Skip to content

fix(iac): enforce AWS CLI federation guard parity - #459

Merged
cristim merged 1 commit into
mainfrom
fix/91-aws-wif-guard-parity
Sep 30, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/91-aws-wif-guard-parity

Conversation

@cristim

@cristim cristim commented Sep 30, 2026

Copy link
Copy Markdown
Member

AWS CLI onboarding could reuse a lookalike OIDC provider, continue after lookup failures, and create a provider with an all-zero thumbprint. This change requires an exact provider match and validates its URL, audience and thumbprints before role creation. It rejects invalid claims before AWS calls, preserves rendered audience defaults, builds trust JSON with jq, and lets AWS retrieve the thumbprint when creating a provider.

Refs #91. This PR covers only AWS CLI WIF task 1. Issue #91 remains open for Azure CLI credential handling, GCP issuer parity, Azure Bicep/ARM role parity, host prerequisites including #131, and cross-path CI/documentation plus shared AWS issuer URL hardening. Issuer validation here mirrors the existing Terraform rule; it is not full URL hardening.

Validation: generated Bash regression tests fail against the original template and pass after the fix; affected package race tests, build, vet, pinned golangci-lint 2.10.1, rendered ShellCheck and pre-commit hooks pass. Independent review approved exact commit 944b87e and reran the complete iacfiles race suite successfully.

Verification uses local recording AWS/curl stubs and real jq. It proves script control flow, arguments and JSON, not live AWS acceptance. No cloud resources were changed.

Reject invalid federation inputs before AWS calls and require an exact,
readable OIDC provider with the requested audience before creating roles.
Use AWS thumbprint retrieval and preserve rendered audience defaults.

Exercise rendered Bash with local CLI stubs, including lookup failures,
lookalike providers, invalid thumbprints, and literal JSON claims.

Refs #91
@cristim cristim added urgency/this-sprint Within the current sprint effort/l Weeks triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm impact/all-users Affects every user type/security Security finding labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

  • Run on-demand review

This review includes 3 billable files and costs up to $0.75.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 28 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 70 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 0df376dd-e675-4dd9-a4c3-226b26d9356b

📥 Commits

Reviewing files that changed from the base of the PR and between 82b251c and 944b87e.

📒 Files selected for processing (3)
  • internal/iacfiles/templates/aws-wif-cli.sh.tmpl
  • internal/iacfiles/templates_aws_wif_test.go
  • internal/iacfiles/templates_test.go

Comment @coderabbitai help to get the list of available commands.

@cristim
cristim merged commit cdccc0a into main Sep 30, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/l Weeks impact/all-users Affects every user priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant