Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Publish layer to Gov Cloud regions #1166

Open
bryantbiggs opened this issue Dec 11, 2021 · 21 comments
Open

Publish layer to Gov Cloud regions #1166

bryantbiggs opened this issue Dec 11, 2021 · 21 comments
Assignees
Labels
feature-request feature request internal Maintenance changes need-customer-feedback Requires more customers feedback before making or revisiting a decision v3 Features that will be included in Powertools v3.

Comments

@bryantbiggs
Copy link

Is your feature request related to a problem? Please describe.

  • Consider publishing the layer to the Gov Cloud regions. I checked the list of regions the layer is currently published to but it looks like the Gov Cloud regions are not present.

Describe the solution you'd like

  • It would be great if the layer could be published and available in the Gov Cloud regions as well

Describe alternatives you've considered

  • For now, I am recommending Gov Cloud users perform a copy of the layer to their account and use that route as a temporary work around

Additional context

@boring-cyborg
Copy link

boring-cyborg bot commented Dec 11, 2021

Thanks for opening your first issue here! We'll come back to you as soon as we can.

@heitorlessa
Copy link
Contributor

Thanks a lot for raising this @bryantbiggs - I'm moving to the Roadmap under Backlog as it's something we want to do, but require additional permissions internally given its purpose and regulations.

@heitorlessa
Copy link
Contributor

Update: @am29d is working on migrating our internal Lambda Layers pipeline to CodePipeline in a Powertools AWS account. Once that's done (~H2), we should be able to expand to more AWS regions - that said, GovCloud is a special region and might take longer for us to get approval to do so.

You can follow progress here: https://github.com/orgs/awslabs/projects/51/views/11

@boring-cyborg
Copy link

boring-cyborg bot commented Apr 28, 2022

Thanks for opening your first issue here! We'll come back to you as soon as we can.

@heitorlessa heitorlessa transferred this issue from aws-powertools/powertools-lambda Apr 28, 2022
@heitorlessa heitorlessa added feature-request feature request and removed python labels Apr 28, 2022
@heitorlessa heitorlessa added the need-customer-feedback Requires more customers feedback before making or revisiting a decision label Jan 31, 2023
@kb-fusus
Copy link

kb-fusus commented May 1, 2023

any updates on this one?

@rubenfonseca
Copy link
Contributor

Hi @kb-fusus I'm actively looking for an update on this, and will get back to you shortly. Publishing the layer to the Gov Cloud regions is a very complex operation, but we're looking to understand the best way to making it work. Thank you for your ping!

@dannellyz
Copy link

@rubenfonseca Also wanted to +1 from a customer side how great it would be to have this available in GovCloud. Specifically, the added optimization the team does compared to just pip installing or packaging ourselves would be a huge win. Thanks!

@heitorlessa
Copy link
Contributor

thanks a lot @dannellyz! We're still looking for US specific controls and procedures to work on this.

You could help us prioritize this by sending an email from your corporate address to aws-lambda-powertools-feedback at amazon dot com. We're collecting customer names / gov agencies to help expedite some of these controls.

Thank you!

@dannellyz
Copy link

Will do!

@heitorlessa
Copy link
Contributor

Adding this to our public roadmap as of now to make it easier for agencies to reach out to us to help prioritize: https://docs.powertools.aws.dev/lambda/python/stage/roadmap/#lambda-layer-in-govcloud-and-china-region

Sent an internal email asking about GovCloud region requirements to publish this Layer.

@leandrodamascena leandrodamascena added the internal Maintenance changes label Aug 17, 2023
@leandrodamascena
Copy link
Contributor

Adding the internal label because we need to handle it internally before making it available for the public.

@leandrodamascena
Copy link
Contributor

Hi everyone, we're still researching this feature. Because of the complexities of GovCloud, this is taking us longer than expected. We'll share any updates as we have them.

Thank you

@rubenfonseca
Copy link
Contributor

Update: we found a way to move forward and to add the Layer to GovCloud regions. Expect to have news by the end of the week! Stay tunned :)

@rubenfonseca
Copy link
Contributor

Update: we’ve completed our infrastructure changes and we are going through additional security and compliance requirements. We’ll keep you posted as soon as we have updates on a plausible ETA; tentatively after re:invent / early next year.

@drissamri
Copy link

It would be really interesting to read on the additional measures you have to take to qualify for the requirements

@heitorlessa
Copy link
Contributor

it's all internal @drissamri the only extra bit we will need to do is to create provenance for the Layer w/ all dependencies, or SBOM (easy).

If you'd like to learn more about AppSec & supply chain security in general, reach out to @sthulb (Simon is on Discord!)

@leandrodamascena
Copy link
Contributor

Hey, everyone! We are still working on this with internal teams and we may have some good news next month.

Changing the status to "Working on it"

@leandrodamascena leandrodamascena added the v3 Features that will be included in Powertools v3. label Apr 23, 2024
@leandrodamascena leandrodamascena added this to the Powertools v3 milestone Apr 23, 2024
@marlhammer
Copy link

greetings! we have a production system that relies on power tools and this is the only blocker to migrating this to GovCloud. :-) can we support this in any way?

@sthulb
Copy link
Contributor

sthulb commented Jun 21, 2024

Hi folks!

We've been making steps towards our releases on GovCloud (us-gov-west-1, us-gov-east-1). If all goes well, we aim to have releases by the end of July. We'll post weekly updates here to document progress (or lack of it, if we have no new news to share).

Thanks
@sthulb

@sthulb
Copy link
Contributor

sthulb commented Jun 28, 2024

Hi folks!

We have created the accounts and in the process of bootstrapping them, hopefully this time next week we'll be in a position to deploy into them.

A question for anyone reading: Do you want:

  • all previous versions backfilled from v2
  • last X versions backfilled
  • just the latest version?

Thanks
@sthulb

@bryantbiggs
Copy link
Author

just the latest - motivation for folks to update 😉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature-request feature request internal Maintenance changes need-customer-feedback Requires more customers feedback before making or revisiting a decision v3 Features that will be included in Powertools v3.
Projects
Status: Working on it
Development

No branches or pull requests

10 participants