Phase 5 — API keys. Verification, not implementation — but it will find work.
Do
Confirm an unmodified AWS SDK acquires and refreshes credentials from AWS_WEB_IDENTITY_TOKEN_FILE, AWS_ROLE_ARN and AWS_ENDPOINT_URL_STS alone.
Done when
A plain boto3 script runs unattended across a credential expiry with no Source-specific code.
Watch
Depends on #221, source-cooperative/source.coop#548 and source-cooperative/source-coop-cli#17.
Part of source-cooperative/source.coop#491.
Phase 5 — API keys. Verification, not implementation — but it will find work.
Do
Confirm an unmodified AWS SDK acquires and refreshes credentials from
AWS_WEB_IDENTITY_TOKEN_FILE,AWS_ROLE_ARNandAWS_ENDPOINT_URL_STSalone.Done when
A plain boto3 script runs unattended across a credential expiry with no Source-specific code.
Watch
tests/test_writes.py) POSTRoleArn: "_default"by hand. That is not ARN-shaped, so the SDK's client-side ARN validation — the exact path this issue exists to prove — has never been exercised.get_rolereturnsNonefor anything but_defaultuntil Add the ReadOnly Role alongside FullAccess #221 lands, so any non-default Role in the test fails before then.aws-actions/configure-aws-credentialsis out of scope: it callsGetCallerIdentity, unimplemented upstream (multistore-sts: implement GetCallerIdentity (unblocks aws-actions/configure-aws-credentials) developmentseed/multistore#127).Depends on #221, source-cooperative/source.coop#548 and source-cooperative/source-coop-cli#17.
Part of source-cooperative/source.coop#491.