Allow dynamic assumeRoleArn in Athena driver config
- Dominant language
- Rust
- Stars
- 20.8k
- Forks
- 2.1k
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 181
Description
Apologies if there is another way to do this, but I tried multiple approaches with no results..
**Is your feature request related to a problem? Please describe.**
The Athena driver only reads assumeRoleArn from environment variables. In multi-tenant setups, it is not possible to pass a tenant-specific assume-role ARN via the driver config.
**Describe the solution you'd like**
Allow the driver to accept assumeRoleArn (and optionally assumeRoleExternalId) from the driver config, prioritizing it over the environment variable. Example:
```
@config("driver_factory")
def driver_factory(context):
return {
type: 'athena',
database: '...',
assumeRoleArn: 'arn:aws:iam::123456789012:role/cube-tenant-XYZ',
assumeRoleExternalId: 'optional-external-id',
accessKeyId: '...',
secretAccessKey: '...',
region: 'us-east-1',
S3OutputLocation: 's3://...',
}
```
**Describe alternatives you've considered**
I tried to generate the credentials externally and pass it to the driver but this is also not supported.
**Additional context**
This change would simplify multi-tenant deployments where each tenant uses a unique Athena role.
Contributor guide
Assessment
This issue has not been assessed yet.