CloudWatch Logs: Limit CloudWatch logs queries to use logGroupIdentifiers only for monitoring accounts (#113137)

* Set the log group name when executing log queries from the frontend

* Add helper for a data source instance to check if its a monitoring account

* Execute log queries with log group identifiers only for monitoring account queries

* fix cloudwatch datasource.ts tests

* remove unneeded check
This commit is contained in:
Kevin Yu
2025-11-06 12:19:39 -08:00
committed by GitHub
parent 2ac4d0a13e
commit 69060f5437
6 changed files with 240 additions and 32 deletions
+32 -3
View File
@@ -6,6 +6,7 @@ import (
"fmt"
"net/http"
"slices"
"sync"
"time"
"github.com/aws/aws-sdk-go-v2/aws"
@@ -54,9 +55,10 @@ type DataSource struct {
ProxyOpts *proxy.Options
AWSConfigProvider awsauth.ConfigProvider
logger log.Logger
tagValueCache *cache.Cache
resourceHandler backend.CallResourceHandler
logger log.Logger
tagValueCache *cache.Cache
resourceHandler backend.CallResourceHandler
monitoringAccountCache sync.Map
}
func (ds *DataSource) newAWSConfig(ctx context.Context, region string) (aws.Config, error) {
@@ -273,6 +275,33 @@ func (ds *DataSource) getRGTAClient(ctx context.Context, region string) (resourc
return NewRGTAClient(cfg), nil
}
func (ds *DataSource) isMonitoringAccount(ctx context.Context, region string) (bool, error) {
if value, ok := ds.monitoringAccountCache.Load(region); ok {
cached := value.(bool)
return cached, nil
}
client, err := ds.GetAccountsService(ctx, region)
if err != nil {
return false, err
}
accounts, err := client.GetAccountsForCurrentUserOrRole(ctx)
if err != nil {
return false, err
}
for _, account := range accounts {
if account.Value.IsMonitoringAccount {
ds.monitoringAccountCache.Store(region, true)
return true, nil
}
}
ds.monitoringAccountCache.Store(region, false)
return false, nil
}
var terminatedStates = []cloudwatchlogstypes.QueryStatus{
cloudwatchlogstypes.QueryStatusComplete,
cloudwatchlogstypes.QueryStatusCancelled,