Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-12767

Allow use of instance roles instead of credentials with S3 storage

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 5.7.3, 5.8
    • Fix Version/s: 5.9.1
    • Component/s: Core VCS

      Description

      The S3 binary manager currently requires use of the AWS Access Key Id and AWS Secret Access Key.
      It should also be able to handle IAM instance roles, which allow the use of automatically retrieved temporary id/secret keys.

      This requires extending the AmazonS3Client and AmazonS3EncryptionClient to detect errors due to expired credentials on operations, and automatically renew them and retry the operation.

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - 2 days
                2d
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 4 hours Time Not Required
                4h