Switch to using FIPS-enabled endpoints

This changeset switches AWS service touchpoints to use their FIPS-enabled counterparts.  Note that S3 has some specific configuration associated with it.

This changeset also updates our allow ACLs to cover the FIPS-enabled endpoints.  We should investigate removing the non-FIPS endpoints as a part of this.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
This commit is contained in:
Carlo Costino
2023-08-10 18:02:45 -04:00
parent d8dcde4403
commit d4848a67b5
8 changed files with 58 additions and 11 deletions

View File

@@ -1,5 +1,14 @@
logs.us-east-1.amazonaws.com
logs-fips.us-east-1.amazonaws.com
monitoring.us-west-2.amazonaws.com
monitoring-fips.us-west-2.amazonaws.com
email.us-west-2.amazonaws.com
email-fips.us-west-2.amazonaws.com
s3-fips.us-east-1.amazonaws.com
s3-fips.us-east-2.amazonaws.com
s3-fips.us-west-1.amazonaws.com
s3-fips.us-west-2.amazonaws.com
sns.us-east-1.amazonaws.com
sns-fips.us-east-1.amazonaws.com
gov-collector.newrelic.com
egress-proxy-notify-api-demo.apps.internal

View File

@@ -1,5 +1,9 @@
logs.us-gov-west-1.amazonaws.com
monitoring.us-west-2.amazonaws.com
email.us-gov-west-1.amazonaws.com
email-fips.us-gov-west-1.amazonaws.com
s3-fips.us-gov-east-1.amazonaws.com
s3-fips.us-gov-west-1.amazonaws.com
sns.us-gov-west-1.amazonaws.com
gov-collector.newrelic.com
egress-proxy-notify-api-production.apps.internal

View File

@@ -1,6 +1,14 @@
logs.us-west-2.amazonaws.com
logs-fips.us-west-2.amazonaws.com
monitoring.us-west-2.amazonaws.com
monitoring-fips.us-west-2.amazonaws.com
email.us-west-2.amazonaws.com
email-fips.us-west-2.amazonaws.com
s3-fips.us-east-1.amazonaws.com
s3-fips.us-east-2.amazonaws.com
s3-fips.us-west-1.amazonaws.com
s3-fips.us-west-2.amazonaws.com
sns.us-west-2.amazonaws.com
sns-fips.us-west-2.amazonaws.com
gov-collector.newrelic.com
egress-proxy-notify-api-staging.apps.internal