Skip to content

Verify credential acquisition with an unmodified AWS SDK #224

Description

@alukach

Phase 5 — API keys.

Do
Confirm a stock AWS SDK acquires and refreshes credentials from AWS_WEB_IDENTITY_TOKEN_FILE, AWS_ROLE_ARN and AWS_ENDPOINT_URL_STS alone, with no Source-specific code.

Done when
A plain boto3 script runs unattended across a credential expiry and keeps working.

Why it matters
This is the property that makes unattended operation real: the SDK re-reads the token file on refresh, so key rotation is invisible to the application.

Depends on source-cooperative/source.coop#548.


Part of source-cooperative/source.coop#491.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions