Fix cross-partition issue preventing fetching EKS binaries from GovCloud #2152
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue #, if available:
1536
1482
1823
Description of changes:
Modified all files used for building the AMI to pass in the
--no-sign-request
flag when pulling files from S3 using the AWS CLI and crossing partitions between GovCloud and Commercial AWS. Wherever the S3 AWS CLI commands are performed, a check is made to see if theAWS_REGION
variable containsus-gov
and if theBINARY_BUCKET_REGION
does not. In these scenarios, the flag will be passed in the request so that the request is not authenticated as crossing partitions will cause the request to fail.This also required passing in these variables into the
hack/latest-binaries.sh
script as well as modifying the Makefile to include default values when they are not passed in by the user.This also resolves a few to-dos mentioned here and here
Note: AS-IS builds in GovCloud have been broken for over a year. A few pull requests have been submitted, but nothing has passed all tests and been merged.
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
Testing Done
Built several different k8s versions of AL2 and AL2023 AMIs across multiple Commercial and GovCloud regions.
See this guide for recommended testing for PRs. Some tests may not apply. Completing tests and providing additional validation steps are not required, but it is recommended and may reduce review time and time to merge.