3 ms·
> Well yes, you can do that, but it won't be compatible with the cloud SDKs I am confused why you just could not use the AWS_WEB_IDENTITY_TOKEN_FILE. You coul
by gray_-_wolf 3y ago
> Well yes, you can do that, but it won't be compatible with the cloud SDKs
I am confused why you just could not use the AWS_WEB_IDENTITY_TOKEN_FILE. You could just produce that file for every user, refresh it before expiration and set the environment variable for each user. I believe that should work with the default SDK just fine, no?
I mean, sure, it is not exactly zero effort, but still seems fairly doable...
- cedws 3y agoI have only had a brief look but seems you would also need to specify the role ARN at least, so it would not be as simple as IMDS-sourced credentials. This solution is also AWS-specific, not sure how it would be solved for Google Cloud. It doesn't solve the issue of getting regular metadata without sidestepping the SDKs.