aws / aws/amazon-redshift-python-driver

Support 'external_id' for temporary credentials

Đang mở
#109 3 bình luận 0 reaction 0 người được giao Xem trên GitHub
enhancement
Ngôn ngữ chính
Python
Star
220
Fork
86
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

## Driver version

v2.0.907 [Latest](https://github.com/aws/amazon-redshift-python-driver/releases/latest)

## Redshift version

N/A

## Client Operating System

N/A

## Python version

N/A

## Table schema

N/A

## Problem description

1. Expected behaviour: Library is able to use EKS IRSA / AWS SSO to discovery credential, then use `AssumeRole` with `role_arn` and `external_id` to receive current one.
2. Actual behaviour: No support for `external_id`.
4. Error message/stack trace: N/A
5. Any other details that can be helpful:

Partner Hosted Foundational Technical Review requires "CAA-002 - Use external ID with cross-account roles to access customer accounts."

Credential management is already supported. In my opinion, AWS SDK (in this scenario `boto3`) defines the credentials standard for IAM that is adopted for language in AWS. In my opinion, this library should only receive instance `boto3.Session` to build proper IAM credentials on its own. It allows use `aws-assume-role-lib` ( https://github.com/benkehoe/aws-assume-role-lib ) to automatically refresh credentials when reconnection happens (The fact that it is an external library is a separate problem in boto3 because [JavaScript](https://docs.aws.amazon.com/AWSJavaScriptSDK/latest/AWS/TemporaryCredentials.html) / Java ( https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/com/amazonaws/auth/STSAssumeRoleSessionCredentialsProvider.html ) has the appropriate built-in credential provider.). Then a large amount of code - repeated in relation to boto3 - regarding the use of credential management will become redundant.

## Python Driver trace logs

## Reproduction code

```python
import redshift_connector

# Connects to Redshift cluster using AWS credentials
conn = redshift_connector.connect(
host='examplecluster.abc123xyz789.us-west-1.redshift.amazonaws.com',
database='dev',
user='awsuser',
role_arn='aws:...',
external_id='...'
)
```

CC: @podpio

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start at the redshift_connector.connect example and trace how role_arn credentials are obtained. Review the requested boto3.Session and AssumeRole flow, including external_id and credential refresh on reconnection. Done means the connector accepts external_id for temporary credentials and the documented reproduction flow works.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
aws, python
Lĩnh vực
authentication, cloud, databases
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
38/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.