-
Notifications
You must be signed in to change notification settings - Fork 9.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Skip IAM/STS validation and metadata check #7874
Skip IAM/STS validation and metadata check #7874
Conversation
Just saw this PR while looking at references to my own. Totally agree with the Boolean switch reasoning and happy to close my PR and move forward with this approach. |
* Skip IAM/STS identity validation - For environments or other api implementations where there are no IAM/STS endpoints available, this option lets you opt out from that provider initialization step. * Skip metdata api check - For environments in which you know ahead of time there isn't going to be a metadta api endpoint, this option lets you opt out from that check to save time.
ed98ace
to
0f041b5
Compare
if c.SkipIamValidation == false { | ||
// These two services need to be set up early so we can check on AccountID | ||
client.iamconn = iam.New(awsIamSess) | ||
client.stsconn = sts.New(sess) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This would cause Terraform to crash if you tried apply
ing any iam_*
resource with SkipIamValidation
set to true
. Is there any reason why not keep it outside of the conditional block?
@renier Thanks for the separation. This really helps us reviewing each feature thoroughly and discuss details and effects more easily. I left you two comments there that may need addressing. I will probably add a few comments to the docs once we merge this - effects to be aware of. e.g.
|
@radeksimko Thanks for the review. I don't think this would ever be used against real AWS environments, but I think I addressed all your comments with the iam/sts initialization and increased skip choice resolution. provider "aws" {
region = "us-east-1"
skip_iam_creds_validation = true
skip_iam_account_id = true
skip_metadata_api_check = true
} |
👍 Technically credentials or account ID may not always come from the IAM API (but from metadata API), but that's a really a naming nitpick I'm happy to address in a separate PR. |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further. |
Skip IAM/STS validation and metadata check
implementations where there are no IAM/STS endpoints available, this
option lets you opt out from that provider initialization step.
time there isn't going to be a metadta api endpoint, this option lets
you opt out from that check to save time.
Sample provider config: