-
Notifications
You must be signed in to change notification settings - Fork 4.3k
feat(amplify): add compute role support for Amplify branches #34708
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 6 commits
0997c45
5eee1ea
d407d28
0cfeb39
a7dd592
bab1ebc
052bb10
d26173b
30ea997
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -20,6 +20,11 @@ export interface IApp extends IResource { | |
| * @attribute | ||
| */ | ||
| readonly appId: string; | ||
|
|
||
| /** | ||
| * The platform of the app | ||
| */ | ||
| readonly platform?: Platform; | ||
| } | ||
|
|
||
| /** | ||
|
|
@@ -237,6 +242,11 @@ export class App extends Resource implements IApp, iam.IGrantable { | |
| */ | ||
| public readonly computeRole?: iam.IRole; | ||
|
|
||
| /** | ||
| * The platform of the app | ||
| */ | ||
| public readonly platform?: Platform; | ||
|
|
||
| private readonly customRules: CustomRule[]; | ||
| private readonly environmentVariables: { [name: string]: string }; | ||
| private readonly autoBranchEnvironmentVariables: { [name: string]: string }; | ||
|
|
@@ -256,7 +266,8 @@ export class App extends Resource implements IApp, iam.IGrantable { | |
| this.grantPrincipal = role; | ||
|
|
||
| let computedRole: iam.IRole | undefined; | ||
| const isSSR = props.platform === Platform.WEB_COMPUTE || props.platform === Platform.WEB_DYNAMIC; | ||
| const appPlatform = props.platform || Platform.WEB; | ||
| const isSSR = appPlatform === Platform.WEB_COMPUTE || appPlatform === Platform.WEB_DYNAMIC; | ||
|
||
|
|
||
| if (props.computeRole) { | ||
| if (!isSSR) { | ||
|
|
@@ -272,6 +283,8 @@ export class App extends Resource implements IApp, iam.IGrantable { | |
|
|
||
| const sourceCodeProviderOptions = props.sourceCodeProvider?.bind(this); | ||
|
|
||
| this.platform = appPlatform; | ||
|
|
||
| const app = new CfnApp(this, 'Resource', { | ||
| accessToken: sourceCodeProviderOptions?.accessToken?.unsafeUnwrap(), // Safe usage | ||
| autoBranchCreationConfig: props.autoBranchCreation && { | ||
|
|
@@ -302,7 +315,7 @@ export class App extends Resource implements IApp, iam.IGrantable { | |
| oauthToken: sourceCodeProviderOptions?.oauthToken?.unsafeUnwrap(), // Safe usage | ||
| repository: sourceCodeProviderOptions?.repository, | ||
| customHeaders: props.customResponseHeaders ? renderCustomResponseHeaders(props.customResponseHeaders) : undefined, | ||
| platform: props.platform || Platform.WEB, | ||
| platform: appPlatform, | ||
| }); | ||
|
|
||
| this.appId = app.attrAppId; | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -9,11 +9,12 @@ import { | |
| Duration, | ||
| NestedStack, | ||
| Stack, | ||
| ValidationError, | ||
| } from 'aws-cdk-lib/core'; | ||
| import { Provider } from 'aws-cdk-lib/custom-resources'; | ||
| import { Construct } from 'constructs'; | ||
| import { CfnBranch } from 'aws-cdk-lib/aws-amplify'; | ||
| import { IApp } from './app'; | ||
| import { IApp, Platform } from './app'; | ||
| import { BasicAuth } from './basic-auth'; | ||
| import { renderEnvironmentVariables } from './utils'; | ||
| import { AssetDeploymentIsCompleteFunction, AssetDeploymentOnEventFunction } from '../custom-resource-handlers/dist/aws-amplify-alpha/asset-deployment-provider.generated'; | ||
|
|
@@ -137,6 +138,16 @@ export interface BranchOptions { | |
| * @default None - Default setting is no skew protection. | ||
| */ | ||
| readonly skewProtection?: boolean; | ||
|
|
||
| /** | ||
| * The IAM role to assign to a branch of an SSR app. | ||
| * The SSR Compute role allows the Amplify Hosting compute service to securely access specific AWS resources based on the role's permissions. | ||
| * | ||
| * This role overrides the app-level compute role. | ||
| * | ||
| * @default undefined - No specific role for the branch. If the app has a compute role, it will be inherited. | ||
| */ | ||
| readonly computeRole?: iam.IRole; | ||
| } | ||
|
|
||
| /** | ||
|
|
@@ -183,6 +194,13 @@ export class Branch extends Resource implements IBranch { | |
| // Enhanced CDK Analytics Telemetry | ||
| addConstructMetadata(this, props); | ||
|
|
||
| const platform = props.app.platform; | ||
|
||
| const isSSR = platform === Platform.WEB_COMPUTE || platform === Platform.WEB_DYNAMIC; | ||
|
|
||
| if (props.computeRole && !isSSR) { | ||
| throw new ValidationError('`computeRole` can only be specified for branches of apps with `Platform.WEB_COMPUTE` or `Platform.WEB_DYNAMIC`.', this); | ||
| } | ||
|
|
||
| this.environmentVariables = props.environmentVariables || {}; | ||
|
|
||
| const branchName = props.branchName || id; | ||
|
|
@@ -199,6 +217,7 @@ export class Branch extends Resource implements IBranch { | |
| stage: props.stage, | ||
| enablePerformanceMode: props.performanceMode, | ||
| enableSkewProtection: props.skewProtection, | ||
| computeRoleArn: props.computeRole?.roleArn, | ||
leonmk-aws marked this conversation as resolved.
Show resolved
Hide resolved
|
||
| }); | ||
|
|
||
| this.arn = branch.attrArn; | ||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,134 @@ | ||
| { | ||
| "Resources": { | ||
| "ComputeRole65BDBE3E": { | ||
| "Type": "AWS::IAM::Role", | ||
| "Properties": { | ||
| "AssumeRolePolicyDocument": { | ||
| "Statement": [ | ||
| { | ||
| "Action": "sts:AssumeRole", | ||
| "Effect": "Allow", | ||
| "Principal": { | ||
| "Service": "amplify.amazonaws.com" | ||
| } | ||
| } | ||
| ], | ||
| "Version": "2012-10-17" | ||
| } | ||
| } | ||
| }, | ||
| "AppRole1AF9B530": { | ||
| "Type": "AWS::IAM::Role", | ||
| "Properties": { | ||
| "AssumeRolePolicyDocument": { | ||
| "Statement": [ | ||
| { | ||
| "Action": "sts:AssumeRole", | ||
| "Effect": "Allow", | ||
| "Principal": { | ||
| "Service": "amplify.amazonaws.com" | ||
| } | ||
| } | ||
| ], | ||
| "Version": "2012-10-17" | ||
| } | ||
| } | ||
| }, | ||
| "AppComputeRole426920E4": { | ||
| "Type": "AWS::IAM::Role", | ||
| "Properties": { | ||
| "AssumeRolePolicyDocument": { | ||
| "Statement": [ | ||
| { | ||
| "Action": "sts:AssumeRole", | ||
| "Effect": "Allow", | ||
| "Principal": { | ||
| "Service": "amplify.amazonaws.com" | ||
| } | ||
| } | ||
| ], | ||
| "Version": "2012-10-17" | ||
| } | ||
| } | ||
| }, | ||
| "AppF1B96344": { | ||
| "Type": "AWS::Amplify::App", | ||
| "Properties": { | ||
| "BasicAuthConfig": { | ||
| "EnableBasicAuth": false | ||
| }, | ||
| "CacheConfig": { | ||
| "Type": "AMPLIFY_MANAGED_NO_COOKIES" | ||
| }, | ||
| "ComputeRoleArn": { | ||
| "Fn::GetAtt": [ | ||
| "AppComputeRole426920E4", | ||
| "Arn" | ||
| ] | ||
| }, | ||
| "IAMServiceRole": { | ||
| "Fn::GetAtt": [ | ||
| "AppRole1AF9B530", | ||
| "Arn" | ||
| ] | ||
| }, | ||
| "Name": "App", | ||
| "Platform": "WEB_COMPUTE" | ||
| } | ||
| }, | ||
| "AppmainF505BAED": { | ||
| "Type": "AWS::Amplify::Branch", | ||
| "Properties": { | ||
| "AppId": { | ||
| "Fn::GetAtt": [ | ||
| "AppF1B96344", | ||
| "AppId" | ||
| ] | ||
| }, | ||
| "BranchName": "main", | ||
| "ComputeRoleArn": { | ||
| "Fn::GetAtt": [ | ||
| "ComputeRole65BDBE3E", | ||
| "Arn" | ||
| ] | ||
| }, | ||
| "EnableAutoBuild": true, | ||
| "EnablePullRequestPreview": true | ||
| } | ||
| } | ||
| }, | ||
| "Parameters": { | ||
| "BootstrapVersion": { | ||
| "Type": "AWS::SSM::Parameter::Value<String>", | ||
| "Default": "/cdk-bootstrap/hnb659fds/version", | ||
| "Description": "Version of the CDK Bootstrap resources in this environment, automatically retrieved from SSM Parameter Store. [cdk:skip]" | ||
| } | ||
| }, | ||
| "Rules": { | ||
| "CheckBootstrapVersion": { | ||
| "Assertions": [ | ||
| { | ||
| "Assert": { | ||
| "Fn::Not": [ | ||
| { | ||
| "Fn::Contains": [ | ||
| [ | ||
| "1", | ||
| "2", | ||
| "3", | ||
| "4", | ||
| "5" | ||
| ], | ||
| { | ||
| "Ref": "BootstrapVersion" | ||
| } | ||
| ] | ||
| } | ||
| ] | ||
| }, | ||
| "AssertDescription": "CDK bootstrap stack version 6 required. Please run 'cdk bootstrap' with a recent version of the CDK CLI." | ||
| } | ||
| ] | ||
| } | ||
| } | ||
| } |
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should not add optional field in the interface that extends
iResource, see below one approach on how to do the isSSR check without exposing the field in this interface.