Andrea Cosentino created CAMEL-24870:
----------------------------------------
Summary: camel-aws2: add an opt-in auto-detect credentials
provider that selects the AWS credentials source from the detected runtime
Key: CAMEL-24870
URL: https://issues.apache.org/jira/browse/CAMEL-24870
Project: Camel
Issue Type: Improvement
Components: camel-aws2, camel-aws2-s3
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Fix For: 4.23.0
h3. Background / motivation
All camel-aws2 (SDK v2) components resolve credentials through one shared
selector — {{AwsClientBuilderUtil.resolveCredentialsProvider(...)}} in
{{camel-aws-common}} — choosing between static keys, profile, session, or
{{useDefaultCredentialsProvider}} (SDK {{DefaultCredentialsProvider}}).
The SDK's {{DefaultCredentialsProvider}} walks its chain env -> sysprops ->
web-identity/IRSA -> profile -> ECS/EKS-Pod-Identity container -> EC2 IMDS,
trying *IMDS last*. Off-EC2 (local dev, non-AWS containers) this can hang on
the IMDS metadata timeout, and the chain never reports which source it actually
used.
h3. Proposal
Add a new opt-in option {{useAutoDetectCredentialsProvider}} (label
{{security}}), a sibling to the existing
{{useDefaultCredentialsProvider}}/{{useProfileCredentialsProvider}}/{{useSessionCredentials}}
options. When enabled, a new shared helper in {{camel-aws-common}} explicitly
detects the runtime and returns the *single matching* SDK credentials provider
(targeted, no silent fallthrough), in this precedence — deliberately mirroring
the SDK chain order so we are faster and louder but never behave differently:
# static env creds ({{AWS_ACCESS_KEY_ID}}/{{AWS_SECRET_ACCESS_KEY}})
# web-identity / IRSA ({{AWS_WEB_IDENTITY_TOKEN_FILE}} + {{AWS_ROLE_ARN}})
# container creds — ECS ({{AWS_CONTAINER_CREDENTIALS_RELATIVE_URI}}) / EKS Pod
Identity ({{AWS_CONTAINER_CREDENTIALS_FULL_URI}} + token file)
# profile / SSO ({{~/.aws/config}}, {{AWS_PROFILE}})
# EC2 IMDS, behind a *short-timeout reachability probe* (skips the off-EC2 hang)
# otherwise -> fall back to the full SDK {{DefaultCredentialsProvider}} chain
(never worse than today)
Log one INFO line at startup naming the detected environment and the chosen
provider.
h3. Scope
* Backwards compatible: purely opt-in; the existing no-creds default path is
untouched.
* v1 delivers the shared helper + the central selector branch, wired first on
{{camel-aws2-s3}} (pilot). Rolling the option out to the remaining SDK-v2
components is mechanical follow-up (add the {{@UriParam}} field per config
class + regenerate catalog/DSL).
* STS explicit assume-role is out of scope for v1 (IRSA/web-identity is already
role-based via the SDK).
* Non-AWS clouds and external secret stores are out of scope for v1.
h3. Implementation notes
* New class
{{org.apache.camel.component.aws.common.AwsRuntimeCredentialsResolver}},
invoked from {{AwsClientBuilderUtil.resolveCredentialsProvider}}; add
{{isUseAutoDetectCredentialsProvider()}} to {{AwsCommonConfiguration}}.
* Designed with an injectable environment view (env / file / IMDS-probe seam)
for deterministic unit tests.
* Full coverage later also updates the three provider-building spots that
bypass the shared util: S3 presigner ({{AWS2S3Producer.getOrCreatePresigner}}),
KCL consumer ({{KclKinesis2Consumer}}), Transcribe verifier.
* New option documented in component docs; no upgrade-guide entry (new opt-in,
no behavior change).
*Precedence on conflict:* if {{useAutoDetectCredentialsProvider}} is set
alongside other {{use*}}/static options, auto-detect wins (its own step 1 still
honors env-static creds); log a warning.
_Drafted with Claude Code on behalf of Andrea Cosentino (@oscerd)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)