Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test disabling enforce client side settings on athena workgroups #5678

Draft
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

SoumayaMauthoorMOJ
Copy link
Contributor

@SoumayaMauthoorMOJ SoumayaMauthoorMOJ commented Oct 15, 2024

Pull Request Objective

The Athena Primary workgroup does not enforce client side settings which means that IAM builder automatically grants access to the right folder : arn:aws:s3:::mojap-athena-query-dump/${aws:userid}/*"

We want to test the impact of not enforcing client https://docs.aws.amazon.com/athena/latest/ug/workgroups-settings-override.html on the new Airflow workgroups

Checklist

Note

Each items should be checked. Skipping below checks could delay your PR review!

  • I have reviewed the style guide
    and ensured that my code complies with it
  • All checks have passed (or override label applied, if I've
    used the override-static-analysis label, I've explained why)
  • I have self-reviewed my code
  • I have reviewed the checks and can attest they're as expected

Additional Comments

Copy link
Contributor

github-actions bot commented Oct 15, 2024

Terraform Component 🧱: aws-analytical-platform-data-production-athena

Terraform Initialization ⚙️: success

Terraform Validation 🤖: success

Terraform Plan 🛠️: success

Pusher: @SoumayaMauthoorMOJ, Action: pull_request, Working Directory: terraform/aws/analytical-platform-data-production/athena, Workflow: Terraform, Marker: aws-analytical-platform-data-production-athena_plan

Copy link
Contributor

github-actions bot commented Oct 15, 2024

Terraform Component 🧱: aws-analytical-platform-data-production-athena

Checkov 🛂: success

Trivy 🛂: failure

Static Analysis Override Label 🏷️: false

Pusher: @SoumayaMauthoorMOJ, Action: pull_request, Working Directory: terraform/aws/analytical-platform-data-production/athena, Workflow: Terraform, Marker: aws-analytical-platform-data-production-athena_static_analysis

@SoumayaMauthoorMOJ
Copy link
Contributor Author

@jacobwoffenden any ideas why the terraform workflow is failing?

@SoumayaMauthoorMOJ
Copy link
Contributor Author

I don't think there's a problem with the code, I think the problem is because terraform doesn't allow us switch off "override client settings"

@SoumayaMauthoorMOJ
Copy link
Contributor Author

@SoumayaMauthoorMOJ SoumayaMauthoorMOJ changed the title Update athena-workgroups Test disabling enforce client side settings on athena workgroups Oct 16, 2024
@jacobwoffenden jacobwoffenden marked this pull request as draft October 21, 2024 20:40
@jacobwoffenden
Copy link
Member

@williamorrie any ideas on how this proceeds in Soumaya's absense?

CC: @jhpyke

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants