ARN without the query string, as CreateOpenIDConnectProvider does, so a stack-created provider reads back the same as an API-created one. - Both update in place: ClientIdList, ThumbprintList, SamlMetadataDocument and Tags change without replacement, as in CloudFormation. Previously every change went through delete-then-create, which under UpdateReplacePolicy Retain collides with the retained provider. A new Url, or a changed or removed Name, still replaces. - Both creates store the template's Tags instead of dropping them. - SAML provider, service-linked role and virtual MFA device ARNs take the stack region's partition like the other IAM resources.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #2556.
IAM API
CreateSAMLProviderhad no duplicate check: a second create with a name in use silently replaced the existing provider's metadata, tags and creation date. It now fails withEntityAlreadyExists(declared in the model).CreateOpenIDConnectProviderdeduplicated by full ARN, which since fix(iam): derive every IAM ARN's partition from the region #2556 carries the request region's partition, so the same URL could be registered twice fromawsandaws-cnregions. It now deduplicates by URL. The check (IamState::has_oidc_provider_for) and the scheme/query split (oidc_url_parts) are shared with CloudFormation.CloudFormation (
AWS::IAM::OIDCProvider,AWS::IAM::SAMLProvider)GetOpenIDConnectProvideron a stack-created provider now returnsaccounts.example.com, nothttps://accounts.example.com, matching the API path and AWS's documented response. The old e2e expectation is updated accordingly.ClientIdList,ThumbprintList,SamlMetadataDocumentandTagsupdate without replacement, as in CloudFormation. Previously every change went through delete-then-create, which underUpdateReplacePolicy: Retainwould collide with the retained provider. A newUrl, or a changed/removedName, still replaces.Tagsare stored instead of dropped.Known, pre-existing and out of scope
No surface changes: no new API, flag or SDK field; default-region output unchanged except the CFN OIDC
Urlshape above.Test plan
oidc_provider_url_is_unique_across_partitions,saml_provider_name_is_unique(IAM);iam_entities_provisioned_in_china_region_use_aws_cn_partition,iam_oidc_provider_matches_api_shape_and_is_unique_per_url,iam_oidc_and_saml_providers_update_in_place(CFN, covers Retain, in-place, Url/Name replacement, query-string URL refresh). Verified failing on main.cargo test -p fakecloud-iam(558),-p fakecloud-cloudformation(465),-p fakecloud-core(331).iam,multi_account,cloudformation_iam,cloudformation_iam_extras.cargo clippy --workspace --all-targets -- -D warningsclean.Summary by cubic
Makes IAM SAML/OIDC providers unique per account and aligns CloudFormation provisioning with the IAM API.
Behavior changes
CreateSAMLProvidernow fails withEntityAlreadyExistsinstead of silently replacing an existing provider's metadata.CreateOpenIDConnectProvidernow deduplicates by URL instead of ARN, so the same URL can no longer be registered from bothawsandaws-cnpartitions.AWS::IAM::OIDCProviderandAWS::IAM::SAMLProviderreject duplicate URLs/names instead of taking over providers another stack or the API created.GetOpenIDConnectProvidernow returnsaccounts.example.comfor stack-created providers, nothttps://accounts.example.com.ClientIdList,ThumbprintList,SamlMetadataDocument, andTagsupdate in place; a new URL or a changed/removed name still triggers replacement. Previously all changes went through delete-then-create, which collided with retained providers underUpdateReplacePolicy: Retain. Template tags are now stored instead of dropped.Known pre-existing limitation: replacement is delete-then-create, so changing a provider to an already-used URL/name deletes the old provider before create fails.
Written for commit af979a2. Summary will update on new commits.