r/aws_sagemaker_domain: add trusted_identity_propagation_enabled argument #44965
+94
−4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Rollback Plan
If a change needs to be reverted, we will publish an updated version of the library.
Changes to Security Controls
No changes to security controls. This PR adds a new optional configuration field that enables Trusted Identity Propagation, which enhances access control and auditing capabilities when used with SSO authentication.
Description
Adds support for enabling Trusted Identity Propagation (TIP) in SageMaker domains through the
trusted_identity_propagation_enabledargument in thedomain_settingsblock.When enabled, user identities from IAM Identity Center are propagated through the domain to TIP enabled AWS services, providing enhanced access control and auditing capabilities.
Changes:
trusted_identity_propagation_enabledboolean field todomain_settingsschema (defaults tofalse)auth_mode = "SSO"when field istrueRelations
Closes #44962
References
Output from Acceptance Testing