Summary
Propagate the command context.Context through IAM role and policy operations and through the creator lookup.
Rationale
The IAM service-account create command receives a command context. The current creator lookup and role bridge do not propagate that context to the underlying AWS operations. A cancelled command can therefore remain blocked in an AWS call.
Required changes
- Add context-accepting AWS client APIs for the creator lookup and IAM role/policy operations.
- Update
pkg/aws/rolebridge to pass the supplied context to those APIs.
- Update
cmd/create/iamserviceaccount/cmd.go to use the context-aware creator lookup and IAM adapter.
- Preserve cancellation and timeout behavior for
EnsureRole, AttachRolePolicy, and PutRolePolicy.
- Add tests that verify context propagation and cancellation behavior.
Affected areas
cmd/create/iamserviceaccount/cmd.go
pkg/aws/rolebridge
- AWS client interfaces and implementations that provide creator and IAM operations
Acceptance criteria
- The command context reaches the creator lookup and all IAM role/policy AWS calls.
- Cancellation or deadline expiry stops the affected AWS operations when the AWS SDK supports it.
- Tests cover forwarding of the command context through the adapter and client APIs.
Backlinks
Summary
Propagate the command
context.Contextthrough IAM role and policy operations and through the creator lookup.Rationale
The IAM service-account create command receives a command context. The current creator lookup and role bridge do not propagate that context to the underlying AWS operations. A cancelled command can therefore remain blocked in an AWS call.
Required changes
pkg/aws/rolebridgeto pass the supplied context to those APIs.cmd/create/iamserviceaccount/cmd.goto use the context-aware creator lookup and IAM adapter.EnsureRole,AttachRolePolicy, andPutRolePolicy.Affected areas
cmd/create/iamserviceaccount/cmd.gopkg/aws/rolebridgeAcceptance criteria
Backlinks