7 "github.com/aws/aws-sdk-go/aws"
8 "github.com/aws/aws-sdk-go/aws/credentials"
9 "github.com/aws/aws-sdk-go/aws/defaults"
12 // EnvProviderName provides a name of the provider when config is loaded from environment.
13 const EnvProviderName = "EnvConfigCredentials"
15 // envConfig is a collection of environment values the SDK will read
16 // setup config from. All environment values are optional. But some values
17 // such as credentials require multiple values to be complete or the values
19 type envConfig struct {
20 // Environment configuration values. If set both Access Key ID and Secret Access
21 // Key must be provided. Session Token and optionally also be provided, but is
25 // AWS_ACCESS_KEY_ID=AKID
26 // AWS_ACCESS_KEY=AKID # only read if AWS_ACCESS_KEY_ID is not set.
28 // # Secret Access Key
29 // AWS_SECRET_ACCESS_KEY=SECRET
30 // AWS_SECRET_KEY=SECRET=SECRET # only read if AWS_SECRET_ACCESS_KEY is not set.
33 // AWS_SESSION_TOKEN=TOKEN
34 Creds credentials.Value
36 // Region value will instruct the SDK where to make service API requests to. If is
37 // not provided in the environment the region must be provided before a service
38 // client request is made.
40 // AWS_REGION=us-east-1
42 // # AWS_DEFAULT_REGION is only read if AWS_SDK_LOAD_CONFIG is also set,
43 // # and AWS_REGION is not also set.
44 // AWS_DEFAULT_REGION=us-east-1
47 // Profile name the SDK should load use when loading shared configuration from the
48 // shared configuration files. If not provided "default" will be used as the
51 // AWS_PROFILE=my_profile
53 // # AWS_DEFAULT_PROFILE is only read if AWS_SDK_LOAD_CONFIG is also set,
54 // # and AWS_PROFILE is not also set.
55 // AWS_DEFAULT_PROFILE=my_profile
58 // SDK load config instructs the SDK to load the shared config in addition to
59 // shared credentials. This also expands the configuration loaded from the shared
60 // credentials to have parity with the shared config file. This also enables
61 // Region and Profile support for the AWS_DEFAULT_REGION and AWS_DEFAULT_PROFILE
62 // env values as well.
64 // AWS_SDK_LOAD_CONFIG=1
65 EnableSharedConfig bool
67 // Shared credentials file path can be set to instruct the SDK to use an alternate
68 // file for the shared credentials. If not set the file will be loaded from
69 // $HOME/.aws/credentials on Linux/Unix based systems, and
70 // %USERPROFILE%\.aws\credentials on Windows.
72 // AWS_SHARED_CREDENTIALS_FILE=$HOME/my_shared_credentials
73 SharedCredentialsFile string
75 // Shared config file path can be set to instruct the SDK to use an alternate
76 // file for the shared config. If not set the file will be loaded from
77 // $HOME/.aws/config on Linux/Unix based systems, and
78 // %USERPROFILE%\.aws\config on Windows.
80 // AWS_CONFIG_FILE=$HOME/my_shared_config
81 SharedConfigFile string
83 // Sets the path to a custom Credentials Authority (CA) Bundle PEM file
84 // that the SDK will use instead of the system's root CA bundle.
85 // Only use this if you want to configure the SDK to use a custom set
88 // Enabling this option will attempt to merge the Transport
89 // into the SDK's HTTP client. If the client's Transport is
90 // not a http.Transport an error will be returned. If the
91 // Transport's TLS config is set this option will cause the
92 // SDK to overwrite the Transport's TLS config's RootCAs value.
94 // Setting a custom HTTPClient in the aws.Config options will override this setting.
95 // To use this option and custom HTTP client, the HTTP client needs to be provided
96 // when creating the session. Not the service client.
98 // AWS_CA_BUNDLE=$HOME/my_custom_ca_bundle
106 enableEndpointDiscovery string
107 // Enables endpoint discovery via environment variables.
