googleapis / googleapis/google-cloud-python
Support AWS_WEB_IDENTITY_TOKEN_FILE
Open
:rotating_light:
priority: p3
type: feature request
- Dominant language
- Python
- Stars
- 5.4k
- Forks
- 1.8k
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 122
Description
AWS service accounts can assume an identity using AWS_WEB_IDENTITY_TOKEN_FILE and AWS_ROLE_ARN.
https://aws.amazon.com/blogs/opensource/introducing-fine-grained-iam-roles-service-accounts
A call to `aws sts get-caller-identity` returns the correct assumed role, but `aws.py` doesn't seem to support this and [returns the cluster role](https://github.com/googleapis/google-auth-library-python/blob/49bb80551b526d9d0708f155a367a542f7567973/google/auth/aws.py#L628) instead.
I'm not sure how to support this programmatically, so filing a feature request hoping someone does.
Contributor guide
Assessment
This issue has not been assessed yet.