Skip to content

Commit a8e2b4f

Browse files
refactor(aws-creds-cache): set default cache expiry to 1 hour (#3365)
> All credential providers passed to or returned by LoadDefaultConfig are wrapped in a [CredentialsCache](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/aws#CredentialsCache) automatically. This enables caching and credential rotation that is concurrency safe. If you explicitly configure a provider on aws.Config directly, you must also explicitly wrap the provider with this type using [NewCredentialsCache](https://pkg.go.dev/github.com/aws/aws-sdk-go-v2/aws#NewCredentialsCache). Not sure if we can fully remove the cache, but we can make the cache expiry to 1 hour before creds expire so the creds are valid for atleast 1 hour
1 parent 16263fb commit a8e2b4f

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

flow/connectors/utils/aws.go

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -295,6 +295,10 @@ func GetAWSCredentialsProvider(ctx context.Context, connectorName string, peerCr
295295
}
296296

297297
awsConfig, err := config.LoadDefaultConfig(ctx, func(options *config.LoadOptions) error {
298+
options.CredentialsCacheOptions = func(options *aws.CredentialsCacheOptions) {
299+
options.ExpiryWindow = time.Hour
300+
options.ExpiryWindowJitterFrac = 0
301+
}
298302
return nil
299303
})
300304
if err != nil {

0 commit comments

Comments
 (0)