Skip to content

[DCV-3896] Document IAM role (IRSA) auth for the AWS Secrets Manager backend - #58

Merged
noel merged 1 commit into
mainfrom
DCV-3896-aws-irsa-docs
Aug 18, 2026
Merged

[DCV-3896] Document IAM role (IRSA) auth for the AWS Secrets Manager backend#58
noel merged 1 commit into
mainfrom
DCV-3896-aws-irsa-docs

Conversation

@gams87

@gams87 gams87 commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Adds an "Use an IAM role instead of access keys (IRSA)" section to the AWS Secrets Manager configure page, plus a tip in Prereqs pointing to it.

Covers when it applies (Datacoves running on EKS), the per-environment IAM role trust policy scoped to system:serviceaccount:dcw-<environment-slug>:datacoves-airflow, the keyless backend configuration (no aws_access_key_id / aws_secret_access_key), and the notes that the setup is coordinated with the Datacoves platform team and that Airflow 3 environments require Datacoves 6.1+.

Companion to datacoves/datacoves#1589 (DCV-3896), which fixes the Airflow 3 api-server pinning that identity-based secrets backends need; publish together with the release that carries it.

🤖 Generated with Claude Code

@gams87
gams87 requested a review from noel August 17, 2026 20:18
@noel
noel merged commit e613f9a into main Aug 18, 2026
2 checks passed
@noel
noel deleted the DCV-3896-aws-irsa-docs branch August 18, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants