destination-s3 use instanceprofile if credentials are not provided - #9399
Conversation
| "access_key_id", | ||
| "secret_access_key", |
There was a problem hiding this comment.
Sherif A. Nada (@sherifnada) can you check this PR adding the option to use S3 destination with InstanceProfile. No additional change in UI, but how users can experience errors from the front-end. What do you think? Should add an option to select the connection method => (credentials or instance profile)?
There was a problem hiding this comment.
I think that the user-experience will not suffer,
if access_key_id AND secret_access_key are not provided -> instanceprofile auth
if access_key_id OR secret_access_key are not provided -> standard authentication error
the rest will stay the same.
|
reassigning to Edward Gao (@edgao) for review |
Edward Gao (edgao)
left a comment
There was a problem hiding this comment.
added a few minor comments!
Co-authored-by: Edward Gao <edward.gao@airbyte.io>
Edward Gao (edgao)
left a comment
There was a problem hiding this comment.
one small wording change, otherwise LGTM!
…o/airbyte/integrations/destination/s3/S3DestinationConfig.java Co-authored-by: Edward Gao <edward.gao@airbyte.io>
|
M. Marx (@marcosmarxm) and Sherif A. Nada (@sherifnada) is anything else needed to proceed with the merge? |
What
Describe what the change is solving
Destination-s3 connector does not support using instanceprofile authentication. This is a huge drawback for some organizations.
This solves the issues 5942 and 8227
How
Allow the fields accessKeyId and secretAccessKey to be optional on the destination-s3 configuration page.
If they are not provided, the getS3Client method will use InstanceProfileCredentialsProvider.
effect:

build:

cmd used -
./gradlew :airbyte-integrations:connectors:destination-s3:buildresult of sync, Airbyte is running on ec2 instance, and no aws credentials were provided

my modified connector image can be found here
Recommended reading order
doc for InstanceProfileCredentialsProvider
🚨 User Impact 🚨
Are there any breaking changes? What is the end result perceived by the user? If yes, please merge this PR with the 🚨🚨 emoji so changelog authors can further highlight this if needed.
Users will now be able to use instance profile authentication for the connector destination-s3
Pre-merge Checklist
Expand the relevant checklist and delete the others.
New Connector
Community member or Airbyter
airbyte_secret./gradlew :airbyte-integrations:connectors:<name>:integrationTest.README.mdbootstrap.md. See description and examplesdocs/SUMMARY.mddocs/integrations/<source or destination>/<name>.mdincluding changelog. See changelog exampledocs/integrations/README.mdairbyte-integrations/builds.mdAirbyter
If this is a community PR, the Airbyte engineer reviewing this PR is responsible for the below items.
/test connector=connectors/<name>command is passing./publishcommand described hereUpdating a connector
Community member or Airbyter
airbyte_secret./gradlew :airbyte-integrations:connectors:<name>:integrationTest.README.mdbootstrap.md. See description and examplesdocs/integrations/<source or destination>/<name>.mdincluding changelog. See changelog exampleAirbyter
If this is a community PR, the Airbyte engineer reviewing this PR is responsible for the below items.
/test connector=connectors/<name>command is passing./publishcommand described hereConnector Generator
-scaffoldin their name) have been updated with the latest scaffold by running./gradlew :airbyte-integrations:connector-templates:generator:testScaffoldTemplatesthen checking in your changes