Enable transitive AWS STS Session Tagging

Currently, session tagging when assuming an AWS IAM Role via Spacelift will only tag the first assumption. For situations where there are multiple links in an assumption chain, e.g using a Spacelift integration to automatically assume an access role, then using the OpenTofu AWS provider to assume a second role in a target account, this means only the access role assumption is tagged.

Ideally, transitive session tags would be used so the tag persists through the entire assumption chain.

AWS docs for session tagging for reference: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html

Our security team is keen for this feature so that AWS CloudTrail events can be captured in our SIEM to understand exactly which Spacelift stack run resulted in changes, which can then be linked back to specific commits/authors.

Please authenticate to join the conversation.

Upvoters

Linked requests

Board

💡 Feature Requests

Tags

Self-hosted

Date

About 7 hours ago

Subscribe to request

Get notified by email when there are changes.