Skip to content

Assume Role With Web Identity doesn't respect region #8697

@liorpsweetsecurity

Description

@liorpsweetsecurity

Describe the bug

Running aws sts assume-role-with-web-identity --role-arn ${ROLE_ARN} --web-identity-token ${ACCESS_TOKEN}--role-session-name${SESSION_NAME} --region us-east-2 seems to send to us-east-1.

Expected Behavior

I expect to see corresponding events in the cloudtrail associated with us-east-2.

Current Behavior

I see AssumeRoleWithWebIdentity events under us-east-1 cloud trail.

Reproduction Steps

Run aws sts assume-role-with-web-identity --role-arn ${ROLE_ARN} --web-identity-token ${ACCESS_TOKEN}--role-session-name${SESSION_NAME} --region us-east-2.
Check cloudtrail logs.
It seems to be in us-east-1, regardless of the region parameter.

Possible Solution

No response

Additional Information/Context

No response

CLI version used

aws-cli/1.18.69 Python/3.8.10 Linux/5.15.0-1064-azure botocore/1.16.19

Environment details (OS name and version, etc.)

NAME="Ubuntu" VERSION="20.04.6 LTS (Focal Fossa)" ID=ubuntu ID_LIKE=debian PRETTY_NAME="Ubuntu 20.04.6 LTS" VERSION_ID="20.04" HOME_URL="https://www.ubuntu.com/" SUPPORT_URL="https://help.ubuntu.com/" BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/" PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy" VERSION_CODENAME=focal UBUNTU_CODENAME=focal

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions