aws / aws/aws-cdk

(route53): CustomDeleteExistingRecordSetCustomResourceProviderRole fails with Maximum policy size of 10240 bytes exceeded for role #23279

Open
#23,424 1 comment 2 reactions 0 assignees View on GitHub
@aws-cdk/aws-route53 bug p2
Dominant language
TypeScript
Stars
12.9k
Forks
4.6k
Avg merge
2d 3h
Merged PRs (30d)
83

Description

### Describe the bug

When deploying many records using route53.RecordSet and having delete_existing=True the deployment fails due to exceeding the maximum policy size for the custom role that allows the lambda to delete the records.

### Expected Behavior

The role and function to delete records should be created normally.

### Current Behavior

Error is raised when deploying:

Maximum policy size of 10240 bytes exceeded for the role [redacted]-CustomDeleteExistingReco-1OGW8OMHV7Y0G

### Reproduction Steps

Create at least 50 (I don't know what the exact critical number that makes this fail is) route53.RecordSet objects in a stack with delete_existing=True.

The same happens for more specific objects, such as CnameRecord or ARecord, even if there is a mix of record types.
```
@dataclass
class Record:
name: str
type: RecordType
target_values: list[str]
ttl_seconds: int = 1800
comment: str = ""
zone: route53.IHostedZone = hosted_zone

records = [ # have at least 50 different records here.
Record(
name="test.com",
type=RecordType.A,
target_values=[
"0.0.0.0",
],
ttl_seconds=300,
comment="website",
),
Record(
name="test.com",
type=RecordType.MX,
target_values=[
"1\tASPMX.L.GOOGLE.COM.",
"5\tALT1.ASPMX.L.GOOGLE.COM.",
"5\tALT2.ASPMX.L.GOOGLE.COM.",
"10\tALT3.ASPMX.L.GOOGLE.COM.",
"10\tALT4.ASPMX.L.GOOGLE.COM.",
],
comment="email",
ttl_seconds=300,
),
]

for idx, record in enumerate(records):
route53.RecordSet(
scope=self,
id=f"Record{idx}",
record_name=record.name,
record_type=record.type,
target=RecordTarget(values=record.target_values),
ttl=cdk.Duration.seconds(amount=record.ttl_seconds),
comment=record.comment,
zone=record.zone,
delete_existing=True
)
```

### Possible Solution

_No response_

### Additional Information/Context

The current implementation will add a new inline Policy Statement for each record with repeated statements. In the end the policy ends up huge and above the minimum amount.

I tried activating the [@aws-cdk/aws-iam:minimizePolicies](https://github.com/aws/aws-cdk/blob/main/packages/%40aws-cdk/cx-api/FEATURE_FLAGS.md#aws-cdkaws-iamminimizepolicies) feature flag set to true in cdk.json, but after activating the flag the generated policy is still ~1800 lines long.

```
❯ cdk --version
2.55.1 (build 30f1ae4)
```

cdk.json:
```
{
"app": "python3 app.py",
"requireApproval": "never",
"watch": { "include": [ "**" ] },
"context": {
"@aws-cdk/aws-apigateway:usagePlanKeyOrderInsensitiveId": true,
"@aws-cdk/core:stackRelativeExports": true,
"@aws-cdk/aws-rds:lowercaseDbIdentifier": true,
"@aws-cdk/aws-lambda:recognizeVersionProps": true,
"@aws-cdk/aws-cloudfront:defaultSecurityPolicyTLSv1.2_2021": true,
"@aws-cdk-containers/ecs-service-extensions:enableDefaultLogDriver": true,
"@aws-cdk/aws-ec2:uniqueImdsv2TemplateName": true,
"@aws-cdk/aws-iam:minimizePolicies": true,
"@aws-cdk/core:target-partitions": [
"aws",
"aws-cn"
]
}
}
```

For example, this particular policy below is repeated 24 times in the policy statement:
```
{
"Effect": "Allow",
"Action": "route53:ChangeResourceRecordSets",
"Resource": {
"Fn::Join": [
"",
[
"arn:",
{
"Ref": "AWS::Partition"
},
":route53:::hostedzone/",
{
"Ref": "PublicDnsPublicHostedZoneEAEBE413"
}
]
]
},
"Condition": {
"ForAllValues:StringEquals": {
"route53:ChangeResourceRecordSetsRecordTypes": [
"CNAME"
],
"route53:ChangeResourceRecordSetsActions": [
"DELETE"
]
}
}
},
```

Could it be that the flag is not merging the statements because the policy has a Condition?

Looking at the docs I don't see any mentions to what the flag does when there is a Condition:
https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.aws_iam.PolicyDocumentProps.html#minimize

### CDK CLI Version

2.55.1 (build 30f1ae4)

### Framework Version

_No response_

### Node.js Version

v16.14.0

### OS

ubuntu / macOs

### Language

Python

### Language Version

Python 3.9.11

### Other information

_No response_

Contributor guide

Open the contributing guide

Research direction

Start at route53.RecordSet with delete_existing=True and inspect the generated custom resource role policy, then review the PolicyDocument minimize behavior described in the issue. Reproduce the failure with at least 50 records and inspect the synthesized policy; done means the deployment succeeds without exceeding the 10240-byte role policy limit.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cloud, infrastructure
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.