aws / aws/aws-toolkit-vscode

US Gov region support

Open
#8,573 0 comments 1 reaction 0 assignees View on GitHub
feature-request
Dominant language
TypeScript
Stars
2k
Forks
807
Avg merge
10h 12m
Merged PRs (30d)
7

Description

### Feature Request: Add Full AWS GovCloud (US) Partition Support

#### Problem
The AWS Toolkit does not support the `aws-us-gov` partition. During sign-in, GovCloud regions (`us-gov-west-1`, `us-gov-east-1`) are not available for selection, preventing authentication even with valid AWS Console or Workforce (SSO) credentials.

#### Expected Behavior
- GovCloud regions appear during sign-in region selection
- Full support for the `aws-us-gov` partition, including:
- Partition-aware endpoints
- Correct ARN formats
- GovCloud STS and IAM endpoints
- Compatibility with Console credentials and Workforce/SSO

#### Actual Behavior
- GovCloud regions are not listed
- Authentication cannot proceed
- No documented workaround exists

#### Impact
This blocks usage in U.S. Government and regulated environments where commercial AWS regions are not permitted.

#### Notes
This request requires full partition support, not just adding regions to a selector.

Contributor guide

Open the contributing guide

Research direction

Start at the sign-in region-selection flow and the Console or Workforce/SSO authentication entry points, then compare how the existing commercial AWS partition is represented. Trace partition-aware endpoint and ARN handling, with done defined as selectable GovCloud regions and working Console and Workforce/SSO authentication against the required GovCloud endpoints.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
authentication, cloud
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.