node S3 Object Storage Linode

Viewed 347

Im trying to use the aws-sdk to acces my linode S3 compatible bucket, but everything I try doesn't work. Not sure what the correct endpoint should be? For testing purposes is my bucket set to public read/write.

const s3 = new S3({
  endpoint: "https://linodeobjects.com",
  region: eu-central-1,
  accesKeyId: <accesKey>,
  secretAccessKey: <secretKey>,
});

const params = {
  Bucket: bucketName,
  Key: "someKey",
  Expires: 60,
};

const uploadURL = await s3.getSignedUrlPromise("putObject", params);

The error im getting

code: 'CredentialsError',
  time: 2021-07-15T08:29:50.000Z,
  retryable: true,
  originalError: {
    message: 'Could not load credentials from any providers',
    code: 'CredentialsError',
    time: 2021-07-15T08:29:50.000Z,
    retryable: true,
    originalError: {
      message: 'EC2 Metadata roleName request returned error',
      code: 'TimeoutError',
      time: 2021-07-15T08:29:49.999Z,
      retryable: true,
      originalError: [Object]
    }
  }
}
2 Answers

It seems like a problem with the credentials of the environment that this code is executed in and not with the bucket permissions themselves.

The pre-signing of the URL is an operation that is done entirely locally. It uses local credentials (i.e., access key ID and secret access key) to create a sigv4 signature for the URL. This also means that whether or not the credentials used for signing the URL are valid is only checked at the moment the URL is used, and not at the moment of signing the URL itself.

The error simply indicates that from all the ways the SDK is trying to find credentials (more info here) it cannot find credentials it can use to sign the URL.

This might be unrelated, but according to the documentation, the endpoint should be the following: The endpoint URI to send requests to. The default endpoint is built from the configured region. The endpoint should be a string like 'https://{service}.{region}.amazonaws.com' or an Endpoint object. Which, in the code example above, is not the case.

You should set the endpoint to be eu-central-1.linodeobjects.com. When using Linode object storage the region is not determined by the endpoint that you use.

Related