109 // AWS_ENABLE_ENDPOINT_DISCOVERY=true
110 EnableEndpointDiscovery *bool
114 csmEnabledEnvKey = []string{
117 csmPortEnvKey = []string{
120 csmClientIDEnvKey = []string{
123 credAccessEnvKey = []string{
127 credSecretEnvKey = []string{
128 "AWS_SECRET_ACCESS_KEY",
131 credSessionEnvKey = []string{
135 enableEndpointDiscoveryEnvKey = []string{
136 "AWS_ENABLE_ENDPOINT_DISCOVERY",
139 regionEnvKeys = []string{
141 "AWS_DEFAULT_REGION", // Only read if AWS_SDK_LOAD_CONFIG is also set
143 profileEnvKeys = []string{
145 "AWS_DEFAULT_PROFILE", // Only read if AWS_SDK_LOAD_CONFIG is also set
147 sharedCredsFileEnvKey = []string{
148 "AWS_SHARED_CREDENTIALS_FILE",
150 sharedConfigFileEnvKey = []string{
155 // loadEnvConfig retrieves the SDK's environment configuration.
156 // See `envConfig` for the values that will be retrieved.
158 // If the environment variable `AWS_SDK_LOAD_CONFIG` is set to a truthy value
159 // the shared SDK config will be loaded in addition to the SDK's specific
160 // configuration values.
161 func loadEnvConfig() envConfig {
162 enableSharedConfig, _ := strconv.ParseBool(os.Getenv("AWS_SDK_LOAD_CONFIG"))
163 return envConfigLoad(enableSharedConfig)
166 // loadEnvSharedConfig retrieves the SDK's environment configuration, and the
167 // SDK shared config. See `envConfig` for the values that will be retrieved.
169 // Loads the shared configuration in addition to the SDK's specific configuration.
170 // This will load the same values as `loadEnvConfig` if the `AWS_SDK_LOAD_CONFIG`
171 // environment variable is set.
172 func loadSharedEnvConfig() envConfig {
173 return envConfigLoad(true)
176 func envConfigLoad(enableSharedConfig bool) envConfig {
179 cfg.EnableSharedConfig = enableSharedConfig
181 setFromEnvVal(&cfg.Creds.AccessKeyID, credAccessEnvKey)
182 setFromEnvVal(&cfg.Creds.SecretAccessKey, credSecretEnvKey)
183 setFromEnvVal(&cfg.Creds.SessionToken, credSessionEnvKey)
185 // CSM environment variables
186 setFromEnvVal(&cfg.csmEnabled, csmEnabledEnvKey)
187 setFromEnvVal(&cfg.CSMPort, csmPortEnvKey)
188 setFromEnvVal(&cfg.CSMClientID, csmClientIDEnvKey)
189 cfg.CSMEnabled = len(cfg.csmEnabled) > 0
191 // Require logical grouping of credentials
192 if len(cfg.Creds.AccessKeyID) == 0 || len(cfg.Creds.SecretAccessKey) == 0 {
193 cfg.Creds = credentials.Value{}
195 cfg.Creds.ProviderName = EnvProviderName
198 regionKeys := regionEnvKeys
199 profileKeys := profileEnvKeys
200 if !cfg.EnableSharedConfig {
201 regionKeys = regionKeys[:1]
202 profileKeys = profileKeys[:1]
205 setFromEnvVal(&cfg.Region, regionKeys)
206 setFromEnvVal(&cfg.Profile, profileKeys)
208 // endpoint discovery is in reference to it being enabled.
209 setFromEnvVal(&cfg.enableEndpointDiscovery, enableEndpointDiscoveryEnvKey)
210 if len(cfg.enableEndpointDiscovery) > 0 {
211 cfg.EnableEndpointDiscovery = aws.Bool(cfg.enableEndpointDiscovery != "false")
214 setFromEnvVal(&cfg.SharedCredentialsFile, sharedCredsFileEnvKey)
215 setFromEnvVal(&cfg.SharedConfigFile, sharedConfigFileEnvKey)
217 if len(cfg.SharedCredentialsFile) == 0 {
218 cfg.SharedCredentialsFile = defaults.SharedCredentialsFilename()
220 if len(cfg.SharedConfigFile) == 0 {
221 cfg.SharedConfigFile = defaults.SharedConfigFilename()
224 cfg.CustomCABundle = os.Getenv("AWS_CA_BUNDLE")
229 func setFromEnvVal(dst *string, keys []string) {
230 for _, k := range keys {
231 if v := os.Getenv(k); len(v) > 0 {