mirror of
https://github.com/ceph/ceph-csi.git
synced 2024-12-22 13:00:19 +00:00
4f0bb2315b
With Amazon STS and kubernetes cluster is configured with OIDC identity provider, credentials to access Amazon KMS can be fetched using oidc-token(serviceaccount token). Each tenant/namespace needs to create a secret with aws region, role and CMK ARN. Ceph-CSI will assume the given role with oidc token and access aws KMS, with given CMK to encrypt/decrypt DEK which will stored in the image metdata. Refer: https://docs.aws.amazon.com/STS/latest/APIReference/welcome.html Resolves: #2879 Signed-off-by: Rakshith R <rar@redhat.com>
36 lines
1.2 KiB
JSON
36 lines
1.2 KiB
JSON
{
|
|
"dependencies": {
|
|
"github.com/aws/aws-sdk-go-v2": "v1.4.0",
|
|
"github.com/aws/aws-sdk-go-v2/internal/configsources": "v0.0.0-00010101000000-000000000000",
|
|
"github.com/aws/aws-sdk-go-v2/internal/endpoints/v2": "v2.0.0-00010101000000-000000000000",
|
|
"github.com/aws/aws-sdk-go-v2/service/internal/presigned-url": "v1.0.7",
|
|
"github.com/aws/smithy-go": "v1.4.0"
|
|
},
|
|
"files": [
|
|
"api_client.go",
|
|
"api_client_test.go",
|
|
"api_op_AssumeRole.go",
|
|
"api_op_AssumeRoleWithSAML.go",
|
|
"api_op_AssumeRoleWithWebIdentity.go",
|
|
"api_op_DecodeAuthorizationMessage.go",
|
|
"api_op_GetAccessKeyInfo.go",
|
|
"api_op_GetCallerIdentity.go",
|
|
"api_op_GetFederationToken.go",
|
|
"api_op_GetSessionToken.go",
|
|
"deserializers.go",
|
|
"doc.go",
|
|
"endpoints.go",
|
|
"generated.json",
|
|
"internal/endpoints/endpoints.go",
|
|
"internal/endpoints/endpoints_test.go",
|
|
"protocol_test.go",
|
|
"serializers.go",
|
|
"types/errors.go",
|
|
"types/types.go",
|
|
"validators.go"
|
|
],
|
|
"go": "1.15",
|
|
"module": "github.com/aws/aws-sdk-go-v2/service/sts",
|
|
"unstable": false
|
|
}
|