Update the AWS STS endpoint to be regional as the method is now regional #528
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Required to support AWS GovCloud.
Currently the
token
method accepts a region to create the signature for logging into an AWS Cluster, which should make it "quicker" on a regional basis.However the AWS GovCloud partition does not / is not supported by the URL
https://sts.amazonaws.com
as AWS treats it as a totally separate entity.This change updates the STS endpoint to match the region provided with the method.
I would be happy to change the PR to update the
token
method (even the parameters) to pass agov_cloud
named parameter (similar to the region one), then the originalhttps://sts.amazonaws.com
could be kept for speed / efficiency for end-users that do not set region and use normal AWS regions - then only set the region in the URL when using the govCloud partition?List of AWS STS endpoint URLs
Fixes #527
Follows on from #507