Hive Hive
Sign in

fix(server): configure STS region for IRSA

GitHub issue · Closed

Metadata
Source
tuist/tuist #11111
Updated
Jun 24, 2026
Domains
Storage
Details

Resolves N/A

Fixes the IRSA ExAws configuration so the global STS client uses the same S3 region source as the S3 client. Without this, ExAws falls back to us-east-1 for the STS web identity credential refresh even when S3 is configured for eu-west-1, which can break in environments that only allow regional STS egress.

The change keeps the existing in-memory awscli profile for web identity credentials and adds a regression assertion that the IRSA config carries Environment.s3_region(secrets).

How to test locally

  • mix format --check-formatted lib/tuist/aws/s3_authentication_config.ex test/tuist/aws/s3_authentication_config_test.exs
  • MIX_ENV=test mix run --no-start -e 'ExUnit.start(autorun: false); Code.require_file("test/tuist/aws/s3_authentication_config_test.exs"); result = ExUnit.run(); if result.failures > 0, do: System.halt(1)'
  • git diff --check -- server/lib/tuist/aws/s3_authentication_config.ex server/test/tuist/aws/s3_authentication_config_test.exs server/mix.lock

Note: mix test test/tuist/aws/s3_authentication_config_test.exs was attempted, but the local test database migration setup failed before this unit test ran with relation "users" does not exist.

Flights

Investigate, reproduce, or fix this item in an isolated repository. Each Flight preserves its outcome and agent session.

New Flights are paused Configure model inference, GitHub, and a sandbox provider to start another Flight. Existing results remain available below.
No Flights yet

Start a Flight and preserve its objective, outcome, and session here.

Comments
TA
tuist-atlas[bot] Jun 6, 2026

This fix is now available in xcresult-processor-image@0.12.0. Update to this version to get it.

TA
tuist-atlas[bot] Jun 6, 2026

The fix for configuring STS region for IRSA is now available in server@1.207.0. Update to get this fix.