fix(ec2): DescribePrefixLists and gateway endpoint prefix-list routes - #1377
Merged
Merged
Conversation
…efix-lists # Conflicts: # providers/aws/vpc/tags.go # server/aws/ec2/tags.go
NitinKumar004
marked this pull request as ready for review
September 27, 2026 18:05
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Terraform
aws_vpc_endpointcould not refresh against cloudemu. Its read callsDescribePrefixListswith aprefix-list-namefilter to fillprefix_list_idandcidr_blocks, and that action was missing, so both Gateway and Interface endpoints failed withInvalidAction.What changed:
com.amazonaws.<region>.s3and.dynamodb) withprefixListId,prefixListNameandcidrSet. It supports theprefix-list-idandprefix-list-namefilters,PrefixListId.N,MaxResultsandNextToken. The pl- ids are derived from the list name, so they stay the same across calls and differ between regions. An unknown id returnsInvalidPrefixListID.NotFound, and an unknown filter returnsInvalidParameterValue.destinationPrefixListIdset to the service's pl- id andgatewayIdset to the vpce- id. ModifyVpcEndpoint route-table changes and DeleteVpcEndpoints keep those routes in step. EC2 allows one endpoint route per service in a route table, so a second s3 (or dynamodb) endpoint on the same table now fails withRouteAlreadyExists, on create and on modify. Deleting a route table also drops it from any endpoint that listed it.Add/RemoveRouteTableId,Add/RemoveSubnetIdandAdd/RemoveSecurityGroupIdas a delta inside the provider, under its lock, through a new optionalVPCEndpointSetModifiercapability. Before, the wire layer read the current sets, merged the change and wrote the whole set back, so parallel modifies lost updates. Terraform hit this when it created severalaws_vpc_endpoint_route_table_associationresources at once. Subnet changes on an Interface endpoint now add or release the matching ENIs. Create and Delete also hold the lock across the store write and the route sync, so a racing delete can't leave an orphan pl- route.ownerIdAWS,arn:aws:ec2:<region>:aws:prefix-list/...), and GetManagedPrefixListEntries can read them and now honoursMaxResults/NextToken. Like real EC2, the AWS-owned lists carry nomaxEntriesorversion. The describe call gained theprefix-list-id,prefix-list-name,owner-idand tag filters plus paging. An explicitly named id that doesn't exist is nowInvalidPrefixListID.NotFoundinstead of being silently dropped.The behaviour lives in the AWS VPC provider behind a new optional
ServicePrefixListscapability. The wire layer only handles filtering, paging and encoding.vpce tag support comes from #1335, which is already in development.
Depends on #1354 for groupSet. Without it, the Interface endpoint's
security_group_idsstill drifts on plan (nullvs the sg id). The Gateway endpoint plans clean on this PR alone.Deferred
InvalidPrefixListID.NotFound.Testing
providers/aws/vpc/service_prefix_list_test.go,providers/aws/vpc/endpoint_sets_test.go,server/aws/ec2/service_prefix_list_test.goandserver/aws/ec2/endpoint_modify_test.go. These include-racetests for concurrent ModifyVpcEndpoint adds/removes and parallel create/delete.go build ./..., thengo vetandgo test -raceon providers/aws/vpc, server/aws/ec2, services/networking/..., persist and features/topology.golangci-lint --new-from-rev=origin/developmentreports 0 issues, and coverage docs are regenerated.serve: describe-prefix-lists with and without filters, in us-west-2, with paging and with an unknown id; a Gateway s3 endpoint shows the pl- route and loses it on delete; an Interface ssm endpoint; the managed lists show owner AWS and their entries.aws_vpc_endpoint_route_table_associationresources) at default parallelism. Apply, clean plan, tag update, clean plan and destroy all pass, and the dynamodb endpoint ends up with all three tables.