Merge pull request #17161 from jValdron/route53-only-config-sts-for-idms

Only configure STS region for Route 53 when we obtain it using IDMS
This commit is contained in:
Kubernetes Prow Robot 2025-01-03 02:34:13 +01:00 committed by GitHub
commit 581f3638ba
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 22 additions and 19 deletions

View File

@ -71,34 +71,37 @@ func newRoute53() (*Interface, error) {
region = imdsRegionResp.Region region = imdsRegionResp.Region
} }
stsCfg, err := awsconfig.LoadDefaultConfig(ctx,
awsconfig.WithClientLogMode(aws.LogRetries),
awslog.WithAWSLogger(),
awsconfig.WithRetryer(func() aws.Retryer {
return retry.AddWithMaxAttempts(retry.NewStandard(), 5)
}),
awsconfig.WithRegion(region),
)
if err != nil {
return nil, fmt.Errorf("failed to load default aws config for STS client: %w", err)
}
awsOptions := []func(*awsconfig.LoadOptions) error{ awsOptions := []func(*awsconfig.LoadOptions) error{
awsconfig.WithClientLogMode(aws.LogRetries), awsconfig.WithClientLogMode(aws.LogRetries),
awslog.WithAWSLogger(), awslog.WithAWSLogger(),
awsconfig.WithRetryer(func() aws.Retryer { awsconfig.WithRetryer(func() aws.Retryer {
return retry.AddWithMaxAttempts(retry.NewStandard(), 5) return retry.AddWithMaxAttempts(retry.NewStandard(), 5)
}), }),
awsconfig.WithAssumeRoleCredentialOptions(func(aro *stscreds.AssumeRoleOptions) {
// Ensure the STS client has a region configured, if discovered by IMDS
aro.Client = sts.NewFromConfig(stsCfg)
}),
} }
if imdsClient != nil { if imdsClient != nil {
awsOptions = append(awsOptions, awsconfig.WithEC2IMDSRegion(func(o *awsconfig.UseEC2IMDSRegion) { stsCfg, err := awsconfig.LoadDefaultConfig(ctx,
o.Client = imdsClient awsconfig.WithClientLogMode(aws.LogRetries),
})) awslog.WithAWSLogger(),
awsconfig.WithRetryer(func() aws.Retryer {
return retry.AddWithMaxAttempts(retry.NewStandard(), 5)
}),
awsconfig.WithRegion(region),
)
if err != nil {
return nil, fmt.Errorf("failed to load default aws config for STS client: %w", err)
}
awsOptions = append(
awsOptions,
awsconfig.WithEC2IMDSRegion(func(o *awsconfig.UseEC2IMDSRegion) {
o.Client = imdsClient
}),
awsconfig.WithAssumeRoleCredentialOptions(func(aro *stscreds.AssumeRoleOptions) {
// Ensure the STS client has a region configured, if discovered by IMDS
aro.Client = sts.NewFromConfig(stsCfg)
}),
)
} }
cfg, err := awsconfig.LoadDefaultConfig(ctx, awsOptions...) cfg, err := awsconfig.LoadDefaultConfig(ctx, awsOptions...)