- Notifications
You must be signed in to change notification settings - Fork146
Add support for assuming the role specified in AWS_ROLE_ARN when not using WebIdentity#121
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Draft
atom-andrew wants to merge1 commit intonginx:masterChoose a base branch fromatom-computing:assume-role
base:master
Could not load branches
Branch not found:{{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline, and old review comments may become outdated.
Uh oh!
There was an error while loading.Please reload this page.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters
…ILE is missingAllow use of AssumeRole to assume the desired identify when web identity is not in useAlso update some signature code to explicitly pass through the desired method instead of assuming it matches the request.Finally, make it more obvious in signature code that signed components are path rather than a full uri.
This PR has been in a draft state for some time. Can I answer any questions or help in any way? |
igor-nikiforov commentedNov 2, 2023
@atom-andrew any chance that this PR will be completed? We're looking for this feature as well. Thanks! |
Hi@igor-nikiforov , thanks for reaching out. I don't have plans to continue work on this but please feel free to pick it up and run with it. |
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Assume the role specified in AWS_ROLE_ARN if AWS_WEB_IDENTITY_TOKEN_FILE is missing.
Also update some signature code to explicitly pass through the desired method instead of assuming it matches the request. Finally, make it more obvious in signature code that signed components are path rather than a full uri.