スキップしてコンテンツを表示

Zero Regional endpoints for STS

0

When I navigate to the Security Token Service (STS) (logged in as a root user). I am currently getting zero endpoints available. Enter image description here

For context: I am trying to deploy an Amplify Next.js app, but it appears the IAM role lacks permissions (everything is default, so this should be fine). I have traced my way back to STS endpoints and see that I have none. How can I fix this and add them back in? When I look at any of the docs, they already have the endpoints appearing to be enabled/disabled.

I am deploying on eu-central-1 which is an AWS region enabled by default

Thank you!

3回答
2

I'm getting that error too. It appears to be a temporary problem with the console. The STS endpoint does exist at sts.eu-central-1.amazonaws.com, and as you stated, eu-central-1 is enabled by default, so the endpoint is available without having to be enabled separately.

エキスパート

回答済み 2年前

エキスパート

レビュー済み 2年前

エキスパート

レビュー済み 2年前

1
承認された回答

Thank you for the responses! @Didier it isn't possible to complete those docs, I did try before writing the question, but I can not complete step 3 as there is no options for regions to set as Active or Inaction.

  1. In the Security Token Service (STS) section Endpoints, find the Region that you want to configure, and then choose Active or Inactive in the STS status column.

This did lead me down a path of investigating other EU regions, all had the same error, and even on a new account, same error.

I managed to get a build (in Amplify) working on us-east-1 without changing anything. I'm no expect but my speculation is that because IAM and other Global services are hosted at us-east-1 there was no need for Amplify to request a sts:AssumeRole from another region, bypassing this check.

回答済み 2年前

エキスパート

レビュー済み 2年前

  • You can set anything based on AWS SDKs, whether things like the boto3 library for Python or the AWS CLI, to choose the regional endpoint by setting the environment variable AWS_STS_REGIONAL_ENDPOINTS to regional (https://docs.aws.amazon.com/sdkref/latest/guide/feature-sts-regionalized-endpoints.html) or by specifying it explicitly to the AssumeRole API you call via the AWS SDK. It's generally recommended to use the regional endpoints, because they share regional availability characteristics with other resources, and provide minimal-latency access from inside the region.

1

Hi,

Did you exactly follow this page: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html#sts-regions-activate-deactivate

It details all steps to accomplish to successfully access STS regional endpoints.

Best,

Didier

エキスパート

回答済み 2年前

エキスパート

レビュー済み 2年前

エキスパート

レビュー済み 2年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

関連するコンテンツ