Failing to get IAM User Credentials for AWSSDK in Asp.NET Core Web API

Viewed 350

I am attempting to leverage AWS' SDK for .NET Core within my API, using the following documentation provided by Amazon: Configuring the AWS SDK for .NET with .NET Core.

I have within the AWS Explorer VS Extension created a 'Default' profile, installed the AWSSDK.Extensions.NETCore.Setup NuGet Package (along with AWSSDK.ServiceCatalog which is the service I intend to access), and included their middleware likeso:

StartUp.cs

using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.AspNetCore.Builder;
using Microsoft.AspNetCore.Hosting;
using Microsoft.AspNetCore.HttpsPolicy;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Configuration;
using Microsoft.Extensions.DependencyInjection;
using Microsoft.Extensions.Hosting;
using Microsoft.Extensions.Logging;
using Microsoft.Identity.Web;
using System;
using System.Collections.Generic;
using System.Linq;
using System.Threading.Tasks;
using Amazon.ServiceCatalog;
using Amazon.Extensions.NETCore.Setup;

namespace AWS_Service_Catalog_API
{
    public class Startup
    {
        public Startup(IConfiguration configuration)
        {
            Configuration = configuration;
        }

        public IConfiguration Configuration { get; }

        // This method gets called by the runtime. Use this method to add services to the container.
        public void ConfigureServices(IServiceCollection services)
        {
            //Enables authentication using Microsoft Azure requiring JSON Web Token passed in with request to API
            services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
                .AddMicrosoftIdentityWebApi(Configuration, "AzureAd")
            //Enables Controllers to fetch API Token. This will be used to call Microsoft Graph API for Plan/Task data
                .EnableTokenAcquisitionToCallDownstreamApi()
            //It is OK if the token cache is cleared when API is restarted
                .AddInMemoryTokenCaches();

            services.AddDefaultAWSOptions(Configuration.GetAWSOptions());
            services.AddAWSService<IAmazonServiceCatalog>();

            services.AddControllers().AddJsonOptions(options =>
            {
                //Enables 'pretty' output of response JSON data
                options.JsonSerializerOptions.WriteIndented = true;
            });

            services.AddAuthorization();
        }

        // This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
        {
            if (env.IsDevelopment())
                app.UseDeveloperExceptionPage();
            else
                app.UseHsts();

            app.UseHttpsRedirection();

            app.UseRouting();
            app.UseAuthentication();
            app.UseAuthorization();

            app.UseEndpoints(endpoints =>
            {
                endpoints.MapControllers();
            });
        }
    }
}

I then inject the client into my controller likeso:

private readonly IConfiguration _configuration;
        private IAmazonServiceCatalog _amazonServiceCatalogClient;
        public ServerController(IConfiguration configuration, IAmazonServiceCatalog _amazonServiceCatalogClient)
        {
            this._configuration = configuration;
            this._amazonServiceCatalogClient = _amazonServiceCatalogClient;
        }

In my appsettings.json (when I try appsettings.development.json it errors out. My API is in development mode so honestly who knows.) I have added the following:

"AWS": {
    "Profile": "Default",
    "Region": "us-east-1"
  },

The issue I have, from what I can tell, is that my API is not detecting my profile/credentials and is attempting to pull an Instance Profile - as I will receive the following error when attempting to send a request:

 unable to get iam security credentials from ec2 instance metadata service

So any thoughts on how to resolve would be awesome. Thanks!

0 Answers
Related