fix(amazon): use session.NewSession so IRSA credentials are resolved - #1007
Merged
Merged
Conversation
session.New() routes through deprecatedNewSession, which pins the credential chain to EnvProvider, SharedCredentialsProvider and RemoteCredProvider. That chain has no web identity provider, so a pod running with IRSA on EKS fails with "NoCredentialProviders: no valid providers in chain" even when AWS_ROLE_ARN and AWS_WEB_IDENTITY_TOKEN_FILE are correctly injected. session.NewSession() resolves credentials through resolveCredentials, which handles the web identity case explicitly.
Collaborator
|
@svillegas-flores thanks for contributing ~ I will give it a look . |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Replace the deprecated
session.New()withsession.Must(session.NewSession())in the three S3 backend constructors.Why
session.New()routes throughdeprecatedNewSession, which setscfg.Credentials = defaults.CredChain(...). That chain is fixed toEnvProvider,SharedCredentialsProviderandRemoteCredProvider— it has no web identity provider, so a pod running with IRSA on EKS fails with:even though
AWS_ROLE_ARNandAWS_WEB_IDENTITY_TOKEN_FILEare correctly injected.session.NewSession()usesresolveCredentials, which handles the web identity case explicitly (aws/session/credentials.go, thelen(envCfg.WebIdentityTokenFilePath) != 0branch).WebIdentityTokenFilePathis populated unconditionally from the environment inenvConfigLoad, so noAWS_SDK_LOAD_CONFIGis required.This complements #907, which added EKS Pod Identity support: Pod Identity works because
RemoteCredProvideris in the deprecated chain, but IRSA is not reachable from it.Notes
Everything else is unchanged: the per-call
aws.Configstill overrides region, endpoint and credentials, soNewAmazonS3BackendWithCredentialsbehaves exactly as before.amazon.gois left unformatted on purpose, matching 62f6224.Verified with
go build ./...andgo vet ./.... The test suite is integration-only and needs live buckets, so it was not run.