Skip to content

feat(aws): expose shared configuration and region discovery - #902

Merged
Xuanwo merged 4 commits into
mainfrom
xuanwo/aws-shared-config-894
Oct 5, 2026
Merged

Xuanwo merged 4 commits into
mainfrom
xuanwo/aws-shared-config-894

Conversation

@Xuanwo

@Xuanwo Xuanwo commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Consumers need to load an AWS profile's region and global endpoint without duplicating INI parsing or acquiring credentials. SharedConfig exposes the selected profile, merged properties, and explicit/environment/file precedence. Profile, process, and SSO credential providers reuse its file selection and parser; static credentials retain complete-file precedence without mixing key pairs across files.

resolve_region uses explicit, environment, and profile values before an opt-in IMDSv2RegionProvider fallback. Discovery is independent of IAM credentials and bounds the complete token-plus-region exchange with a configurable deadline. The timer is runtime-independent and supports browser timers on wasm32. Missing values remain absent; malformed-file and metadata errors remain visible to callers.

Configuration loading has no network or credential execution side effects. Endpoint settings are exposed for the caller to interpret; service endpoint rules and role/SSO execution remain outside this API.

Fixes #894.

@Xuanwo
Xuanwo marked this pull request as ready for review October 5, 2026 05:23
@Xuanwo
Xuanwo merged commit a550ed9 into main Oct 5, 2026
64 checks passed
@Xuanwo
Xuanwo deleted the xuanwo/aws-shared-config-894 branch October 5, 2026 05:26
Xuanwo added a commit that referenced this pull request Oct 5, 2026
Closes #898. Builds on the shared AWS configuration loader introduced in
#902.

Named SSO sessions renew expired access tokens through
`Context::http_send` using cached OIDC registration and refresh
material. Configuration is resolved through the shared AWS loader from
#902, including literal command values. This includes named-session
resolution and cache selection from #856, without implementing
assume-role profile graphs.

Each internal `SsoSession` owns its token state and refresh lock.
Provider clones share sessions, but a blocked refresh does not block
another session. Disk JSON is converted into typed in-memory state with
`Timestamp` expirations. A successful refresh replaces the complete
token state before requesting role credentials, preserving rotated
refresh tokens across role-exchange failures. Rejected grants require
login; throttling (including HTTP 400 `slow_down`) and transient
failures remain retryable without exposing response descriptions or
secrets.

The AWS default provider executes SSO between its preceding and
following provider chains and propagates SSO errors directly. Absent SSO
configuration continues resolution. Core APIs are unchanged, as are
custom `ProvideCredentialChain` behavior, `with_chain`, slot removal,
and `push_front` precedence.

Refreshed material remains in memory for the provider and its clones.
The AWS CLI cache is never written, independent providers/processes do
not coordinate, and restarting requires usable on-disk refresh material.
Once an in-memory token expires, a newer CLI login cache can replace it.
Legacy inline configuration remains non-refreshable and no interactive
login is started.

Tests use synthetic files and HTTP responses, a controlled clock, and
gated concurrent calls. Coverage includes rotation and subsequent
refresh, independent-session progress, same-session coordination, failed
role exchanges, default-chain boundaries, and the reported non-SSO
configuration reproducer. No developer SSO cache or real SSO account is
required.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(aws): expose shared configuration and region resolution

1 participant