This changeset switches AWS service touchpoints to use their FIPS-enabled counterparts. Note that S3 has some specific configuration associated with it.
This changeset also updates our allow ACLs to cover the FIPS-enabled endpoints. We should investigate removing the non-FIPS endpoints as a part of this.
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
This changeset adds another endpoint to the staging egress proxy to enable access to AWS CloudWatch logs.
NOTE: We will have to probably do this for production as well.
Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>