ExpiredTokenException with 3.4.0 and assuming IAM role
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 23.1k
- Forks
- 1.1k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 9
Description
I have been using 3.4.0 for the last few months without issue in ECS with assuming an IAM role for KMS permissions. In the last few days, I have been getting:
2020-02-02 12:14:52- | Error decrypting key: ExpiredTokenException: The security
2020-02-02 12:14:52| token included in the request is expired
2020-02-02 12:14:52| status code: 400, request id:
2020-02-02 12:14:52| xxxxxxxxx
Is this something that is fixed with 3.5.0? Any advice if the IAM permissions are in order? This happened previously with a pre-3.4.0 version and upgrading to 3.4.0 initially fixed it. No other changes have occurred in my environment.
Thoughts appreciated.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are identified in the report. Start by reproducing the expired-token failure around ECS IAM-role assumption and compare credential-refresh behavior across versions 3.4.0 and 3.5.0; done means identifying the cause and documenting a confirmed fix or actionable configuration change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, go
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100