Skip to content

fix(ec2): DescribePrefixLists and gateway endpoint prefix-list routes - #1377

Merged
NitinKumar004 merged 4 commits into
developmentfrom
fix/aws-ec2-prefix-lists
Sep 27, 2026
Merged

NitinKumar004 merged 4 commits into
developmentfrom
fix/aws-ec2-prefix-lists

Conversation

@NitinKumar004

@NitinKumar004 NitinKumar004 commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Terraform aws_vpc_endpoint could not refresh against cloudemu. Its read calls DescribePrefixLists with a prefix-list-name filter to fill prefix_list_id and cidr_blocks, and that action was missing, so both Gateway and Interface endpoints failed with InvalidAction.

What changed:

  • DescribePrefixLists returns the AWS service prefix lists for the caller's region (com.amazonaws.<region>.s3 and .dynamodb) with prefixListId, prefixListName and cidrSet. It supports the prefix-list-id and prefix-list-name filters, PrefixListId.N, MaxResults and NextToken. The pl- ids are derived from the list name, so they stay the same across calls and differ between regions. An unknown id returns InvalidPrefixListID.NotFound, and an unknown filter returns InvalidParameterValue.
  • Gateway endpoints now add a route to each of their route tables, with destinationPrefixListId set to the service's pl- id and gatewayId set to the vpce- id. ModifyVpcEndpoint route-table changes and DeleteVpcEndpoints keep those routes in step. EC2 allows one endpoint route per service in a route table, so a second s3 (or dynamodb) endpoint on the same table now fails with RouteAlreadyExists, on create and on modify. Deleting a route table also drops it from any endpoint that listed it.
  • ModifyVpcEndpoint applies Add/RemoveRouteTableId, Add/RemoveSubnetId and Add/RemoveSecurityGroupId as a delta inside the provider, under its lock, through a new optional VPCEndpointSetModifier capability. Before, the wire layer read the current sets, merged the change and wrote the whole set back, so parallel modifies lost updates. Terraform hit this when it created several aws_vpc_endpoint_route_table_association resources at once. Subnet changes on an Interface endpoint now add or release the matching ENIs. Create and Delete also hold the lock across the store write and the route sync, so a racing delete can't leave an orphan pl- route.
  • DescribeManagedPrefixLists also returns the AWS-owned lists (ownerId AWS, arn:aws:ec2:<region>:aws:prefix-list/...), and GetManagedPrefixListEntries can read them and now honours MaxResults/NextToken. Like real EC2, the AWS-owned lists carry no maxEntries or version. The describe call gained the prefix-list-id, prefix-list-name, owner-id and tag filters plus paging. An explicitly named id that doesn't exist is now InvalidPrefixListID.NotFound instead of being silently dropped.

The behaviour lives in the AWS VPC provider behind a new optional ServicePrefixLists capability. The wire layer only handles filtering, paging and encoding.

vpce tag support comes from #1335, which is already in development.

Depends on #1354 for groupSet. Without it, the Interface endpoint's security_group_ids still drifts on plan (null vs the sg id). The Gateway endpoint plans clean on this PR alone.

Deferred

  • Per-region service CIDRs: every region currently reuses the published us-east-1 ranges for the s3 and dynamodb lists.
  • The specific EC2 error code for ModifyManagedPrefixList or DeleteManagedPrefixList on an AWS-owned list. Today it returns plain InvalidPrefixListID.NotFound.

Testing

  • New provider and SDK wire tests, written first and failing on the old code: providers/aws/vpc/service_prefix_list_test.go, providers/aws/vpc/endpoint_sets_test.go, server/aws/ec2/service_prefix_list_test.go and server/aws/ec2/endpoint_modify_test.go. These include -race tests for concurrent ModifyVpcEndpoint adds/removes and parallel create/delete.
  • go build ./..., then go vet and go test -race on providers/aws/vpc, server/aws/ec2, services/networking/..., persist and features/topology.
  • golangci-lint --new-from-rev=origin/development reports 0 issues, and coverage docs are regenerated.
  • aws CLI against serve: describe-prefix-lists with and without filters, in us-west-2, with paging and with an unknown id; a Gateway s3 endpoint shows the pl- route and loses it on delete; an Interface ssm endpoint; the managed lists show owner AWS and their entries.
  • Terraform (hashicorp/aws 6.x) with aws_vpc, aws_route_table and aws_vpc_endpoint (Gateway s3 with route_table_ids, and Interface ssm with a subnet and security group), all tagged: apply, clean plan, tag update, clean plan, destroy. This passes with the groupSet fix from feat: Kafka, Backup and DR, APIM and CDN control planes; ECS tag, VPC endpoint and PSC fidelity fixes #1354 in place.
  • Terraform, the lost-update repro: two Gateway endpoints (s3 with an inline route_table_ids, and dynamodb with three aws_vpc_endpoint_route_table_association resources) at default parallelism. Apply, clean plan, tag update, clean plan and destroy all pass, and the dynamodb endpoint ends up with all three tables.

@NitinKumar004
NitinKumar004 marked this pull request as ready for review September 27, 2026 18:05
@NitinKumar004
NitinKumar004 merged commit 9221793 into development Sep 27, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant