Migrate AWS EC2 role-id property to role in EnvironmentVaultConfiguration

Support both, role and role-id for aws-ec2 for backwards compatibility.

Fix EnvironmentVaultConfiguration documentation.

Closes gh-508.
Original pull request: gh-509.
This commit is contained in:
Raoof Mohammed
2019-11-25 17:52:28 -05:00
committed by Mark Paluch
parent 5154e49b6a
commit 7fa31da4de
2 changed files with 13 additions and 7 deletions

View File

@@ -131,7 +131,8 @@ import org.springframework.web.client.RestOperations;
* <ul>
* <li>AWS EC2 path: {@code vault.aws-ec2.aws-ec2-path} (since 2.2.1, defaults to
* {@link AwsEc2AuthenticationOptions#DEFAULT_AWS_AUTHENTICATION_PATH})</li>
* <li>RoleId: {@code vault.aws-ec2.role-id}</li>
* <li>Role: {@code vault.aws-ec2.role} (since 2.2.1)</li>
* <li>RoleId: {@code vault.aws-ec2.role-id} (@Deprecated - use {@code vault.aws-ec2.role} instead)</li>
* <li>Identity Document URL: {@code vault.aws-ec2.identity-document} (defaults to
* {@link AwsEc2AuthenticationOptions#DEFAULT_PKCS7_IDENTITY_DOCUMENT_URI})</li>
* </ul>
@@ -340,23 +341,27 @@ public class EnvironmentVaultConfiguration extends AbstractVaultConfiguration
protected ClientAuthentication awsEc2Authentication() {
String role = getProperty("vault.aws-ec2.role");
String roleId = getProperty("vault.aws-ec2.role-id");
String identityDocument = getProperty("vault.aws-ec2.identity-document");
String path = getProperty("vault.aws-ec2.aws-ec2-path",
AwsEc2AuthenticationOptions.DEFAULT_AWS_AUTHENTICATION_PATH);
Assert.hasText(roleId,
"Vault AWS EC2 authentication: RoleId (vault.aws-ec2.role-id) must not be empty");
Assert.isTrue(StringUtils.hasText(roleId) || StringUtils.hasText(role),
"Vault AWS-EC2 authentication: Role (vault.aws-ec2.role) must not be empty");
Assert.isTrue(!(StringUtils.hasText(roleId) && StringUtils.hasText(role)),
"Vault AWS-EC2 authentication: Only one of Role (vault.aws-ec2.role) or"
+ " RoleId(@Deprecated) (vault.aws-ec2.roleId) must be provided");
AwsEc2AuthenticationOptionsBuilder builder = AwsEc2AuthenticationOptions.builder()
.role(roleId).path(path);
.role(StringUtils.hasText(role) ? role : roleId).path(path);
if (StringUtils.hasText(identityDocument)) {
builder.identityDocumentUri(URI.create(identityDocument));
}
return new AwsEc2Authentication(builder.build(), restOperations(),
restOperations());
return new AwsEc2Authentication(builder.build(), restOperations(), restOperations());
}
protected ClientAuthentication azureMsiAuthentication() {

View File

@@ -198,7 +198,8 @@ Any other value is used with `StaticUserId`.
**<<vault.authentication.awsec2>>**
* AWS EC2 path: `vault.aws-ec2.aws-ec2-path` (defaults to `aws-ec2`)
* RoleId: `vault.aws-ec2.role-id`
* Role: `vault.aws-ec2.role`
* RoleId: `vault.aws-ec2.role-id` (deprecated - use `vault.aws-ec2.role` instead)
* Identity Document URL: `vault.aws-ec2.identity-document` (defaults to `http://169.254.169.254/latest/dynamic/instance-identity/pkcs7`)
**<<vault.authentication.azuremsi>>**