Has anyone had success in using an AWS ECS task ro...
# lucee
m
Has anyone had success in using an AWS ECS task role credentials with Lucee’s s3? I have a simple onServerStart method that gets the credentials from the
AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
and makes them available for Application.cfc level params. However, haven’t quite got the permissions to work as expected. Is there a gotcha that makes it all now work?
g
I am not sure if this is helpful or not... We get AWS credentials from the secrets manager via the AWS CLI and store secrets in environment variables. Then use those in CFML.
Copy code
//read up on how how to use the AWS CLI if you don't already know
//Access the secrets manager
aws_secrets=$(aws secretsmanager get-secret-value ... )

//Get the DB Password.
db_secretstring=$(echo $aws_secrets | python -c 'import json,sys;obj=json.load(sys.stdin);print obj["SecretString"]')
db_password=$(echo $db_secretstring | python -c 'import json,sys;obj=json.load(sys.stdin);print obj["password"]')
With the above there is now a system environment variable "db_password" And we access it in code with the server.system.environment scope.
m
Right now the ask from the client is use the ECS permissions to access to S3. But that is pretty cool
👍🏼 1
Definitely come in handy
p
I think, from memory that the AWS stuff in ACF reliese on access keys not IAM
I kinda remember last when I was messing with ACF that I ended up using the native java library which does use IAM as I wasn;t keen on created keys.
d
We tried doing something like this with s3 as a virtual mapping but the IAM role/ECS container creds dont work with Lucees S3 implementation which uses a key and a secret. If you use the aws-cfml library to access S3 it will work fine using IAM roles or ECS creds
d
I second the aws-cfml library (an html wrapper for the aws api) makes life much easier than trying to use native cfml stuff, also the secrets manager and or the system manager parameter store are both useful ways to store credentials to get at either runtime or environment variables.
m
I’m getting that it doesn’t work. It’s just disappointing that the reason given is that you need a key and secret key. Which is what you get from
Copy code
<http://169.254.170.2>$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
from within the container. So I have keys. It’s just that for some reason the retrieved keys are not useful.
I just had a co-worker say that with task base IAM credentials you have to also pass the
Token
value that is returned from the same `
Copy code
<http://169.254.170.2>$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
endoint.
So it may be that missing token and not keys that stops it from working
j
i'm interested in knowing how this shakes out, because i've wanted to explore AWS role-based permissions for S3 access.
d
So it may be that missing token and not keys that stops it from working
Yes, this. Lucee doesnt have the ability to natively use temporary credentials (though, we have looked at the source code and it wouldnt be a stretch to fix that, considering it uses the AWS Java libraries) We rely heavily on S3 for storage and aws-cfml works great