Repository navigation
feat(aws): expose shared configuration and region discovery - #902
Merged
Merged
Conversation
Xuanwo
marked this pull request as ready for review
October 5, 2026 05:23
Xuanwo
added a commit
that referenced
this pull request
Oct 5, 2026
Closes #898. Builds on the shared AWS configuration loader introduced in #902. Named SSO sessions renew expired access tokens through `Context::http_send` using cached OIDC registration and refresh material. Configuration is resolved through the shared AWS loader from #902, including literal command values. This includes named-session resolution and cache selection from #856, without implementing assume-role profile graphs. Each internal `SsoSession` owns its token state and refresh lock. Provider clones share sessions, but a blocked refresh does not block another session. Disk JSON is converted into typed in-memory state with `Timestamp` expirations. A successful refresh replaces the complete token state before requesting role credentials, preserving rotated refresh tokens across role-exchange failures. Rejected grants require login; throttling (including HTTP 400 `slow_down`) and transient failures remain retryable without exposing response descriptions or secrets. The AWS default provider executes SSO between its preceding and following provider chains and propagates SSO errors directly. Absent SSO configuration continues resolution. Core APIs are unchanged, as are custom `ProvideCredentialChain` behavior, `with_chain`, slot removal, and `push_front` precedence. Refreshed material remains in memory for the provider and its clones. The AWS CLI cache is never written, independent providers/processes do not coordinate, and restarting requires usable on-disk refresh material. Once an in-memory token expires, a newer CLI login cache can replace it. Legacy inline configuration remains non-refreshable and no interactive login is started. Tests use synthetic files and HTTP responses, a controlled clock, and gated concurrent calls. Coverage includes rotation and subsequent refresh, independent-session progress, same-session coordination, failed role exchanges, default-chain boundaries, and the reported non-SSO configuration reproducer. No developer SSO cache or real SSO account is required.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consumers need to load an AWS profile's region and global endpoint without duplicating INI parsing or acquiring credentials.
SharedConfigexposes the selected profile, merged properties, and explicit/environment/file precedence. Profile, process, and SSO credential providers reuse its file selection and parser; static credentials retain complete-file precedence without mixing key pairs across files.resolve_regionuses explicit, environment, and profile values before an opt-inIMDSv2RegionProviderfallback. Discovery is independent of IAM credentials and bounds the complete token-plus-region exchange with a configurable deadline. The timer is runtime-independent and supports browser timers on wasm32. Missing values remain absent; malformed-file and metadata errors remain visible to callers.Configuration loading has no network or credential execution side effects. Endpoint settings are exposed for the caller to interpret; service endpoint rules and role/SSO execution remain outside this API.
Fixes #894.