Skip to content
This repository was archived by the owner on May 12, 2026. It is now read-only.
This repository was archived by the owner on May 12, 2026. It is now read-only.

For AWS Credentials , can we use AWSCredentialsProviderChain . This will provide the credentials if the application running on EC2, ECS, EKS ,etc or from default env variables. #714

Activity

  1. sankalpkale88 commented on Aug 5, 2021

    @sankalpkale88
    Author

    @VisibleForTesting
    AwsSecurityCredentials getAwsSecurityCredentials() throws IOException {

    AWSCredentialsProvider awsCredentialsProvider = DefaultAWSCredentialsProviderChain.getInstance();
    AWSCredentials awsCredentials = awsCredentialsProvider.getCredentials();
    if (awsCredentials instanceof BasicSessionCredentials){
      BasicSessionCredentials basicSessionCredentials = (BasicSessionCredentials) awsCredentials;
      return new AwsSecurityCredentials(basicSessionCredentials.getAWSAccessKeyId(),
              basicSessionCredentials.getAWSSecretKey(),basicSessionCredentials.getSessionToken());
    }
    return new AwsSecurityCredentials(awsCredentials.getAWSAccessKeyId(), awsCredentials.getAWSSecretKey(),null);
    

    }

  2. added
    type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.
    on Aug 6, 2021
  3. oprigan-cgi commented on Aug 18, 2021

    @oprigan-cgi

    We have the same problem when using the lib in AWS Lambda.

    AWS Lambda is using an assumed IAM Role with temporary security credentials and therefore It is not possible to create a valid subject token to be exchanged with sts.googleapis.com.

    In AWSCredentials the following code exists:

      @VisibleForTesting
      AwsSecurityCredentials getAwsSecurityCredentials() throws IOException {
        // Check environment variables for credentials first.
        String accessKeyId = getEnvironmentProvider().getEnv("AWS_ACCESS_KEY_ID");
        String secretAccessKey = getEnvironmentProvider().getEnv("AWS_SECRET_ACCESS_KEY");
        String token = getEnvironmentProvider().getEnv("Token");
        if (accessKeyId != null && secretAccessKey != null) {
          return new AwsSecurityCredentials(accessKeyId, secretAccessKey, token);
        }
        ...
    
    

    As @sankalpkale88 mentioned the provider chain could be a possible solution.

    On the other hand the environment variable for the session token in an AWS environment is named "AWS_SESSION_TOKEN" and not "Token" so this could be another approach to fix the issue.

        String token = getEnvironmentProvider().getEnv("AWS_SESSION_TOKEN");
    

    Refer to Python library google-auth-library-python where the processing of temporary security credentials is correctly implemented.

    Kind regards,
    Oliver

  4. TimurSadykov commented on Nov 30, 2021

    @TimurSadykov

    @oprigan-cgi Could you please confirm if this issue now resolved? Given the one of the possible solutions got implemented.

  5. pwalczak commented on Oct 21, 2022

    @pwalczak

    Hi team!

    Is there some plan to implement this? This would allow services deployed on AWS EKS using IRSA to get successfully the GCP tokens using WIF.

    Thanks!
    Piotrek

  6. TimurSadykov commented on Oct 22, 2022

    @TimurSadykov

    @pwalczak please clarify what exactly are you referring to? The AWSCredentialsProviderChain or something else? The original issue got mitigated by a related fix: #723

  7. pwalczak commented on Oct 25, 2022

    @pwalczak

    Hi @TimurSadykov. Yes, the AWSCredentialsProviderChain. Especially if there are any plans to enhance AwsCredentials class to support reading AWS credentials using WebIdentityTokenFileCredentialsProvider method.

    I am having a use case that I have my service deployed on AWS EKS cluster which uses IRSA mechanism. Metadata service access is blocked. With the usage of AWSCredentialsProviderChain (especially WebIdentityTokenFileCredentialsProvider) I can get my AWS credentials using the AWS SDK, however the AWSCredentials class from the google-auth-library does not support this method of retrieving credentials. The AWSCredentials class (especially

    AwsSecurityCredentials getAwsSecurityCredentials(Map<String, Object> metadataRequestHeaders)
    ) only scans the environment variables and if nothing is found it jumps to metadata service.

  8. sankalpkale88 commented on Jan 25, 2023

    @sankalpkale88
    Author

    Hi @TimurSadykov , Any update on this ?

  9. TimurSadykov commented on Jan 30, 2023

    @TimurSadykov

    @lsirac could you please comment?

  10. lsirac commented on Jan 31, 2023

    @lsirac
    Contributor

    We're aware of the gaps and will update when we add support for this.

  11. michalstefanext commented on Mar 14, 2023

    @michalstefanext

    Hi @TimurSadykov @Isirac, do you have at least some rough ETA, when this could be introduced please?

  12. TimurSadykov commented on Mar 30, 2023

    @TimurSadykov

    @michalstefanext hopefully sometime next week

  13. lsirac commented on Mar 31, 2023

    @lsirac
    Contributor

    @michalstefanext hopefully sometime next week

    Timur means next half :)

  14. aeitzman commented on Feb 7, 2024

    @aeitzman
    Contributor

    Added support for using a custom implementation to supply AWS security credentials in #1336, released in v1.23.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions