-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support AWS China #70
Conversation
@maxsxu:Thanks for your contribution. For this PR, do we need to update docs? |
This looks good to me, just note that PR #72 brought in some changes to the managed-cloud module, in particular a new set of *-runtime.json.tpl files that will need the |
The autdience will be changed by aws partition by default, which could cause some apps (like external-dns, etc) unable to work.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks great, very thorough. Thanks @maxsxu!
Fixes #68
Motivation
Support AWS China.
Modifications
partition
in IAM bootstrap to make was partition configurableStreamNativeCloudManagementRole
trusteduser/aws-cn-test
. As AWS China have to use the generic authentication approachsts.amazonaws.com
to openid_connect_audiences. As applications like external-dns cannot utilize the generatedsts.amazonaws.com.cn
aws-cn
in validation rule atmodules/vpc/variables.tf
var.aws_partition
Verifying this change
(Please pick either of the following options)
This change is a trivial rework / code cleanup without any test coverage.
(or)
This change is already covered by existing tests, such as (please describe tests).
(or)
This change added tests and can be verified as follows:
(example:)
Documentation
Check the box below.
Need to update docs?
doc-required
(If you need help on updating docs, create a doc issue)
no-need-doc
(Please explain why)
doc
(If this PR contains doc changes)