One of the use case is to allow dynamic addition of IAM roles while instantiating s3 resources to gain additional (or different) permissions, or get permissions to perform actions in a different AWS account.

Comments

arpitr created an issue. See original summary.

nitesh624’s picture

Assigned: Unassigned » nitesh624
nitesh624’s picture

StatusFileSize
new3.89 KB
new11.06 KB

Add configuration to use IAM roles under "/admin/config/media/s3fs"
Only local images are allowed.

nitesh624’s picture

Assigned: nitesh624 » Unassigned
tdnshah’s picture

Assigned: Unassigned » tdnshah
tdnshah’s picture

StatusFileSize
new4.56 KB

Updated patch with changes added to test

tdnshah’s picture

StatusFileSize
new7.81 KB

Schema file updated with the aws roles config settings and improved upon the coding standard.

tdnshah’s picture

Assigned: tdnshah » Unassigned
Status: Active » Needs review
bunty badgujar’s picture

StatusFileSize
new11.15 KB

Re-rolling patch with exception handling, check for role_external_id and schema update.

Status: Needs review » Needs work

The last submitted patch, 9: 3120052-9.patch, failed testing. View results
- codesniffer_fixes.patch Interdiff of automated coding standards fixes only.

bunty badgujar’s picture

StatusFileSize
new11.54 KB

Unit test issue fix.

bunty badgujar’s picture

Status: Needs work » Needs review
skyredwang’s picture

Status: Needs review » Needs work

#11 patch no longer applies to alpha16, needs a reroll

raman.b’s picture

Status: Needs work » Needs review
StatusFileSize
new11.59 KB

Re-rolled for the latest dev branch

cmlara’s picture

Added a patch in #3121830: Use CredentialProvider::defaultProvider rather than individual providers that I believe will solve this in a way that makes more sense than adding more UI elements.

I believe if one uses a custom INI written as follows:

[default]
role_arn = arn:aws:iam::123456789012:role/role-name
role_session_name = maria_garcia_role
external_id = TheExternalID

That the new patch will work. I believe one could actually do this with the current GUI by checking "USE EC2" and than adding the INI file but that is not obvious to administrators.

Reference Guide for config files: https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-files.html

cmlara’s picture

Status: Active » Fixed

As noted in #15 I believe the changes commited under #3121830: Use CredentialProvider::defaultProvider rather than individual providers should solve this without adding a graphical UI by using config files.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.