Repository navigation
feat(auth): op-level IAM for Route 53 and CloudFront under --enforce-auth (AUTHZ-X1g-1) - #1536
Merged
Merged
Conversation
…ocal distribution
…dition keys under --enforce-auth
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1495 (AUTHZ-X1g, first of four PRs: Route 53 + CloudFront; EKS, API Gateway and execute-api:Invoke follow).
What changed
Under
cloudemu serve --enforce-auth, Route 53 and CloudFront are now authorized per operation on real resource ARNs instead of at service level, so fine-grained and resource-scoped policies work for them.The pattern follows S3 (#1444) and Lambda (#1530):
classify(r) (opID, opArgs).ServeHTTPdispatches on it andIAMChecks/IAMChecksWithContextuse the same function, so the operation and resource IAM checks are the ones that run. A request classify cannot name is answered with the handler's existing 4xx and no side effect (fail closed: shortcut principals get that error, policy users get 403). New auth-off golden cases were recorded on the base code and pass unchanged on this branch.route53:<Operation>onarn:aws:route53:::hostedzone/<id>,healthcheck/<id>andchange/<id>(no region or account); account-level operations on*. Condition keys:route53:ChangeResourceRecordSetsActions,route53:ChangeResourceRecordSetsRecordTypesandroute53:ChangeResourceRecordSetsNormalizedRecordNames(from the same XML decode dispatch uses), androute53:VPCsasVPCId=<id>,VPCRegion=<region>. Creating a private zone and AssociateVPCWithHostedZone also needec2:DescribeVpcson*.cloudfront:<Operation>onarn:aws:cloudfront::<account>:distribution/<id>; invalidation operations on their distribution; CreateDistribution and ListDistributions on*. CreateDistributionWithTags is authorized ascloudfront:CreateDistributionpluscloudfront:TagResource, the latter ondistribution/*since the id does not exist yet.aws:RequestTag/*,aws:TagKeysandaws:ResourceTag/*are set.{ResourceType}:/tags/healthcheck/<zone-id>tagged the zone, and any id (even one naming nothing) was tagged. It now answers InvalidInput for an unknown type and NoSuchHostedZone / NoSuchHealthCheck when the id is not a resource of that type.awsauthz.Scope.PartitionARNandawsauthz.XMLBody(XML twin ofJSONBody).EnforceAuthcomment, contrib/server README.Sources
servicereference.us-east-1.amazonaws.com/v1/route53/route53.json,.../cloudfront/cloudfront.json,.../ec2/ec2.json(ec2:DescribeVpcs takes no resource).\ooooctal,*is\052), uppercase actions and types,route53:VPCsformatVPCId=<vpc-id>,VPCRegion=<region>lower case, example pairing the VPC actions withec2:DescribeVpcs.Resource: "*".Verification
IAMChecksWithContexttables (actions, ARNs, condition keys, body put back), record name normalization, distribution ARN parsing.TestAuthzMatrixRoute53,TestAuthzMatrixCloudFront(scoped ARNs, RecordTypes condition, single Deny, private zone needs ec2:DescribeVpcs, ResourceTag, WithTags needs TagResource, foreign tagging ARN),TestUnknownRESTOpHasNoSideEffect(shortcut caller gets the 4xx, restricted caller 403, state unchanged),TestOpLevelRESTHandlersAreResolvers,TestAuthOffResponsesUnchanged(13 new cases, golden recorded on the base code).TestEnforceAuthRoute53,TestEnforceAuthCloudFrontwith the real SDKs.cloudemu serve --enforce-auth, scoped IAM users made with the aws CLI:cloudfront:*with a Deny on CreateInvalidation): create, get, update (disable), tag/list/untag, delete OK; CreateInvalidation denied with the explicit-deny message; a tagging ARN of another account denied.aws_route53_zone,aws_route53_record(TXT) andaws_cloudfront_distribution: apply,plan -detailed-exitcode= 0, destroy all clean; adding an A record fails with AccessDenied.go build ./...,go vet,go test -raceon server/aws/route53, server/aws/cloudfront, server/aws, server/wire/..., persist;go -C contrib/server test -run Enforce; golangci-lint (new issues) 0;go generateno docs diff.