Skip to content

Support deferring resolving credentials until needed #1740

Description

@G-Rath

Is your feature request related to a problem? Please describe.
Resolving AWS credentials can take a not-zero time when they're not available since some providers wait until a request times out.

For example, this takes about 3 seconds:

❯ bundle exec ruby -raws-sdk-core -e 'Aws::InstanceProfileCredentials.new'
Error retrieving instance profile credentials: Failed to open TCP connection to 169.254.169.254:80 (execution expired)

This time is spent whenever Rails is initialized which happens for a lot of reasons including precompiling assets, doing database migrations, and so on making it very tedious to try and account for all these different situations.

Since some providers will raise an error when they cannot resolve credentials (such as the ECS provider), this also means the whole app can crash rather than degrade gracefully.

Describe the solution you'd like
It would be nice if resolving the credentials could be deferred in some way, such as by being able to pass a lambda to credentials_provider:

Searchkick.aws_credentials = {
  credentials_provider: -> { Aws::CredentialProviderChain.new.resolve },
  region: ENV["AWS_REGION"].presence,
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions