aws / aws/amazon-redshift-python-driver
Support 'external_id' for temporary credentials
- Vorherrschende Sprache
- Python
- Sterne
- 220
- Forks
- 86
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
## Driver version
v2.0.907 [Latest](https://github.com/aws/amazon-redshift-python-driver/releases/latest)
## Redshift version
N/A
## Client Operating System
N/A
## Python version
N/A
## Table schema
N/A
## Problem description
1. Expected behaviour: Library is able to use EKS IRSA / AWS SSO to discovery credential, then use `AssumeRole` with `role_arn` and `external_id` to receive current one.
2. Actual behaviour: No support for `external_id`.
4. Error message/stack trace: N/A
5. Any other details that can be helpful:
Partner Hosted Foundational Technical Review requires "CAA-002 - Use external ID with cross-account roles to access customer accounts."
Credential management is already supported. In my opinion, AWS SDK (in this scenario `boto3`) defines the credentials standard for IAM that is adopted for language in AWS. In my opinion, this library should only receive instance `boto3.Session` to build proper IAM credentials on its own. It allows use `aws-assume-role-lib` ( https://github.com/benkehoe/aws-assume-role-lib ) to automatically refresh credentials when reconnection happens (The fact that it is an external library is a separate problem in boto3 because [JavaScript](https://docs.aws.amazon.com/AWSJavaScriptSDK/latest/AWS/TemporaryCredentials.html) / Java ( https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/com/amazonaws/auth/STSAssumeRoleSessionCredentialsProvider.html ) has the appropriate built-in credential provider.). Then a large amount of code - repeated in relation to boto3 - regarding the use of credential management will become redundant.
## Python Driver trace logs
## Reproduction code
```python
import redshift_connector
# Connects to Redshift cluster using AWS credentials
conn = redshift_connector.connect(
host='examplecluster.abc123xyz789.us-west-1.redshift.amazonaws.com',
database='dev',
user='awsuser',
role_arn='aws:...',
external_id='...'
)
```
CC: @podpio
Beitragsleitfaden
Rechercherichtung
Beginne beim Beispiel für redshift_connector.connect und verfolge, wie role_arn-Anmeldedaten abgerufen werden. Überprüfe den angeforderten boto3.Session- und AssumeRole-Ablauf einschließlich external_id und der Aktualisierung der Anmeldedaten bei einer erneuten Verbindung. Als erledigt gilt die Aufgabe, wenn der Connector external_id für temporäre Anmeldedaten akzeptiert und der dokumentierte Reproduktionsablauf funktioniert.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- aws, python
- Bereich
- authentication, cloud, databases
- Issue-Typ
- Feature
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 38/100