feat: add STSPresignClient field to GetTokenOptions for custom credential injection - #1063
feat: add STSPresignClient field to GetTokenOptions for custom credential injection#1063jitinchekka2 wants to merge 1 commit into
Conversation
|
|
|
Welcome @jitinchekka2! |
|
Hi @jitinchekka2. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: jitinchekka2 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@hakuna-matatah @ronaldngounou Please review |
What this PR does / why we need it:
GetWithOptionscalls config.LoadDefaultConfig internally, which builds its own AWS config from the environment. There is no way to pass a pre-configured STS client, so callers who have already built credentials (e.g. named profiles, cross-account role chains, or custom endpoints) are forced to re-implement the token presigning logicthemselves rather than using this library.
This pull request adds an optional STSPresignClient STSPresignAPI field to GetTokenOptions. When set, GetWithOptions uses it directly and skips LoadDefaultConfig entirely. When nil, existing behavior is unchanged.
The STSPresignAPI interface is narrow — a single PresignGetCallerIdentity method — and is satisfied by *sts.PresignClient without any adapter.
The presigning logic is extracted from GetWithSTS into a private presignToken helper shared by both paths, so there is no duplication.