aws / aws/amazon-cloudwatch-agent

Support Credentials from IAM Roles Anywhere

Open
#1,241 5 comments 1 reaction 0 assignees View on GitHub
question status/backlog
Dominant language
Go
Stars
550
Forks
271
Avg merge
1d 21h
Merged PRs (30d)
13

Description

**Is your feature request related to a problem? Please describe.**
When I using credentials from IAM Roles Anywhere, I'm unable to use Cloudwatch Agent, since in OnPrem mode it looks for hard-coded Access Keys in the .aws config files

**Describe the solution you'd like**
I'd like to use the standard IAM Roles Anywhere service, or the credential_process.

**Additional context**
I've persued the "RUN_WITH_IRSA" config mode, but this is very poorly documented and also doesn't seem to solve the issue.

Contributor guide

Open the contributing guide

Research direction

Start by tracing the OnPrem credential-loading path that reads the .aws configuration files, then review the RUN_WITH_IRSA configuration and its documentation. Check how credential_process and IAM Roles Anywhere credentials are expected to be selected; done means the CloudWatch Agent can obtain credentials through the requested standard mechanism without hard-coded access keys.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go
Domain
authentication, cloud
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.