Skip to content

fix(amazon): use session.NewSession so IRSA credentials are resolved - #1007

Merged
scbizu merged 1 commit into
chartmuseum:mainfrom
svillegas-flores:fix/irsa-credentials
Sep 6, 2026
Merged

scbizu merged 1 commit into
chartmuseum:mainfrom
svillegas-flores:fix/irsa-credentials

Conversation

@svillegas-flores

Copy link
Copy Markdown
Contributor

What

Replace the deprecated session.New() with session.Must(session.NewSession()) in the three S3 backend constructors.

Why

session.New() routes through deprecatedNewSession, which sets cfg.Credentials = defaults.CredChain(...). That chain is fixed to EnvProvider, SharedCredentialsProvider and RemoteCredProvider — it has no web identity provider, so a pod running with IRSA on EKS fails with:

NoCredentialProviders: no valid providers in chain. Deprecated.

even though AWS_ROLE_ARN and AWS_WEB_IDENTITY_TOKEN_FILE are correctly injected.

session.NewSession() uses resolveCredentials, which handles the web identity case explicitly (aws/session/credentials.go, the len(envCfg.WebIdentityTokenFilePath) != 0 branch). WebIdentityTokenFilePath is populated unconditionally from the environment in envConfigLoad, so no AWS_SDK_LOAD_CONFIG is required.

This complements #907, which added EKS Pod Identity support: Pod Identity works because RemoteCredProvider is in the deprecated chain, but IRSA is not reachable from it.

Notes

Everything else is unchanged: the per-call aws.Config still overrides region, endpoint and credentials, so NewAmazonS3BackendWithCredentials behaves exactly as before. amazon.go is left unformatted on purpose, matching 62f6224.

Verified with go build ./... and go vet ./.... The test suite is integration-only and needs live buckets, so it was not run.

session.New() routes through deprecatedNewSession, which pins the
credential chain to EnvProvider, SharedCredentialsProvider and
RemoteCredProvider. That chain has no web identity provider, so a pod
running with IRSA on EKS fails with "NoCredentialProviders: no valid
providers in chain" even when AWS_ROLE_ARN and
AWS_WEB_IDENTITY_TOKEN_FILE are correctly injected.

session.NewSession() resolves credentials through resolveCredentials,
which handles the web identity case explicitly.
@scbizu

scbizu commented Sep 6, 2026

Copy link
Copy Markdown
Collaborator

@svillegas-flores thanks for contributing ~ I will give it a look .

@scbizu
scbizu merged commit 276ff74 into chartmuseum:main Sep 6, 2026
0 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants