Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-8594

STS with Web Identity Support for AWS S3 [3.13]

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • None

      See feature for details. https://issues.redhat.com/browse/PROJQUAY-8576

      Currently, STS support requires an IAM user with static credentials to be provided in order to assume a role for S3 access. Customers in secure environments often disallow IAM users in favor of a web identity solution for workloads running on top of OpenShift such as Quay (see PROJQUAY-5850 for a broader effort around CCO credentials).

      However, it would be useful for customers to be able to use their own managed web identities (such as IRSA service account annotations) for authentication outside of the management of CCO. This would also be foundational work required for PROJQUAY-5850.

              jonathankingfc Jonathan King (Inactive)
              bcaton@redhat.com Brandon Caton
              Votes:
              1 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: