gaborgsomogyi commented on code in PR #29344:
URL: https://github.com/apache/flink/pull/29344#discussion_r4153360811
##########
flink-filesystems/flink-s3-fs-base/src/main/java/org/apache/flink/fs/s3/common/token/AbstractS3DelegationTokenProvider.java:
##########
@@ -87,22 +88,29 @@ public boolean delegationTokensRequired() {
public ObtainedDelegationTokens obtainDelegationTokens() throws Exception {
LOG.info("Obtaining session credentials token with access key: {}",
accessKey);
- AWSSecurityTokenService stsClient =
- AWSSecurityTokenServiceClientBuilder.standard()
- .withRegion(region)
- .withCredentials(
- new AWSStaticCredentialsProvider(
- new BasicAWSCredentials(accessKey,
secretKey)))
- .build();
- GetSessionTokenResult sessionTokenResult = stsClient.getSessionToken();
- Credentials credentials = sessionTokenResult.getCredentials();
- LOG.info(
- "Session credentials obtained successfully with access key: {}
expiration: {}",
- credentials.getAccessKeyId(),
- credentials.getExpiration());
+ final AWSSecurityTokenService stsClient = createStsClient();
+ // Preserve the acquisition failure if shutting down the client also
fails.
+ try (AutoCloseable ignored = stsClient::shutdown) {
Review Comment:
Since `shutdown` is best effort maybe we should consider it that way with
`try/finally/LOG.WARN`. The current code brings in a risk not to produce tokens
when `shutdown` throws exception.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]