Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-8576

STS with Web Identity Support for AWS S3

XMLWordPrintable

    • Icon: Feature Feature
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected

      Currently, STS support requires an IAM user with static credentials to be provided in order to assume a role for S3 access. Customers in secure environments often disallow IAM users in favor of a web identity solution for workloads running on top of OpenShift such as Quay (see PROJQUAY-5850 for a broader effort around CCO credentials).

      However, it would be useful for customers to be able to use their own managed web identities (such as IRSA service account annotations) for authentication outside of the management of CCO. This would also be foundational work required for PROJQUAY-5850.

       

      See this upstream PR for suggested implementation from a customer: https://github.com/quay/quay/pull/3670

              Unassigned Unassigned
              aaustin@redhat.com Andrew Austin Byrum
              Votes:
              3 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: