Additional Configuration Options
This page collects Configuration Values that do not belong to a single feature: TAP Dashboard request logging, and conditions that scope an individual Rewriter or Filter.
AWS API Request Logging
Combine can log the AWS API Requests that pass through it to a DynamoDB table for auditing and analysis. This log is separate from the Combine Log described in View Combine Logs.
FIPS Endpoints
The Federal Information Processing Standard (FIPS) 140 defines security requirements for cryptographic modules that protect sensitive information. AWS provides FIPS endpoints for many services. These alternate service endpoints use FIPS 140 validated cryptographic modules for TLS encryption, so applications can communicate with AWS services using cryptography that operates in FIPS-approved mode.
IAM User Credential Lookup
IAM User Credential Lookup lets Combine proxy a request signed by an IAM User while preserving the caller identity.
Kubernetes Proxy Access Control
You can configure the Combine Kubernetes Proxy to allow or deny requests based on the source IP address (an individual IP address or a CIDR block) or the IAM Role ARN that signed the request. For guidance on using AWS EKS with Combine, see Combine EKS Support.
PKI Certificate Parameters
You can customize the certificates that Combine's PKI generates, including key size, signing algorithm, private key encryption, and additional DNS names. You can also set the key size and signing algorithm from the TAP Dashboard, in the Certificate Settings section of Admin Settings > TAP Settings > Application Configuration.
PKI Certificates: CSR Signing API
Combine provides an API that signs Certificate Signing Requests (CSRs). It exists only so that customers who want to use a CSR do not have to upload each CSR to Combine by hand.
PKI Certificates: OCSP Support
Combine supports the Online Certificate Status Protocol (OCSP) and provides an OCSP Responder Endpoint through the TAP Servers. Combine 3.13.2 added OCSP support.
Request Reflection
Request Reflection lets a signed stsGetCallerIdentity call to prove who they are to another server (see Authentication via sts:GetCallerIdentity on the Known Issues page).
Resource Role Masquerade
Resource Role Masquerade lets Combine assume the IAM Role attached to an AWS resource, such as an EC2 Instance Profile or a Lambda execution role, when it cannot otherwise infer the credentials that signed an AWS API Call. This preserves the caller identity instead of falling back to the Default Role (see Change the Default Role).
User-Agent Header Injection
Combine can inject a SequoiaCombine/ string into the User-Agent header of each AWS API Call it handles. This lets downstream AWS services or logging systems identify traffic that has passed through Combine.
VPC Wrapping
VPC Wrapping deploys Combine into a VPC that already exists by "wrapping" it, instead of building a new VPC. This lets you deploy Combine without permissions to create network resources.