Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

IC Groups deletion delayed when removing last Account Assignment #48959

Open
tcsc opened this issue Nov 14, 2024 · 0 comments
Open

IC Groups deletion delayed when removing last Account Assignment #48959

tcsc opened this issue Nov 14, 2024 · 0 comments

Comments

@tcsc
Copy link
Contributor

tcsc commented Nov 14, 2024

Expected behavior:

When I remove the last role containing an account assignment role from an Access List, the corresponding group should be immediately deleted in AWS Identity Center

Current behavior:

The Identity Center group persists until the next full provisioning cycle (default interval ~5 mins) and is then deleted from Identity Center

Working Theory:

The IC provisioning system only attempts to provision Access Lists where the access list has at least one Account Assignment granted by a role. Once the last account-assignment granting role is removed from the Access List, the provisioning system disregards any events on that list, including noticing that it needs to delete the corresponding group.

Situation should be detectable by checking if an excluded Access List has an existing provisioning state. If it does, then the provisioning system should delete the downstream group (and the provisioning state record) immediately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants