Changing the default authentication methods in the AWS go SDK v2

Viewed 110

By default, the golang AWS SDK v2 will use the following chain to determine credentials:

  • environment variables
  • shared config
  • ECS task role (if ECS task)
  • EC2 instance profile (if running on EC2)

I have a situation where I need to configure the SDK to ignore the first two (specifically environment variables)... we have a CI workflow where it's possible for AWS environment variables to be set for testing reasons, but we have a service for automating change requests in our change tracking system that should ONLY ever use ECS or EC2 credentials for authentication. The tooling we're using for accessing the change requests is written in go.

The v1 SDK actually had a NewChainCredentials function for creating a new chain, but that is gone in v2. Reading the code seems to indicate it's POSSIBLE to create a new credentials chain, but I haven't been able to figure out how to replace the default chain with just the ECS and EC2 providers.

Has anybody done this? Searching through Google and GitHub hasn't turned up anything that looks like what I want - mostly I find out to replace the default chain with a custom provider or add a new provider to the chain, but trying to use those methods to replace the default chain with the one I want have been unsuccessful.

0 Answers
Related