Jason Martin created HADOOP-19067: ------------------------------------- Summary: Allow tag passing to AWS Credential Provider Key: HADOOP-19067 URL: https://issues.apache.org/jira/browse/HADOOP-19067 Project: Hadoop Common Issue Type: Improvement Components: fs/s3 Affects Versions: 3.3.6 Reporter: Jason Martin
[https://github.com/apache/hadoop/blob/trunk/hadoop-tools/hadoop-aws/src/main/java/org/apache/hadoop/fs/s3a/auth/AssumedRoleCredentialProvider.java#L131-L133] passes a session name and role arn to AssumeRoleRequest. The AWS AssumeRole API also supports passing a list of tags: [https://sdk.amazonaws.com/java/api/latest/software/amazon/awssdk/services/sts/model/AssumeRoleRequest.html#tags()] These tags could be used by platforms to enhance the data encoded into CloudTrail entries to provide better information about the client. For example, a 'notebook' based platform could encode the notebook / jobname / invoker-id in these tags, enabling more granular access controls and leaving a richer breadcrumb-trail as to what operations are being performed. This is particularly useful in larger environments where jobs do not get individual roles to assume, and there is a desire to track what jobs/notebooks are reading a given set of files in S3. -- This message was sent by Atlassian Jira (v8.20.10#820010) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org