Repository navigation
minor: Add new intermediate S3 role - #20540
adarshsanjeev wants to merge 2 commits into
Conversation
| @JsonProperty("endpointConfig") @Nullable AWSEndpointConfig awsEndpointConfig, | ||
| @JsonProperty("clientConfig") @Nullable AWSClientConfig awsClientConfig | ||
| @JsonProperty("clientConfig") @Nullable AWSClientConfig awsClientConfig, | ||
| @JacksonInject @Nullable S3IntermediateRoleConfig intermediateRoleConfig |
There was a problem hiding this comment.
note: was just looking around; I know its a draft - but one thing caught my eye:
there are already some JacksonInject stuff already; couldn't it make sense to just reuse an exiting config instead of adding a new S3IntermediateRoleConfig and passing that to a lot of places?
There was a problem hiding this comment.
I was considering reusing AWSCredentialsConfig, but it's wasn't clear to me since it is not actually injected into all the classes I need. I would have to add it to places which might make it visible and, since it contains credentials, I figured I'd keep it separate in the initial PR.
There was a problem hiding this comment.
We already do have two classes bound to druid.s3 so it shouldn't break anything in terms of backward compatibility.
This pull request introduces support for configuring an intermediate AWS role to assume before the final role specified in S3 ingestion and export operations. This allows Druid clusters to use a fixed intermediate role, simplifying trust policies for S3 bucket owners.
druid.s3.intermediateAssumeRoleArn, which specifies an intermediate AWS role to assume before the finalassumeRoleArn.This PR has: