Credentials from a EC2 instance with instance-profile is not supported
Bug #2007966 reported by
Yoshi Kadokawa
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Canonical Juju |
Triaged
|
High
|
Thomas Miller |
Bug Description
At the moment, as far as I know the credentials for AWS provider,
using access key+secret access key is the only way.
However, there is also a way to retrieve the credentials from metadata(IMDS) when the EC2 instance is created with an instance-
I'm currently having a customer that has security policy that can not allow issuing access/security keys, but only allowing AWS API access from EC2 instance with the instance-profile configured.
As a reference, Terraform does support this method.[0]
Changed in juju: | |
milestone: | 3.1.2 → 3.1.3 |
Changed in juju: | |
milestone: | 3.1.3 → 3.1.4 |
Changed in juju: | |
milestone: | 3.1.4 → 3.1.5 |
Changed in juju: | |
milestone: | 3.1.5 → 3.1.6 |
Changed in juju: | |
milestone: | 3.1.6 → 3.1.7 |
To post a comment you must log in.
FYI we already support instance profiles on the controller https:/ /bugs.launchpad .net/juju/ +bug/2007966
We will look at adding support for instance profiles to the Juju client to work from jump hosts.